Skip to main content
EPSS 5.3%top 7.9%

Red Hat Security Advisory: Red Hat OpenShift GitOps v1.19.1 security update

0
High
Published: 01/28/2026 (01/28/2026, 12:24:36 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

An update is now available for Red Hat OpenShift GitOps. Bug Fix(es) and Enhancement(s): * GITOPS-8080 (CVE-2025-58183 openshift-gitops-1/argocd-rhel8: Unbounded allocation when parsing GNU sparse map [gitops-1.19]) * GITOPS-8083 (CVE-2025-58183 openshift-gitops-1/dex-rhel8: Unbounded allocation when parsing GNU sparse map [gitops-1.19]) * GITOPS-7849 (Cherry pick Repo Type Fix to Argo CD 3.1 stream) * GITOPS-7992 (openshift-gitops-operator-metrics-monitor ServiceMonitor is attempting to use a bearerTokenFile configuration in its endpoints definition) * GITOPS-8225 (RC 1.19.0-2 : haproxy replica remains 1 with HA upgrade) * GITOPS-8249 (Prevent argoCD from automatically refreshing to gitops repository ) * GITOPS-8411 (CVE-2025-55190 still blocking due to github.com/argoproj/argo-cd/[email protected] in gitops-rhel8:v1.18.1) * GITOPS-8535 (Show All Namespaces or Current Namespace Only option) * GITOPS-8591 (Reciving TargetDown after upgrading GitOps )

Affected software

Affected versions
<1.19.1Red HatRed Hat OpenShift GitOpsRed Hat OpenShift GitOps 1.19amd64registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:88d3d7cfa9a703b161eb6155eb959afe9ca3608214a58c11520bfda255b2adca_amd64Red Hat OpenShift GitOps 1.17registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:f218700bb266c8a829f48204a6d1584dda3868d019f1dbb7f9253b431e668ce7_amd64Red Hat OpenShift GitOps 1.15registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:b79b74a5d78853eb8021375ad077e132637cd2f88a5563b8859718f023a5368d_amd64Red Hat OpenShift GitOps 1.16registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:48eee951cbabfec9d37ba7b04b241670f745cbc20eb565288c7171a34780223b_amd64<3.2.7-r0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 21:50:17 UTC

Technical Analysis

CVE-2025-55190 is an information leak vulnerability in Red Hat OpenShift GitOps (Argo CD component) where the project details API endpoint may unintentionally expose sensitive repository credentials. An attacker must have privileges to create or have stolen an API token to exploit this vulnerability. The impact is limited to tampering with projects associated with the compromised API token and does not grant full system control. Red Hat has issued a security update in OpenShift GitOps v1.19.1 to fix this issue. Additional fixes for related issues and enhancements are included in this update. The vulnerability is tracked under CWE-522 (Insufficiently Protected Credentials) and CWE-770 (Allocation of Resources Without Limits or Throttling).

Potential Impact

The vulnerability allows an attacker with valid login credentials or a stolen API token to access sensitive repository credentials via the project details API endpoint. This can lead to unauthorized tampering with projects linked to the API token. However, it does not provide full system control or broader administrative privileges. The severity is rated as high due to the confidentiality, integrity, and availability impacts on the affected projects.

Mitigation Recommendations

A security update is available in Red Hat OpenShift GitOps version 1.19.1 that addresses this vulnerability. Users should apply this update to remediate the issue. Currently, no effective mitigations meeting Red Hat's criteria for ease of use and applicability are available. Prior to updating, ensure all previously released errata relevant to your system have been applied. Refer to Red Hat's official advisory for detailed update instructions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:1488
Cve Count
2
Additional Cves
["CVE-2025-58183"]

Threat ID: 6a16096fe29bf47b506375d6

Added to database: 05/26/2026, 20:58:23 UTC

Last enriched: 08/14/2026, 21:50:17 UTC

Last updated: 09/10/2026, 19:36:51 UTC

Views: 126

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses