Skip to main content
EPSS 0.3%top 79%

Red Hat Security Advisory: cert-manager Operator for Red Hat OpenShift 1.18.1

0
High
Published: 01/22/2026 (01/22/2026, 11:34:41 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The cert-manager Operator for Red Hat OpenShift builds on top of Kubernetes, introducing certificate authorities and certificates as first-class resource types in the Kubernetes API. This makes it possible to provide certificates-as-a-service to developers working within your Kubernetes cluster.

Affected software

Affected versions
>=1.18.0 <=1.18.1Red Hatcert-manager operator for Red Hat OpenShiftcert-manager operator for Red Hat OpenShift 1.18amd64registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:3ca7fb070c05efc25fe53af6fc922875ecb9d11943d3c243b2840d7ca2b1aa33_amd64registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:09c857f0c20721d6b447f5f567182befc1ca6157128225849117a5c830feab23_amd64Red Hat Hardened Imagesaarch64golang-fips1-25-main@aarch64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 18:03:20 UTC

Technical Analysis

The cert-manager Operator for Red Hat OpenShift extends Kubernetes by managing certificate authorities and certificates as API resources. Multiple CVEs affect versions 1.18.0 through 1.18.1, including CVE-2025-61727, which is a flaw in the Go standard library's crypto/x509 package. This flaw allows certificate validation bypass via excluded subdomain constraints not restricting wildcard SANs in leaf certificates. An attacker with a wildcard SAN leaf certificate can exploit this to bypass validation and potentially perform man-in-the-middle attacks. Red Hat rates this vulnerability as moderate in severity but the overall advisory rates the set of vulnerabilities as high severity. No known exploits in the wild have been reported. The advisory does not list any fixed versions or patches but notes that automatic operator upgrades will apply the fix if enabled.

Potential Impact

An attacker who obtains a leaf certificate with a wildcard SAN can bypass certificate validation constraints that exclude certain subdomains, allowing them to impersonate trusted hosts within the Kubernetes cluster. This can lead to man-in-the-middle attacks where the attacker intercepts or modifies communications. The impact includes potential spoofing of trusted entities and unauthorized access to sensitive data. However, the attacker does not gain full control over all data, limiting the scope of the attack. The vulnerabilities affect the integrity and authentication mechanisms of the cert-manager Operator environment.

Mitigation Recommendations

Red Hat does not currently provide a direct patch for these vulnerabilities in the cert-manager Operator for OpenShift 1.18.0 through 1.18.1. However, if the operator's installation uses the default 'Automatic' approval policy, upgrades to fixed operator versions will be applied automatically. For installations with 'Manual' approval policy, administrators must manually approve the operator upgrade to receive the fix. Users should ensure all previously released errata are applied before upgrading. Monitoring Red Hat advisories for updates and following the official upgrade instructions at https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.html is recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:0990
Cve Count
5
Additional Cves
["CVE-2025-61729","CVE-2025-66418","CVE-2025-66471","CVE-2026-21441"]

Threat ID: 6a16096ae29bf47b50630265

Added to database: 05/26/2026, 20:58:18 UTC

Last enriched: 08/10/2026, 18:03:20 UTC

Last updated: 09/10/2026, 19:36:51 UTC

Views: 96

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses