Red Hat Security Advisory: Red Hat OpenShift GitOps v1.18.3 security update
An update is now available for Red Hat OpenShift GitOps. Bug Fix(es) and Enhancement(s): * GITOPS-8239 (CVE-2025-47913 openshift-gitops-1/gitops-rhel8: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [gitops-1.18]) * GITOPS-8079 (CVE-2025-58183 openshift-gitops-1/argocd-rhel8: Unbounded allocation when parsing GNU sparse map [gitops-1.18]) * GITOPS-8082 (CVE-2025-58183 openshift-gitops-1/dex-rhel8: Unbounded allocation when parsing GNU sparse map [gitops-1.18]) * GITOPS-8522 (CVE-2025-68156 openshift-gitops-1/argocd-rhel8: Expr: Denial of Service via uncontrolled recursion in expression evaluation [gitops-1.18]) * GITOPS-8523 (CVE-2025-68156 openshift-gitops-1/argocd-rhel9: Expr: Denial of Service via uncontrolled recursion in expression evaluation [gitops-1.18]) * GITOPS-7849 (Cherry pick Repo Type Fix to Argo CD 3.1 stream) * GITOPS-7992 (openshift-gitops-operator-metrics-monitor ServiceMonitor is attempting to use a bearerTokenFile configuration in its endpoints definition) * GITOPS-8225 (RC 1.19.0-2 : haproxy replica remains 1 with HA upgrade) * GITOPS-8249 (Prevent argoCD from automatically refreshing to gitops repository ) * GITOPS-8411 (CVE-2025-55190 still blocking due to github.com/argoproj/argo-cd/[email protected] in gitops-rhel8:v1.18.1) * GITOPS-8535 (Show All Namespaces or Current Namespace Only option) * GITOPS-8591 (Reciving TargetDown after upgrading GitOps )
AI Analysis
Technical Summary
Red Hat OpenShift GitOps versions from 1.18.0 up to but not including 1.18.3 are affected by multiple security vulnerabilities. The most significant is CVE-2025-13888, where namespace administrators can create ArgoCD Custom Resources that grant them elevated permissions in other namespaces, including privileged ones. This can be exploited to create privileged workloads running on master nodes, effectively granting root access to the entire cluster. Additional vulnerabilities addressed include denial of service via uncontrolled recursion in expression evaluation (CVE-2025-68156), unbounded memory allocation when parsing GNU sparse maps (CVE-2025-58183), and SSH client panic due to unexpected SSH_AGENT_SUCCESS (CVE-2025-47913). Red Hat has released OpenShift GitOps v1.18.3 containing fixes for these issues. The vulnerability requires authenticated namespace admin privileges, reducing exposure to internal threat actors. The advisory includes multiple CVEs and bug fixes related to privilege escalation, denial of service, and memory allocation errors.
Potential Impact
An authenticated namespace administrator can exploit CVE-2025-13888 to escalate privileges across namespaces, including privileged namespaces, enabling creation of privileged workloads on master nodes and effectively gaining root access to the entire cluster. This represents a significant risk of full cluster compromise. Other vulnerabilities may lead to denial of service or unexpected client crashes, impacting availability and stability of the GitOps service. The attack surface is limited to authorized internal users with namespace admin rights, not external unauthenticated attackers.
Mitigation Recommendations
Red Hat has released OpenShift GitOps version 1.18.3 which includes fixes for CVE-2025-13888 and other related vulnerabilities. Users should apply this update promptly after ensuring all prior relevant errata are applied. The vendor advisory confirms the availability of an official fix. No additional mitigations are specified beyond applying the update. Since the vulnerability requires authenticated namespace admin privileges, restricting such privileges to trusted users also reduces risk.
Red Hat Security Advisory: Red Hat OpenShift GitOps v1.18.3 security update
Description
An update is now available for Red Hat OpenShift GitOps. Bug Fix(es) and Enhancement(s): * GITOPS-8239 (CVE-2025-47913 openshift-gitops-1/gitops-rhel8: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [gitops-1.18]) * GITOPS-8079 (CVE-2025-58183 openshift-gitops-1/argocd-rhel8: Unbounded allocation when parsing GNU sparse map [gitops-1.18]) * GITOPS-8082 (CVE-2025-58183 openshift-gitops-1/dex-rhel8: Unbounded allocation when parsing GNU sparse map [gitops-1.18]) * GITOPS-8522 (CVE-2025-68156 openshift-gitops-1/argocd-rhel8: Expr: Denial of Service via uncontrolled recursion in expression evaluation [gitops-1.18]) * GITOPS-8523 (CVE-2025-68156 openshift-gitops-1/argocd-rhel9: Expr: Denial of Service via uncontrolled recursion in expression evaluation [gitops-1.18]) * GITOPS-7849 (Cherry pick Repo Type Fix to Argo CD 3.1 stream) * GITOPS-7992 (openshift-gitops-operator-metrics-monitor ServiceMonitor is attempting to use a bearerTokenFile configuration in its endpoints definition) * GITOPS-8225 (RC 1.19.0-2 : haproxy replica remains 1 with HA upgrade) * GITOPS-8249 (Prevent argoCD from automatically refreshing to gitops repository ) * GITOPS-8411 (CVE-2025-55190 still blocking due to github.com/argoproj/argo-cd/[email protected] in gitops-rhel8:v1.18.1) * GITOPS-8535 (Show All Namespaces or Current Namespace Only option) * GITOPS-8591 (Reciving TargetDown after upgrading GitOps )
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Red Hat OpenShift GitOps versions from 1.18.0 up to but not including 1.18.3 are affected by multiple security vulnerabilities. The most significant is CVE-2025-13888, where namespace administrators can create ArgoCD Custom Resources that grant them elevated permissions in other namespaces, including privileged ones. This can be exploited to create privileged workloads running on master nodes, effectively granting root access to the entire cluster. Additional vulnerabilities addressed include denial of service via uncontrolled recursion in expression evaluation (CVE-2025-68156), unbounded memory allocation when parsing GNU sparse maps (CVE-2025-58183), and SSH client panic due to unexpected SSH_AGENT_SUCCESS (CVE-2025-47913). Red Hat has released OpenShift GitOps v1.18.3 containing fixes for these issues. The vulnerability requires authenticated namespace admin privileges, reducing exposure to internal threat actors. The advisory includes multiple CVEs and bug fixes related to privilege escalation, denial of service, and memory allocation errors.
Potential Impact
An authenticated namespace administrator can exploit CVE-2025-13888 to escalate privileges across namespaces, including privileged namespaces, enabling creation of privileged workloads on master nodes and effectively gaining root access to the entire cluster. This represents a significant risk of full cluster compromise. Other vulnerabilities may lead to denial of service or unexpected client crashes, impacting availability and stability of the GitOps service. The attack surface is limited to authorized internal users with namespace admin rights, not external unauthenticated attackers.
Mitigation Recommendations
Red Hat has released OpenShift GitOps version 1.18.3 which includes fixes for CVE-2025-13888 and other related vulnerabilities. Users should apply this update promptly after ensuring all prior relevant errata are applied. The vendor advisory confirms the availability of an official fix. No additional mitigations are specified beyond applying the update. Since the vulnerability requires authenticated namespace admin privileges, restricting such privileges to trusted users also reduces risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:1017
- Cve Count
- 6
- Additional Cves
- ["CVE-2025-47913","CVE-2025-55190","CVE-2025-58183","CVE-2025-61729","CVE-2025-68156"]
Threat ID: 6a16096ae29bf47b5062f6e3
Added to database: 05/26/2026, 20:58:18 UTC
Last enriched: 08/14/2026, 21:53:52 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 98
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.