Skip to main content
EPSS 2.8%top 15%

Red Hat Security Advisory: Red Hat OpenShift GitOps v1.19.4 security update

0
High
Published: 05/26/2026 (05/26/2026, 14:49:30 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

An update is now available for Red Hat OpenShift GitOps. Bug Fix(es) and Enhancement(s): * GITOPS-8784 (Service-CA annotation removed from argocd-server Service during v1.12.3 -> v1.12.4 upgrade path, persists in later versions)

Affected software

Affected versions
>=1.19.0 <1.19.4Red HatRed Hat OpenShift GitOpsRed Hat OpenShift GitOps 1.19amd64registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:b6773a29fc3d9504143f9aed3438781e04b4262a4ac46d1926f2ce76c87ad0c9_amd64arm64registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:7078ad00e7f3573c36de3bd2b970d77e9d4445f810d4d65f2fb19286f4e9d89f_arm64Red Hat OpenShift Container PlatformRed Hat OpenShift Container Platform 4.17registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:7644b30ed4732df915c526f148de469c71e28ef1ad4f593cad4779d6e8eefc71_amd64Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:5875ce179ab7eb09e92a3355536ba83e534712d7362c2289ff13b9fe0be0d1bf_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 17:11:58 UTC

Technical Analysis

CVE-2026-4800 is a denial of service vulnerability in the Go crypto/x509 package used by Red Hat OpenShift GitOps. It occurs during validation of certificate chains containing a large number of policy mappings, leading to excessive CPU and memory consumption. Exploitation requires presenting a specially crafted, yet trusted, certificate chain, which implies prior compromise of a trusted root certificate. Red Hat has released an update to OpenShift GitOps v1.19.4 that addresses this and other issues, including removal of a persistent Service-CA annotation introduced in earlier versions. The advisory references multiple CVEs and provides detailed remediation instructions.

Potential Impact

The vulnerability can cause denial of service by consuming excessive platform resources during certificate validation, potentially degrading or disrupting service availability. Since exploitation requires a trusted certificate chain, the risk is limited to scenarios where an attacker has compromised a trusted root certificate. No confidentiality or integrity impacts are reported. No known exploits in the wild have been observed. The update mitigates these issues by fixing the inefficient validation process and related bugs.

Mitigation Recommendations

An official security update is available in Red Hat OpenShift GitOps version 1.19.4. Users should apply this update after ensuring all previously released errata are applied. No alternative mitigations meeting Red Hat's criteria are currently available. The vendor manages remediation through this update, and no additional action is required beyond applying the patch.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:20943
Cve Count
5
Additional Cves
["CVE-2026-32281","CVE-2026-33186","CVE-2026-33487","CVE-2026-42880"]

Threat ID: 6a160954e29bf47b50619b0b

Added to database: 05/26/2026, 20:57:56 UTC

Last enriched: 08/17/2026, 17:11:58 UTC

Last updated: 09/14/2026, 10:01:31 UTC

Views: 162

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:20943https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/cve/CVE-2026-33186https://access.redhat.com/security/cve/CVE-2026-33487https://access.redhat.com/security/cve/CVE-2026-42880https://access.redhat.com/security/cve/CVE-2026-4800https://access.redhat.com/security/updates/classification/https://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.19/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:29795https://access.redhat.com/security/cve/CVE-2026-35469https://access.redhat.com/security/cve/CVE-2026-44293https://access.redhat.com/security/cve/CVE-2026-6322https://access.redhat.com/security/cve/CVE-2026-9277Canonical URLhttps://access.redhat.com/errata/RHSA-2026:24762https://access.redhat.com/security/updates/classification/#importanthttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updateshttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade244855324518672452450245349624561792456336245633824563392456735245743224588562464121Canonical URLhttps://access.redhat.com/errata/RHSA-2026:42078https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/release_notes/patch_releaseshttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading245633324609272461624246658224666842467822247715424807562480757248076124853792487937248793824879422487943https://access.redhat.com/errata/RHSA-2026:60023https://access.redhat.com/security/cve/CVE-2026-25681https://access.redhat.com/security/cve/CVE-2026-33814https://access.redhat.com/security/cve/CVE-2026-34986https://access.redhat.com/security/cve/CVE-2026-39820https://access.redhat.com/security/cve/CVE-2026-42499https://access.redhat.com/security/cve/CVE-2026-42504https://access.redhat.com/security/cve/CVE-2026-46597https://access.redhat.com/security/cve/CVE-2026-49332https://access.redhat.com/security/cve/CVE-2026-50236https://access.redhat.com/security/cve/CVE-2026-50237Canonical URLhttps://access.redhat.com/errata/RHSA-2026:36621https://access.redhat.com/security/cve/CVE-2026-12151https://access.redhat.com/security/cve/CVE-2026-26996https://access.redhat.com/security/cve/CVE-2026-29063https://access.redhat.com/security/cve/CVE-2026-9697Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses