Red Hat Security Advisory: cert-manager Operator for Red Hat OpenShift 1.18.1
The cert-manager Operator for Red Hat OpenShift builds on top of Kubernetes, introducing certificate authorities and certificates as first-class resource types in the Kubernetes API. This makes it possible to provide certificates-as-a-service to developers working within your Kubernetes cluster.
AI Analysis
Technical Summary
The cert-manager Operator for Red Hat OpenShift extends Kubernetes by managing certificate authorities and certificates as API resources. Multiple CVEs affect versions 1.18.0 through 1.18.1, including CVE-2025-61727, which is a flaw in the Go standard library's crypto/x509 package. This flaw allows certificate validation bypass via excluded subdomain constraints not restricting wildcard SANs in leaf certificates. An attacker with a wildcard SAN leaf certificate can exploit this to bypass validation and potentially perform man-in-the-middle attacks. Red Hat rates this vulnerability as moderate in severity but the overall advisory rates the set of vulnerabilities as high severity. No known exploits in the wild have been reported. The advisory does not list any fixed versions or patches but notes that automatic operator upgrades will apply the fix if enabled.
Potential Impact
An attacker who obtains a leaf certificate with a wildcard SAN can bypass certificate validation constraints that exclude certain subdomains, allowing them to impersonate trusted hosts within the Kubernetes cluster. This can lead to man-in-the-middle attacks where the attacker intercepts or modifies communications. The impact includes potential spoofing of trusted entities and unauthorized access to sensitive data. However, the attacker does not gain full control over all data, limiting the scope of the attack. The vulnerabilities affect the integrity and authentication mechanisms of the cert-manager Operator environment.
Mitigation Recommendations
Red Hat does not currently provide a direct patch for these vulnerabilities in the cert-manager Operator for OpenShift 1.18.0 through 1.18.1. However, if the operator's installation uses the default 'Automatic' approval policy, upgrades to fixed operator versions will be applied automatically. For installations with 'Manual' approval policy, administrators must manually approve the operator upgrade to receive the fix. Users should ensure all previously released errata are applied before upgrading. Monitoring Red Hat advisories for updates and following the official upgrade instructions at https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.html is recommended.
Red Hat Security Advisory: cert-manager Operator for Red Hat OpenShift 1.18.1
Description
The cert-manager Operator for Red Hat OpenShift builds on top of Kubernetes, introducing certificate authorities and certificates as first-class resource types in the Kubernetes API. This makes it possible to provide certificates-as-a-service to developers working within your Kubernetes cluster.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The cert-manager Operator for Red Hat OpenShift extends Kubernetes by managing certificate authorities and certificates as API resources. Multiple CVEs affect versions 1.18.0 through 1.18.1, including CVE-2025-61727, which is a flaw in the Go standard library's crypto/x509 package. This flaw allows certificate validation bypass via excluded subdomain constraints not restricting wildcard SANs in leaf certificates. An attacker with a wildcard SAN leaf certificate can exploit this to bypass validation and potentially perform man-in-the-middle attacks. Red Hat rates this vulnerability as moderate in severity but the overall advisory rates the set of vulnerabilities as high severity. No known exploits in the wild have been reported. The advisory does not list any fixed versions or patches but notes that automatic operator upgrades will apply the fix if enabled.
Potential Impact
An attacker who obtains a leaf certificate with a wildcard SAN can bypass certificate validation constraints that exclude certain subdomains, allowing them to impersonate trusted hosts within the Kubernetes cluster. This can lead to man-in-the-middle attacks where the attacker intercepts or modifies communications. The impact includes potential spoofing of trusted entities and unauthorized access to sensitive data. However, the attacker does not gain full control over all data, limiting the scope of the attack. The vulnerabilities affect the integrity and authentication mechanisms of the cert-manager Operator environment.
Mitigation Recommendations
Red Hat does not currently provide a direct patch for these vulnerabilities in the cert-manager Operator for OpenShift 1.18.0 through 1.18.1. However, if the operator's installation uses the default 'Automatic' approval policy, upgrades to fixed operator versions will be applied automatically. For installations with 'Manual' approval policy, administrators must manually approve the operator upgrade to receive the fix. Users should ensure all previously released errata are applied before upgrading. Monitoring Red Hat advisories for updates and following the official upgrade instructions at https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.html is recommended.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:0990
- Cve Count
- 5
- Additional Cves
- ["CVE-2025-61729","CVE-2025-66418","CVE-2025-66471","CVE-2026-21441"]
Threat ID: 6a16096ae29bf47b50630265
Added to database: 05/26/2026, 20:58:18 UTC
Last enriched: 08/10/2026, 18:03:20 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 96
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.