RHSA-2026:9699HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift GitOps v1.20.2 security update

Published
April 22, 2026
Last Modified
August 10, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-27137 — crypto/x509: Incorrect enforcement of email constraints in crypto/x509

🎯 Affected products42

  • Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:1a8c1669907826bf3f711845c6d4833b2e2c5c4807bada9797b9b0d6397955b7_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:1eb9a401a5e48ee2536b8d869b23ec28e10452d37160740db3a09dd7f2c9e357_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:1f376f53aa7d80bf48b61314480596b4837a9c80a0bbbefb428dc24ad74a6126_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:322f13074a5f64ec486e52416112a4ce63c6fce9c21443b9909343f1391613b7_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:09708d69743cbc7981ffa823dbdc782b0fac0b577ad6cecc4b875dd712a0c6dc_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:46c6c393d217df1c645c06d0da7ac1e82defc4ee1d773b6e288c976cdfaf1f89_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:b7e423bf7fde922a1d8fe4adf6f5205fc4908881f496e6ebd05db0b5f890d35c_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-agent-rhel9@sha256:f3b25a4b791a6d75c2bb7fa156fa5796ca0ef7e3520c432cd1e0ee094b0b44ca_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:4df95769cab0fd8fdc88f79857a7ace2fd0183fdc7ace73db480aa9de0d2d0af_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:96b8cc9a32104c7262aabc79dc01489640378717cd75d33c0aaca165ff193b2e_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:a87ae94bb4eeaf8e00e5b60639ce8a74af2fa74d5312f1586db65ac2e7e3915e_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel9@sha256:ddd9d15f0962e166d5e2ca0797137a135f34c558a5a51ac85a173f245d763625_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:13348eb0e7ca8a4517becd8f6feae39f26bca07e47568699c153747568f89c3e_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:8b19c499ebb9feeb664ff3721bdc2170fd62a21cc9f5c84d9ff10cd0a71030e7_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:9933d9dfafd4c1085a58e305b187386b3ea3f751a483c811a81b7f3ffd31c738_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel9@sha256:fde967c5f4e625ad901ff3635f7a9cd0e9db64dfff9083618e3d793e21e8488f_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:627f071531fb4da783c4f231fa3afd26d9eb9a56dc51b5d55a742f167b36d2f9_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:65049e2c8984f2f08c05838a407b4641285c956c440f700225bdbf67cf03c8bc_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:8596b4e5df8abf7771e6da9920d25186facd7bef39dc553c1e479b3ef1a9e8cd_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:c7fc5b1653c5d8175d480481d44e797aa843a10a4eae753a7eb70a5871540ed8_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:1bbc1efa6478d85935146b7c50217204094e0c07a3d096f353567cc4aec7b7af_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:26192e97d753181a1b7cb7baf0ec130c1592151c9a46c1940c42e80267df2486_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:c01ac978ee2e58f675e45b39d13a643ceef4fb89cef6438a5be4a2bc3a1c6efa_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/console-plugin-rhel9@sha256:e0d9a33cca85c936439e04862ecec780554cf34e9c6df7f62497595d61e8c1e8_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:0882d236e8887a0467687195620419c72c5064ca518b9f54d7a30dadbcc49726_s390x as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:a3996e99a9ebe783373b78f352e5c77970e66546e888bce3bc9a02594bd37ad3_ppc64le as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:b61518708f23cf947a447823c7747167259faddbd8032a3c8596c8fa9d5b84af_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/dex-rhel9@sha256:feaaf37afd8ccab9460c39606164fbc93cdc4d60eab68e5809465e9aa484e0bf_arm64 as a component of Red Hat OpenShift GitOps 1.20
  • registry.redhat.io/openshift-gitops-1/gitops-operator-bundle@sha256:247a54db35e184702d9c1d6f83cd9e3669f8aae48bd0eeaecdbeeda6176c525f_amd64 as a component of Red Hat OpenShift GitOps 1.20
  • +12 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (5)