Skip to main content
EPSS 0.4%top 71%

Red Hat Security Advisory: Red Hat Web Terminal Operator 1.16.1 release.

0
High
Published: 07/20/2026 (07/20/2026, 13:55:42 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The Web Terminal provides a way to access a fully in-browser terminal emulator within the OpenShift Console. Command-line tools for interacting with the OpenShift cluster are pre-installed.

Affected software

Affected versions
>=3.0.0 <=3.3Red HatRed Hat Web TerminalRed Hat Web Terminal 1.16amd64registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:365e1253b8da2ba88ec97ec5b074d16ac46b31fd7eba3baad6587ce8959b11bf_amd64Red Hat Trusted Artifact SignerRed Hat Trusted Artifact Signer 1.3registry.redhat.io/rhtas/cosign-rhel9@sha256:ce13481894c8221aac0eb0558a940038ef490433339199d07687fb19521dae67_amd64Red Hat OpenShift Service MeshRed Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:7852143b4d381db16057dd3e440e5ae9c4e10995753618472e5e42baa7f1586c_amd64Red Hat OpenShift Service Mesh 3.1registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:918dc1bb66e24f9c8a56e32c6dfb4dabbd596565ca6025c1e0306ec9a1353912_amd64Red Hat OpenShift GitOpsRed Hat OpenShift GitOps 1.2registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:4fc7f450ed27f228e9f3316c3132137b3afe7cf50a305e4dcaefd49f90a85117_amd64Red Hat OpenShift Service Mesh 3.0registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:ca9ef5694c6fb038a38b7f76f03501e5d094af381fad483d49518dd156a001d7_amd64Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:e4e55c3b1e398a962cbde38dd30260c77514d97e558028e0991f4a57bcb8d0be_amd64Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream EUS (v. 10.0)srcosbuild-composer-0:134.1-8.el10_0.srcRed Hat Enterprise Linux AppStream (v. 10)golang-github-openprinting-ipp-usb-0:0.9.27-7.el10_2.1.srcRed Hat Enterprise Linux AppStream EUS (v.9.6)osbuild-composer-0:132.2-8.el9_6.srcDevWorkspace OperatorDevWorkspace Operator 0.42registry.redhat.io/devworkspace/devworkspace-rhel9-operator@sha256:273e029b1618235c7c4ea103d09da99dac8d2803c9be4b5754f1f251563fce27_amd64MicrosoftAzure Linux2.0CBL Mariner 2.03.0Red Hat OpenShift GitOps 1.20

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 23:44:02 UTC

Technical Analysis

CVE-2026-32281 is a denial of service vulnerability in the Go crypto/x509 package caused by inefficient validation of certificate chains containing a large number of policy mappings. This flaw leads to excessive resource consumption during validation, potentially causing performance degradation or denial of service in applications relying on this package. Exploitation requires a specially crafted certificate chain that is trusted, implying the attacker must have control over a trusted root certificate. Red Hat products using this Go package are affected, including Red Hat OpenShift Service Mesh and others. Red Hat has rated the impact as moderate and currently does not provide a mitigation that meets its standards. The vulnerability is tracked under CWE-1050 (Excessive Platform Resource Consumption within a Loop).

Potential Impact

The vulnerability can cause denial of service by consuming excessive CPU and memory resources during certificate chain validation. This can degrade performance or cause unavailability of systems or applications performing such validation. No confidentiality, integrity, or privilege impacts are reported. Exploitation requires a trusted certificate chain, meaning the attacker must have compromised a trusted certificate authority or root certificate.

Mitigation Recommendations

Red Hat currently does not provide a mitigation that meets its criteria for ease of use, deployment, applicability, or stability. Users are advised to monitor Red Hat advisories for updates. Since exploitation requires a trusted certificate chain, maintaining strict control over trusted certificate authorities and monitoring for compromised certificates is recommended. Red Hat Product Security continues to monitor the situation and may provide fixes or mitigations in future updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:20460
Cve Count
1
State
PUBLISHED

Threat ID: 6a160973e29bf47b5063ccb7

Added to database: 05/26/2026, 20:58:27 UTC

Last enriched: 08/14/2026, 23:44:02 UTC

Last updated: 09/13/2026, 22:01:33 UTC

Views: 157

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:20455https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/updates/classificationhttps://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:24482https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/indexhttps://access.redhat.com/security/cve/CVE-2026-32282https://access.redhat.com/security/cve/CVE-2026-33815https://access.redhat.com/security/cve/CVE-2026-33816https://access.redhat.com/security/cve/CVE-2026-34986Canonical URLhttps://access.redhat.com/errata/RHSA-2026:26054https://access.redhat.com/security/updates/classification/#important24554702456333Canonical URLhttps://access.redhat.com/errata/RHSA-2026:36808https://access.redhat.com/security/cve/CVE-2026-39821https://access.redhat.com/security/cve/CVE-2026-39828https://access.redhat.com/security/cve/CVE-2026-39829https://access.redhat.com/security/cve/CVE-2026-39830https://access.redhat.com/security/cve/CVE-2026-42508https://access.redhat.com/security/cve/CVE-2026-46595https://redhat.atlassian.net/browse/CRW-11515Canonical URLhttps://access.redhat.com/errata/RHSA-2026:20947https://access.redhat.com/security/cve/CVE-2026-42880https://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.20/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:20456Canonical URLhttps://access.redhat.com/errata/RHSA-2026:20457Canonical URLhttps://access.redhat.com/errata/RHSA-2026:20460Canonical URLhttps://access.redhat.com/errata/RHSA-2026:27740https://access.redhat.com/security/updates/classification/#moderateCanonical URLhttps://access.redhat.com/errata/RHSA-2026:42048https://access.redhat.com/security/cve/CVE-2026-33811https://access.redhat.com/security/cve/CVE-2026-42504https://redhat.atlassian.net/browse/WTO-411https://redhat.atlassian.net/browse/WTO-422https://redhat.atlassian.net/browse/WTO-426https://redhat.atlassian.net/browse/WTO-435https://redhat.atlassian.net/browse/WTO-451Canonical URLhttps://access.redhat.com/errata/RHSA-2026:27711Canonical URLhttps://access.redhat.com/errata/RHSA-2026:22299Canonical URLhttps://access.redhat.com/errata/RHSA-2026:43651https://access.redhat.com/security/cve/CVE-2026-39892https://docs.redhat.com/en/documentation/red_hat_enterprise_linux_ai/3.3/html/release_notes/rhelai-33-stable-release-notes_release-noteshttps://www.redhat.com/en/technologies/linux-platforms/enterprise-linux/aiCanonical URLhttps://access.redhat.com/errata/RHSA-2026:43670Canonical URLhttps://access.redhat.com/errata/RHSA-2026:43851Canonical URLhttps://access.redhat.com/errata/RHSA-2026:43853Canonical URLhttps://access.redhat.com/errata/RHSA-2026:43854Canonical URLhttps://access.redhat.com/errata/RHSA-2026:43855Canonical URLCVE-2026-32281 Inefficient policy validation in crypto/x509 - VEXMicrosoft Support LifecycleCommon Vulnerability Scoring SystemSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses