RHSA-2026:9697HighCVSS 7.5
Red Hat Security Advisory: Red Hat OpenShift GitOps v1.18.5 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-27137 — crypto/x509: Incorrect enforcement of email constraints in crypto/x509
🎯 Affected products42
- Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:24e67d1a105be747aee40ce6c616db47f26eb9a74b0f51ddccae545337d5a367_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:390b0d8b53bd91fce22617d5914f4a50fa74441c39e636123604d5f2b4ab8440_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:97d073694ecf9c6b0dcc09707a983a1e1d950a9d0bc4a247b1fd464a66c876c8_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:d52b043483f248cf812d61fd253c979343881ef1aae94b0096aa9dcd1e0aafbb_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:8a00814288cc821ea5c8c349895cd0b6ce5a4dbb793685a7fa144f99506052d5_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:9d656e008382d7dd47619843ed2591eb3592f51af0504ae4642f7aa4fbf89e82_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:c9ac9cedc310e8286272b467f740b8a9f97c0c371b02e6bece42a0211d0e89a2_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:f2b65612117a006a24aca63deec9a1adeff0e94b775129154a255307f4a74240_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:76162ab820b06df90cbca62797e3f2ddca3fb1aa527ce469982ae27f01419562_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:91566f97904038fcd46b79db9b6e351c053ebbfe535a15dc0c560efccfc477af_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:d22d2f99b5863f27b31c69e81489cdb4002f53915a9983ede4ec822934533542_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:ef97fb44e3fa878c676dc32db2b7770a67acf94f3f2b5630de3353fbd4b9de2e_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:4285f37ac71f1522cb28b8cea56415eebe7b05f644f83d28246c32b39eb4f98d_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:7a286bd7aac225e6ef6f5ccefb9b1839fb4cb8c6cd5f0cd1ee79ebb43813211f_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:9dd3efe9a0cc081caf3b7e7cea7e03cc13e6a290c8884a492d8ff505dfb0edcd_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:c7d771a9a408e77b825e95f045a84b7334bec1dfe6d5a307fb62066091ac96d1_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:2130222eeb06890b0316489688fb01f0941b4d681e00a33b661c9d4702c4711d_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:4fb65a1e2efffdedff5bb7b5c49b1c9fd7fb52e924971a46928cadd1ce3beac2_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:804431fea3b24f8d8d60f8f6c09d68d8dc6d9926b8c59e869fcaca8bf780d32e_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:e0b9f3902fd2d9117d51e955e58ab46e6fca0af8033fcce4bc860b7aa432c017_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:4b5dfdb8fbd0109362d0a77fc4e2e46933dcc5c8e7f6c38341074f2160702bca_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:61c80fdd31e4e19ee3cc0dbeb8ce72981a6ed1f98327a405637fadd8bb7d5961_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:9b8f15505a7ee118ea6e60870a88c9c582ba9227937113347e03e9afdbb91f16_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:fc8664f60bc08619935ed5133dac7498a7e6f28bb54b5d88184cce1b547a100b_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:35f009047d38584dcb2216ab3a22a019a94e3f5d2d6047737dd33097dd32ab33_ppc64le as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:7892f00200cd9dd55b3b64930ec58bde53489e2bd7815ee9a6cac0f5af2923be_arm64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:e848afbb6a3ce2dae976601c6982fc844cf2a8efaeae88de0c22a005e007e2d0_s390x as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:e996549f3c4b48f14bf61be9777bd66084366c649e9cc0e330b911ffd8ca0f65_amd64 as a component of Red Hat OpenShift GitOps 1.18
- registry.redhat.io/openshift-gitops-1/gitops-operator-bundle@sha256:e8a5213454b71e952de52bd448d5f52e6de868821a23c15b71c2b46809bdd570_amd64 as a component of Red Hat OpenShift GitOps 1.18
- +12 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:9697
- externalhttps://access.redhat.com/security/cve/CVE-2026-27137
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.18/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_9697.json