Red Hat Security Advisory: Red Hat OpenShift GitOps v1.19.1 security update
An update is now available for Red Hat OpenShift GitOps. Bug Fix(es) and Enhancement(s): * GITOPS-8080 (CVE-2025-58183 openshift-gitops-1/argocd-rhel8: Unbounded allocation when parsing GNU sparse map [gitops-1.19]) * GITOPS-8083 (CVE-2025-58183 openshift-gitops-1/dex-rhel8: Unbounded allocation when parsing GNU sparse map [gitops-1.19]) * GITOPS-7849 (Cherry pick Repo Type Fix to Argo CD 3.1 stream) * GITOPS-7992 (openshift-gitops-operator-metrics-monitor ServiceMonitor is attempting to use a bearerTokenFile configuration in its endpoints definition) * GITOPS-8225 (RC 1.19.0-2 : haproxy replica remains 1 with HA upgrade) * GITOPS-8249 (Prevent argoCD from automatically refreshing to gitops repository ) * GITOPS-8411 (CVE-2025-55190 still blocking due to github.com/argoproj/argo-cd/[email protected] in gitops-rhel8:v1.18.1) * GITOPS-8535 (Show All Namespaces or Current Namespace Only option) * GITOPS-8591 (Reciving TargetDown after upgrading GitOps )
AI Analysis
Technical Summary
CVE-2025-55190 is an information leak vulnerability in Red Hat OpenShift GitOps (Argo CD component) where the project details API endpoint may unintentionally expose sensitive repository credentials. An attacker must have privileges to create or have stolen an API token to exploit this vulnerability. The impact is limited to tampering with projects associated with the compromised API token and does not grant full system control. Red Hat has issued a security update in OpenShift GitOps v1.19.1 to fix this issue. Additional fixes for related issues and enhancements are included in this update. The vulnerability is tracked under CWE-522 (Insufficiently Protected Credentials) and CWE-770 (Allocation of Resources Without Limits or Throttling).
Potential Impact
The vulnerability allows an attacker with valid login credentials or a stolen API token to access sensitive repository credentials via the project details API endpoint. This can lead to unauthorized tampering with projects linked to the API token. However, it does not provide full system control or broader administrative privileges. The severity is rated as high due to the confidentiality, integrity, and availability impacts on the affected projects.
Mitigation Recommendations
A security update is available in Red Hat OpenShift GitOps version 1.19.1 that addresses this vulnerability. Users should apply this update to remediate the issue. Currently, no effective mitigations meeting Red Hat's criteria for ease of use and applicability are available. Prior to updating, ensure all previously released errata relevant to your system have been applied. Refer to Red Hat's official advisory for detailed update instructions.
Red Hat Security Advisory: Red Hat OpenShift GitOps v1.19.1 security update
Description
An update is now available for Red Hat OpenShift GitOps. Bug Fix(es) and Enhancement(s): * GITOPS-8080 (CVE-2025-58183 openshift-gitops-1/argocd-rhel8: Unbounded allocation when parsing GNU sparse map [gitops-1.19]) * GITOPS-8083 (CVE-2025-58183 openshift-gitops-1/dex-rhel8: Unbounded allocation when parsing GNU sparse map [gitops-1.19]) * GITOPS-7849 (Cherry pick Repo Type Fix to Argo CD 3.1 stream) * GITOPS-7992 (openshift-gitops-operator-metrics-monitor ServiceMonitor is attempting to use a bearerTokenFile configuration in its endpoints definition) * GITOPS-8225 (RC 1.19.0-2 : haproxy replica remains 1 with HA upgrade) * GITOPS-8249 (Prevent argoCD from automatically refreshing to gitops repository ) * GITOPS-8411 (CVE-2025-55190 still blocking due to github.com/argoproj/argo-cd/[email protected] in gitops-rhel8:v1.18.1) * GITOPS-8535 (Show All Namespaces or Current Namespace Only option) * GITOPS-8591 (Reciving TargetDown after upgrading GitOps )
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-55190 is an information leak vulnerability in Red Hat OpenShift GitOps (Argo CD component) where the project details API endpoint may unintentionally expose sensitive repository credentials. An attacker must have privileges to create or have stolen an API token to exploit this vulnerability. The impact is limited to tampering with projects associated with the compromised API token and does not grant full system control. Red Hat has issued a security update in OpenShift GitOps v1.19.1 to fix this issue. Additional fixes for related issues and enhancements are included in this update. The vulnerability is tracked under CWE-522 (Insufficiently Protected Credentials) and CWE-770 (Allocation of Resources Without Limits or Throttling).
Potential Impact
The vulnerability allows an attacker with valid login credentials or a stolen API token to access sensitive repository credentials via the project details API endpoint. This can lead to unauthorized tampering with projects linked to the API token. However, it does not provide full system control or broader administrative privileges. The severity is rated as high due to the confidentiality, integrity, and availability impacts on the affected projects.
Mitigation Recommendations
A security update is available in Red Hat OpenShift GitOps version 1.19.1 that addresses this vulnerability. Users should apply this update to remediate the issue. Currently, no effective mitigations meeting Red Hat's criteria for ease of use and applicability are available. Prior to updating, ensure all previously released errata relevant to your system have been applied. Refer to Red Hat's official advisory for detailed update instructions.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:1488
- Cve Count
- 2
- Additional Cves
- ["CVE-2025-58183"]
Threat ID: 6a16096fe29bf47b506375d6
Added to database: 05/26/2026, 20:58:23 UTC
Last enriched: 08/14/2026, 21:50:17 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 126
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.