Red Hat Security Advisory: RHTAS 1.4 - GA Release of Model Transparency
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-27459 — pyOpenSSL: DTLS cookie callback buffer overflow
CVE-2026-30922 — pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion
CVE-2026-32597 — pyjwt: PyJWT accepts unknown crit header extensions (RFC 7515 §4.1.11 MUST violation)
🎯 Affected products3
- Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/model-transparency-rhel9@sha256:58f6c2216f1b745ff0af4195dc72395eeab531bf8561b507ea64730f38ecc24d_amd64 as a component of Red Hat Trusted Artifact Signer 1.4
- registry.redhat.io/rhtas/model-transparency-rhel9@sha256:66b12e8e6822f23ad63f43c660d815d8007da46aa5ac3b5cceebf727b147f755_arm64 as a component of Red Hat Trusted Artifact Signer 1.4
✅ Remediation
The Model Transparency CLI Image is a containerized command-line tool for signing and verifying AI/ML workloads against a private Red Hat Trusted Artifact Signer (RHTAS) instance. It lets teams create signatures and attestations for model artifacts and validate them at build or deploy time using enterprise trust material (e.g., Fulcio/Rekor). For details on using the Model Transparency CLI image, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4/html-single/release_notes/index Workaround: To mitigate this flaw, ensure the callback provided to the set_cookie_generate_callback function strictly limits the returned cookie string or byte sequence to under 256 bytes. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:8437
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4/html-single/release_notes/index
- externalhttps://access.redhat.com/security/cve/CVE-2026-27459
- externalhttps://access.redhat.com/security/cve/CVE-2026-30922
- externalhttps://access.redhat.com/security/cve/CVE-2026-32597
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_8437.json