Red Hat Security Advisory: Red Hat OpenShift GitOps v1.18.1 security update
An update is now available for Red Hat OpenShift GitOps. Bug Fix(es) and Enhancement(s): * GITOPS-7606 (ApplicationSet: Bitbucket SCM/PR generator leaks HTTP connections) * GITOPS-7953 (Default resource exclusions list not updated in ArgoCD CR template) * GITOPS-7955 ([1.18] ArgoCD UI fails when Progressive sync is enabled in AppSet but not controller)
AI Analysis
Technical Summary
CVE-2025-55191 describes a race condition in the Argo CD GitOps tool's repository credentials handler. When concurrent operations target the same repository URL, the server may panic and crash, resulting in a denial of service. Triggering this requires a valid API token with create, update, or delete permissions on repository resources. The vulnerability affects Red Hat OpenShift GitOps versions >=1.18.0 and <1.18.1. The issue is tracked under Red Hat Bugzilla 2400562 and fixed in version 1.18.1. The vulnerability is classified under CWE-362 (race condition) and related CWEs. The availability impact is limited to the Argo CD server process; the underlying host is not compromised. Red Hat has released an official security advisory and update to remediate this vulnerability.
Potential Impact
The vulnerability can cause the Argo CD server to crash due to a race condition when handling repository credentials during concurrent operations on the same repository URL. This leads to a denial of service affecting the availability of the Argo CD server. The host system running Argo CD is not affected. No confidentiality or integrity impacts are reported. Exploitation requires valid API tokens with repository resource permissions, limiting the attack surface.
Mitigation Recommendations
An official security update to Red Hat OpenShift GitOps version 1.18.1 is available and should be applied to remediate this vulnerability. Prior to applying this update, ensure all previously released errata relevant to your system are installed. Systems configured to automatically restart the Argo CD service upon crash may partially mitigate availability impact but do not replace applying the official fix. Refer to Red Hat's advisory and documentation for update procedures.
Red Hat Security Advisory: Red Hat OpenShift GitOps v1.18.1 security update
Description
An update is now available for Red Hat OpenShift GitOps. Bug Fix(es) and Enhancement(s): * GITOPS-7606 (ApplicationSet: Bitbucket SCM/PR generator leaks HTTP connections) * GITOPS-7953 (Default resource exclusions list not updated in ArgoCD CR template) * GITOPS-7955 ([1.18] ArgoCD UI fails when Progressive sync is enabled in AppSet but not controller)
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-55191 describes a race condition in the Argo CD GitOps tool's repository credentials handler. When concurrent operations target the same repository URL, the server may panic and crash, resulting in a denial of service. Triggering this requires a valid API token with create, update, or delete permissions on repository resources. The vulnerability affects Red Hat OpenShift GitOps versions >=1.18.0 and <1.18.1. The issue is tracked under Red Hat Bugzilla 2400562 and fixed in version 1.18.1. The vulnerability is classified under CWE-362 (race condition) and related CWEs. The availability impact is limited to the Argo CD server process; the underlying host is not compromised. Red Hat has released an official security advisory and update to remediate this vulnerability.
Potential Impact
The vulnerability can cause the Argo CD server to crash due to a race condition when handling repository credentials during concurrent operations on the same repository URL. This leads to a denial of service affecting the availability of the Argo CD server. The host system running Argo CD is not affected. No confidentiality or integrity impacts are reported. Exploitation requires valid API tokens with repository resource permissions, limiting the attack surface.
Mitigation Recommendations
An official security update to Red Hat OpenShift GitOps version 1.18.1 is available and should be applied to remediate this vulnerability. Prior to applying this update, ensure all previously released errata relevant to your system are installed. Systems configured to automatically restart the Argo CD service upon crash may partially mitigate availability impact but do not replace applying the official fix. Refer to Red Hat's advisory and documentation for update procedures.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:18093
- Cve Count
- 4
- Additional Cves
- ["CVE-2025-59531","CVE-2025-59537","CVE-2025-59538"]
Threat ID: 6a3de72d4853345fc1127f5c
Added to database: 06/26/2026, 02:42:53 UTC
Last enriched: 08/16/2026, 18:22:43 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 54
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.