RHSA-2026:9698HighCVSS 7.5
Red Hat Security Advisory: Red Hat OpenShift GitOps v1.19.3 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-27137 — crypto/x509: Incorrect enforcement of email constraints in crypto/x509
🎯 Affected products46
- Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:1c5ed08bcdd5c13ba8b98054ddc1dfdc3837d24dcd3b670bdc4ff2453fc37789_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:b1d6a23d9957dbe128ba317ed9a0c8028cbea913683bdd8557f6c4caba98d132_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:b3da9ddc02f2caa947f034e64ed37769efa04ff17c98c8b57f21871e058d150d_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:dff08eed24153cb98b9fdf25702c6edd88467516d3a750f915c2b8972a206b72_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:2bb7b0c12f869e1169b7f71bca827916e1e035df0b60d956cf976df692ff5a0b_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:411b46c6b939f0baf070a0e916df823f8dedce22163a7c5be9774724eb6949e6_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:98a3e4019e9f68050237f34cb7a89c125c317973158184fba55ace5f772cd76a_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:df066f65a2ebc5a6910e8ff41bfab5c310b3a5739ffdb60501f9941d9961213f_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:38a8d2575efdebc83519349b0bba68f72abca3c4bff4731cee24b3983252ad13_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:3aca316cc39a16b92ca20177841b5d1643e26132f16b9b16dc1b8171587e21ed_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:b8d4c24efc4d1eb910009373156f8fe1ae2c599a0dff0f278382aedd4cab9a1f_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:f130e22e260da1e96c10d791f126c1ffc8585ba663918557295f281c4c2a9c17_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:228a16b400172e8b31a8f727d700a50a3aa9a2347527be18495a12370e93ae2b_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:6b755ab049dfa8a5f89dbde3bed00275b9ff807b338b2a7ecdaefeaed83b0bbc_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:8d7aa2c0b97e86fb6d8ef542b5f6ab05bded9769d5beb4a3ae0e4dd4b77e6dae_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:cc8347691a1ad2bbcffd256a632ad6ac6768b1491af96ab2df1dbc106bf8b189_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:04673bdebda425bad1c73fa2c99e89016b90adde92ab5b18854a213099e16f99_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:83c466b8c9310f0dc498870c25d43b96ba051de4509d6134540c561b05a12d02_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:83e7e20877ca983a2f2cf64db0b9b8ac44b4979276f3d3a90cc971f04bf9affb_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:c1f0cff25f290e7e9834372bc5bb3e63aad754ae3fe13a11c502eec3f5c8a8b9_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:6d93cb87458ad8e74f330e50a6294fca765ff752c5d68815b2ab738d3faa7060_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:8f9477ae0de3e4b1d039bc6901cec348eb4d4bdde8b8b85775ddff4db2a08c1b_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:943616dc45c24ce59a6962443814dce9f4076d5bd25c041830da5e9ada2dbf1b_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:bb9a3e9293c5b5b131632a32a56b13c7093e2e9881e50d48940d2259facc3777_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:19e0b44f05c4131e6ce86ebba2626aac49c7b3dbdc4f1a403c025234ad17853d_amd64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:23837525f1a838bb9b4b456bb0a06020406c965784f3353690b5f7738007ae75_ppc64le as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:879902f60fe7a589c6fb0fde87111cd39fc058b2958ef3b24f7a919af64eef79_arm64 as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:acd235ec47951169c959d86c143e918598748f966067c6ecf339869c6d9a93c9_s390x as a component of Red Hat OpenShift GitOps 1.19
- registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:818a7de4db02d01bc27802d00564e42b4ff0b47df31083450ebe3c739bdc0cbd_s390x as a component of Red Hat OpenShift GitOps 1.19
- +16 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:9698
- externalhttps://access.redhat.com/security/cve/CVE-2026-27137
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.19/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_9698.json