Skip to main content
EPSS 0.7%top 50%

Red Hat Security Advisory: Red Hat OpenShift API for Data Protection

0
High
Published: 02/26/2026 (02/26/2026, 15:08:47 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume data, and internal container images to external backup storage. OADP enables both file system-based and snapshot-based backups for persistent volumes.

Affected software

Affected versions
>=8.4 <8.4.25>=9.0 <9.0.1>=9.2 <9.2.1>=9.4 <9.4.1>=9.6 <9.6.1=3.2Red HatRed Hat OpenShift AIRed Hat OpenShift AI 3.2amd64registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:43f56335fdb80e29853afaf5b0df3a0841fe224d8510300f7df9074a62b7acf7_amd64Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream E4S (v.9.0)Red Hat Enterprise Linux High Availability E4S (v.9.0)Red Hat Enterprise Linux ResilientStorage E4S (v.9.0)Red Hat Enterprise Linux AppStream E4S (v.9.2)Red Hat Enterprise Linux High Availability E4S (v.9.2)Red Hat Enterprise Linux Resilient Storage E4S (v.9.2)Red Hat Enterprise Linux AppStream EUS (v.9.4)Red Hat Enterprise Linux High Availability EUS (v.9.4)Red Hat Enterprise Linux Resilient Storage EUS (v.9.4)Red Hat Enterprise Linux AppStream EUS (v.9.6)srcfence-agents-0:4.10.0-86.el9_6.13.srcRed Hat Enterprise Linux Server for SAP ELS (v. 7)Red Hat Enterprise Linux Server for SAPHANA ELS (v. 7)Red Hat Enterprise Linux Server HighAvailability (v. 7 ELS)cert-manager operator for Red Hat OpenShiftcert-manager operator for Red Hat OpenShift 1.18registry.redhat.io/cert-manager/cert-manager-operator-rhel9@sha256:a7ec101b25000d25a70294ab241dfe95df032bc1af42ab2ece5fad871c1459ac_amd64Red Hat Enterprise Linux AppStream AUS (v.8.4)Red Hat Enterprise Linux High Availability AUS (v.8.4)Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)Red Hat Enterprise Linux Server ResilientStorage (v. 7 ELS)noarchRed Hat Enterprise Linux BaseOS (v. 9)python-urllib3-0:1.26.5-6.el9_7.1.srcRed Hat Enterprise Linux HighAvailability EUS EXTENSION (v.8.4)Red Hat Enterprise Linux BaseOS (v. 8)python-urllib3-0:1.24.2-9.el8_10.srcRed Hat Enterprise Linux High Availability E4S (v.8.8)Red Hat Enterprise Linux High Availability TUS (v.8.8)Red Hat Enterprise Linux High Availability E4S (v.8.6)Red Hat Enterprise Linux High Availability TUS (v.8.6)Red Hat Enterprise Linux AppStream E4S (v.8.8)Red Hat Enterprise Linux AppStream TUS (v.8.8)Red Hat Enterprise Linux AppStream AUS (v.8.6)Red Hat Enterprise Linux AppStream E4S (v.8.6)ppc64leregistry.redhat.io/rhoai/odh-model-metadata-collection-rhel9@sha256:dece7af4f170f0b0534c0c8df75428e45f1adba8943789930c72e851edb8d3ff_ppc64leRed Hat Update InfrastructureRHUI 4 for RHEL 8python-urllib3-0:2.6.3-1.el8ui.srcpython3.11-urllib3-0:1.26.12-1.el9_2.2.srcOpenShift API for Data ProtectionOpenShift API for Data Protection 1.3registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:b9c6a326e2cc6b45e5fb491c3e2b284d7f519f7decdeeacc724cd30f73a80fd3_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 18:02:49 UTC

Technical Analysis

The vulnerability identified as CVE-2025-66418 affects the urllib3 library used within the cert-manager Operator for Red Hat OpenShift and multiple Red Hat Enterprise Linux products. It is caused by an unbounded decompression chain that can result in resource exhaustion, potentially impacting system stability or availability. The issue is tracked under CWE-770 and CWE-409. Red Hat has released security advisories (RHSA-2026:2279 and RHSA-2026:1026) providing updated packages and instructions for remediation. The advisories cover affected Red Hat Enterprise Linux 8.4 variants and Red Hat OpenShift AI 3.2. No active exploitation has been reported. The vendor manages remediation through official patches, and users should follow the provided update instructions.

Potential Impact

The vulnerability can lead to resource exhaustion due to unbounded decompression chains in urllib3, which may cause denial of service or degraded performance in affected systems. This impacts Red Hat OpenShift clusters using the cert-manager Operator and Red Hat Enterprise Linux 8.4 systems utilizing the fence-agents packages. No known active exploits have been reported, but the potential for resource exhaustion poses a risk to system availability.

Mitigation Recommendations

Red Hat has released official patches addressing CVE-2025-66418. Users should apply the updated fence-agents packages and related updates for Red Hat Enterprise Linux 8.4 and Red Hat OpenShift AI 3.2 as detailed in the Red Hat advisories RHSA-2026:2279 and RHSA-2026:1026. Follow the vendor's instructions at https://access.redhat.com/articles/11258 and https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ to fully remediate the vulnerability. No additional mitigation steps are required beyond applying these official updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:2279
Cve Count
1

Threat ID: 6a160986e29bf47b50652be7

Added to database: 05/26/2026, 20:58:46 UTC

Last enriched: 08/10/2026, 18:02:49 UTC

Last updated: 09/10/2026, 22:04:10 UTC

Views: 90

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:2279https://access.redhat.com/security/updates/classification/#important2419455Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1026https://access.redhat.com/security/cve/CVE-2025-66418https://access.redhat.com/security/updates/classification/https://docs.redhat.com/en/documentation/red_hat_openshift_ai/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1027Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1329Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1330Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1332Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1331Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1336Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1701Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1337Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1338Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1041https://access.redhat.com/security/cve/CVE-2025-66471https://access.redhat.com/security/cve/CVE-2026-21441https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.htmlCanonical URLhttps://access.redhat.com/errata/RHSA-2026:1339Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1340Canonical URLhttps://access.redhat.com/errata/RHSA-2026:272324194672427726Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1087Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1254Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1702Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1485Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1546Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1674Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1693Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1676Canonical URLhttps://access.redhat.com/errata/RHSA-2026:2137https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/indexCanonical URLhttps://access.redhat.com/errata/RHSA-2026:2717Canonical URLhttps://access.redhat.com/errata/RHSA-2026:2728Canonical URLhttps://access.redhat.com/errata/RHSA-2026:3444https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/backup_and_restore/oadp-application-backup-and-restoreCanonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses