Skip to main content
EPSS 0.8%top 46%

Red Hat Security Advisory: osbuild-composer security update

0
High
Published: 05/20/2026 (05/20/2026, 03:59:13 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

A service for building customized OS artifacts, such as VM images and OSTree commits, that uses osbuild under the hood. Besides building images for local usage, it can also upload images directly to cloud. It is compatible with composer-cli and cockpit-composer clients. Security Fix(es): * crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121) * net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected software

Affected versions
Red HatRed Hat OpenShift BuildsRed Hat OpenShift Builds 1.7.3amd64registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:5008dcb0428a0837b9abd827963e7008c8e16af8cfcbd432421286fca63fe714_amd64Red Hat OpenShift Container PlatformRed Hat OpenShift Container Platform 4.14registry.redhat.io/openshift4/ose-cluster-autoscaler@sha256:19aa32e6fa4259d09fb667a7d226a6095084a92dc1120984b00e794029162d08_amd64Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream EUS (v. 10.0)srcosbuild-composer-0:134.1-6.el10_0.srcRed Hat Enterprise Linux AppStream EUS (v.9.6)osbuild-composer-0:132.2-6.el9_6.srcRed Hat Enterprise Linux AppStream (v. 10)go-fdo-server-0:1.0.1-2.el10_2.srcRed Hat Enterprise Linux AppStream E4S (v.9.4)aarch64go-toolset-0:1.25.9-1.el9_4.aarch64Red Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:d203121bfb414569dfbd7af312a57241b1fde72a38d29b6ab2e78b2d69918e2e_amd64Red Hat OpenShift Container Platform 4.15registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:5100b9531f142f9772229703e1ab81755a1f023b5f73d30d294ecac65cceef4c_amd64OpenShift API for Data ProtectionOpenShift API for Data Protection 1.4registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:ad53c993e7afabb98c66f25e8093851fbca592f030ed9c6e32056492958162d0_amd64registry.redhat.io/openshift4/ose-cluster-autoscaler@sha256:b109e0a865754172ec6e14a26bb124d9749a53c033b28449720e53253484f9d4_amd64Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:303943623f1f9d457998502ef24c5a322aa64542035c0aae39d925b6a281eefa_amd64grafana-0:9.2.10-27.el9_4.srcRed Hat Enterprise Linux AppStream E4S (v.9.2)grafana-pcp-0:5.1.1-5.el9_2.1.srcgrafana-pcp-0:5.1.1-8.el9_4.srcgrafana-0:9.0.9-12.el9_2.srcregistry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:6812e1b00a9e7638b5fa969424982877ec1e29154d10b869b04d3b5e720d736f_amd64Red Hat OpenShift Container Platform 4.12registry.redhat.io/openshift4/ose-cluster-autoscaler@sha256:a0bb51b0f2c81216eba98f739cc660790f2ad8ee4bc3dc02206a62773aa9bc5f_amd64Red Hat OpenShift Container Platform 4.18ppc64leregistry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:fca71811c3e493fab2b1a9ab55d34f61c3a4cb90f81b26e611faa3e3a56520dc_ppc64leRed Hat OpenShift EnterpriseRed Hat OpenShift Container Platform 4.17

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 19:51:52 UTC

Technical Analysis

The vulnerability (CVE-2025-68121) exists in the crypto/tls component used by Red Hat products such as OpenShift Container Platform. It occurs during TLS session resumption when the certificate authority (CA) settings are changed between the initial and resumed handshakes. This can cause the TLS implementation to incorrectly validate certificates, allowing an attacker to bypass certificate validation and establish unauthorized connections. The flaw requires specific conditions to be exploitable, including runtime changes to CA settings and TLS session resumption. Red Hat has assigned a CVSS v3 score of 7.4 (high) reflecting the complexity and impact limited to confidentiality and integrity. The vulnerability does not affect system availability and does not have known exploits in the wild. Red Hat has released security updates and advisories for affected products, including OpenShift Container Platform 4.14.68 and related container images.

Potential Impact

An attacker who can manipulate TLS session resumption and CA settings could bypass certificate validation, potentially allowing unauthorized connections that should have been rejected. This leads to an authentication bypass affecting confidentiality and integrity of TLS communications. The impact is limited to the crypto/tls component and does not affect system availability. Exploitation requires a controlled setup and is not straightforward. There are no known exploits in the wild at this time.

Mitigation Recommendations

Red Hat has released official security updates addressing this vulnerability. Users of affected Red Hat products, including OpenShift Container Platform 4.14, should apply the updates provided in Red Hat Advisory RHSA-2026:28893 and related errata. Instructions for upgrading clusters and applying asynchronous errata updates are available in Red Hat documentation. No additional mitigations are specified or required beyond applying the official fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:19475
Cve Count
2
Additional Cves
["CVE-2026-25679"]
State
PUBLISHED

Threat ID: 6a16097fe29bf47b5064bc62

Added to database: 05/26/2026, 20:58:39 UTC

Last enriched: 08/14/2026, 19:51:52 UTC

Last updated: 09/15/2026, 01:45:45 UTC

Views: 147

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:28893https://access.redhat.com/security/cve/CVE-2025-68121https://access.redhat.com/security/cve/CVE-2026-1784https://access.redhat.com/security/cve/CVE-2026-25679https://access.redhat.com/security/cve/CVE-2026-27143https://access.redhat.com/security/cve/CVE-2026-27144https://access.redhat.com/security/cve/CVE-2026-29063https://access.redhat.com/security/cve/CVE-2026-33186https://access.redhat.com/security/cve/CVE-2026-35172https://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:29854https://access.redhat.com/security/cve/CVE-2026-27137https://access.redhat.com/security/cve/CVE-2026-32280https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/cve/CVE-2026-32282https://access.redhat.com/security/cve/CVE-2026-33747https://access.redhat.com/security/cve/CVE-2026-33748https://access.redhat.com/security/cve/CVE-2026-33810https://access.redhat.com/security/cve/CVE-2026-34986https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/backup_and_restore/oadp-application-backup-and-restoreCanonical URLhttps://access.redhat.com/errata/RHSA-2026:10158https://access.redhat.com/security/cve/CVE-2026-33211https://docs.redhat.com/en/documentation/builds_for_red_hat_openshift/1.7Canonical URLhttps://access.redhat.com/errata/RHSA-2026:28964https://access.redhat.com/security/cve/CVE-2026-44486https://access.redhat.com/security/cve/CVE-2026-44487https://access.redhat.com/security/cve/CVE-2026-44488https://access.redhat.com/security/cve/CVE-2026-44492https://access.redhat.com/security/cve/CVE-2026-44494https://access.redhat.com/security/cve/CVE-2026-44495https://access.redhat.com/security/cve/CVE-2026-44496Canonical URLhttps://access.redhat.com/errata/RHSA-2026:19475https://access.redhat.com/security/updates/classification/#important24371112445356Canonical URLhttps://access.redhat.com/errata/RHSA-2026:17686https://access.redhat.com/security/updates/classification/#moderateCanonical URLhttps://access.redhat.com/errata/RHSA-2026:22141245633324563362456339Canonical URLhttps://access.redhat.com/errata/RHSA-2026:480362456338Canonical URLhttps://access.redhat.com/errata/RHSA-2026:4771224563402456342RHEL-178854Canonical URLhttps://access.redhat.com/errata/RHSA-2026:3842Canonical URLhttps://access.redhat.com/errata/RHSA-2026:47714RHEL-191668Canonical URLhttps://access.redhat.com/errata/RHSA-2026:6552Canonical URLhttps://access.redhat.com/errata/RHSA-2026:47719RHEL-182118Canonical URLhttps://access.redhat.com/errata/RHSA-2026:47721RHEL-191711Canonical URLhttps://access.redhat.com/errata/RHSA-2026:47716RHEL-191673Canonical URLhttps://access.redhat.com/errata/RHSA-2026:47722RHEL-191710Canonical URLhttps://access.redhat.com/errata/RHSA-2026:47910Canonical URLhttps://access.redhat.com/errata/RHSA-2026:54603https://access.redhat.com/security/cve/CVE-2026-27145https://access.redhat.com/security/cve/CVE-2026-33811https://access.redhat.com/security/cve/CVE-2026-46597https://access.redhat.com/security/cve/CVE-2026-59869Canonical URLhttps://access.redhat.com/errata/RHSA-2026:56789https://access.redhat.com/security/cve/CVE-2026-16242https://access.redhat.com/security/cve/CVE-2026-26996https://access.redhat.com/security/cve/CVE-2026-39820https://access.redhat.com/security/cve/CVE-2026-42154https://access.redhat.com/security/cve/CVE-2026-42499https://access.redhat.com/security/cve/CVE-2026-4800https://access.redhat.com/security/cve/CVE-2026-50236https://access.redhat.com/security/cve/CVE-2026-50237Canonical URLhttps://access.redhat.com/errata/RHSA-2026:56854https://access.redhat.com/security/cve/CVE-2026-27140https://access.redhat.com/security/cve/CVE-2026-33814https://access.redhat.com/security/cve/CVE-2026-9277Canonical URLhttps://access.redhat.com/errata/RHSA-2026:49509Canonical URLhttps://access.redhat.com/errata/RHSA-2026:49600Canonical URLhttps://access.redhat.com/errata/RHSA-2026:56913Canonical URLhttps://access.redhat.com/errata/RHSA-2026:56855Canonical URLhttps://access.redhat.com/errata/RHSA-2026:56912https://access.redhat.com/security/cve/CVE-2026-49332Canonical URLhttps://access.redhat.com/errata/RHSA-2026:59833Canonical URLhttps://access.redhat.com/errata/RHSA-2026:57488https://access.redhat.com/security/cve/CVE-2026-42504Canonical URLhttps://access.redhat.com/errata/RHSA-2026:600182467809246782024678222484204Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses