Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 1.8%top 23%

Red Hat Security Advisory: Red Hat Migration Toolkit for Containers

0
High
Published: 07/20/2026 (07/20/2026, 08:34:29 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The Migration Toolkit for Containers (MTC) enables you to migrate Kubernetes resources, persistent volume data, and internal container images between OpenShift Container Platform clusters, using the MTC web console or the Kubernetes API.

Affected software

Affected versions
Red HatRed Hat Migration ToolkitRed Hat Migration Toolkit 1.8amd64registry.redhat.io/rhmtc/openshift-migration-controller-rhel8@sha256:c6c8c0043464e89cd453e08d1810f64f51beb257cdea7308bb834514458b07a1_amd64Red Hat OpenShift Service MeshRed Hat OpenShift Service Mesh 3.0registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:01b914135cc54eb935dd9329bc813a273abbb93215c97e3cc189bf1972a22bb5_amd64CryostatCryostat 4 on RHEL 9cryostat/cryostat-agent-init-rhel9@sha256:0e5ffd83db750fb85c1e6e268a6be392bf084558e9b07d29bb6b752b756f98e8_amd64Red Hat Advanced Cluster SecurityRed Hat Advanced Cluster Security 4.8registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:84f25a618b0a92a6261c08f327491f08ee482eb04f1ee46a842915fe2c5775a1_amd64Red Hat Advanced Cluster Security 4.7registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:778c08cc1634d7f7ae3ae60e4b61ea50ec21a27280311948909970a77d5fc845_amd64Red Hat OpenShift AIRed Hat OpenShift AI 2.24registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:801fd3a439df5c91a5902f4416f8edf341aa677e92891f285e5dafa21f44d8c8_amd64Red Hat Developer HubRed Hat Developer Hub 1.8registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:14e2eced22ef02862bd3208f1fbcd5e5662e8a69128116fbb295ddc48498e1f7_amd64s390xregistry.redhat.io/advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:1fd8327d82a7e694b728f64130f6110343b1dfd1a20ad44ac9f00648de74f7d7_s390xRed Hat Migration Toolkit for ContainersRed Hat Migration Toolkit for Containers 1.8

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 19:03:21 UTC

Technical Analysis

The vulnerability CVE-2025-7783 affects the Red Hat Migration Toolkit for Containers (MTC), which enables migration of Kubernetes resources, persistent volume data, and container images between OpenShift clusters. The root cause is an interpretation conflict in the node-forge library used for cryptographic operations. Specifically, attackers can craft malicious ASN.1 structures that desynchronize schema validations, resulting in bypassing cryptographic verifications and security decisions. This flaw impacts multiple Red Hat products that incorporate node-forge. Red Hat has issued a security advisory (RHSA-2026:41928) with an updated MTC version that fixes this vulnerability. The advisory references multiple related CVEs and bug reports. No active exploitation has been observed.

Potential Impact

An unauthenticated attacker can exploit this vulnerability to bypass cryptographic verification mechanisms in affected Red Hat products using node-forge. This bypass can undermine the integrity and confidentiality of security decisions, potentially allowing unauthorized actions or code execution. The impact is rated high by Red Hat due to the critical nature of cryptographic verification bypass in container migration workflows. There are no reports of active exploitation in the wild.

Mitigation Recommendations

Red Hat has released an updated version of the Migration Toolkit for Containers that addresses this vulnerability. Users should apply the latest errata and update to the fixed version of MTC as recommended in Red Hat Advisory RHSA-2026:41928. Prior to updating, ensure all previously released relevant errata are applied. No alternative mitigations are currently available that meet Red Hat's criteria for ease of use and applicability. Monitoring for official updates from Red Hat is advised.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:14919
Cve Count
3
Additional Cves
["CVE-2025-8415","CVE-2025-55163"]
Cvss Version
null

Threat ID: 6a1f4e87e29bf47b5008189b

Added to database: 06/02/2026, 21:43:35 UTC

Last enriched: 08/14/2026, 19:03:21 UTC

Last updated: 09/04/2026, 10:52:06 UTC

Views: 140

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:41928https://access.redhat.com/security/cve/CVE-2025-12816https://access.redhat.com/security/cve/CVE-2025-13465https://access.redhat.com/security/cve/CVE-2025-15284https://access.redhat.com/security/cve/CVE-2025-52881https://access.redhat.com/security/cve/CVE-2025-58183https://access.redhat.com/security/cve/CVE-2025-58754https://access.redhat.com/security/cve/CVE-2025-61726https://access.redhat.com/security/cve/CVE-2025-61729https://access.redhat.com/security/cve/CVE-2025-62718https://access.redhat.com/security/cve/CVE-2025-66031https://access.redhat.com/security/cve/CVE-2025-66418https://access.redhat.com/security/cve/CVE-2025-66471https://access.redhat.com/security/cve/CVE-2025-66506https://access.redhat.com/security/cve/CVE-2025-68121https://access.redhat.com/security/cve/CVE-2025-69223https://access.redhat.com/security/cve/CVE-2025-69227https://access.redhat.com/security/cve/CVE-2025-69228https://access.redhat.com/security/cve/CVE-2025-7783https://access.redhat.com/security/cve/CVE-2026-12143https://access.redhat.com/errata/RHSA-2025:17501https://access.redhat.com/security/cve/CVE-2025-10725https://access.redhat.com/security/cve/CVE-2025-55163https://access.redhat.com/security/cve/CVE-2025-57852https://access.redhat.com/security/updates/classification/https://docs.redhat.com/en/documentation/red_hat_openshift_ai/Canonical URLhttps://access.redhat.com/errata/RHSA-2025:14886https://access.redhat.com/security/updates/classificationCanonical URLhttps://access.redhat.com/errata/RHSA-2025:14919https://access.redhat.com/security/updates/classification/#important238195923857732388252Canonical URLhttps://access.redhat.com/errata/RHSA-2025:15771https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.8/html-single/release_notes/index#about-this-release-484_release-notes-48Canonical URLhttps://access.redhat.com/errata/RHSA-2025:20047https://catalog.redhat.com/search?gs&searchType=containers&q=rhdhhttps://developers.redhat.com/rhdh/overviewhttps://docs.redhat.com/en/documentation/red_hat_developer_hubhttps://issues.redhat.com/browse/RHDHPLAN-234https://issues.redhat.com/browse/RHIDP-8047https://issues.redhat.com/browse/RHIDP-8057Canonical URLhttps://access.redhat.com/errata/RHSA-2025:16918https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.7/html-single/release_notes/index#about-release-477_release-notes-47Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses