Skip to main content
EPSS 0.7%top 49%

Red Hat Security Advisory: Red Hat OpenShift GitOps v1.18.3 security update

0
High
Published: 01/22/2026 (01/22/2026, 15:47:03 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

An update is now available for Red Hat OpenShift GitOps. Bug Fix(es) and Enhancement(s): * GITOPS-8239 (CVE-2025-47913 openshift-gitops-1/gitops-rhel8: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [gitops-1.18]) * GITOPS-8079 (CVE-2025-58183 openshift-gitops-1/argocd-rhel8: Unbounded allocation when parsing GNU sparse map [gitops-1.18]) * GITOPS-8082 (CVE-2025-58183 openshift-gitops-1/dex-rhel8: Unbounded allocation when parsing GNU sparse map [gitops-1.18]) * GITOPS-8522 (CVE-2025-68156 openshift-gitops-1/argocd-rhel8: Expr: Denial of Service via uncontrolled recursion in expression evaluation [gitops-1.18]) * GITOPS-8523 (CVE-2025-68156 openshift-gitops-1/argocd-rhel9: Expr: Denial of Service via uncontrolled recursion in expression evaluation [gitops-1.18]) * GITOPS-7849 (Cherry pick Repo Type Fix to Argo CD 3.1 stream) * GITOPS-7992 (openshift-gitops-operator-metrics-monitor ServiceMonitor is attempting to use a bearerTokenFile configuration in its endpoints definition) * GITOPS-8225 (RC 1.19.0-2 : haproxy replica remains 1 with HA upgrade) * GITOPS-8249 (Prevent argoCD from automatically refreshing to gitops repository ) * GITOPS-8411 (CVE-2025-55190 still blocking due to github.com/argoproj/argo-cd/[email protected] in gitops-rhel8:v1.18.1) * GITOPS-8535 (Show All Namespaces or Current Namespace Only option) * GITOPS-8591 (Reciving TargetDown after upgrading GitOps )

Affected software

Affected versions
>=1.18.0 <1.18.3Red HatRed Hat OpenShift GitOpsRed Hat OpenShift GitOps 1.18amd64registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:ddc27dbea59c611ffb5394114a6c754397cc0032ba3487a3f03041ed34cfce30_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 21:53:52 UTC

Technical Analysis

Red Hat OpenShift GitOps versions from 1.18.0 up to but not including 1.18.3 are affected by multiple security vulnerabilities. The most significant is CVE-2025-13888, where namespace administrators can create ArgoCD Custom Resources that grant them elevated permissions in other namespaces, including privileged ones. This can be exploited to create privileged workloads running on master nodes, effectively granting root access to the entire cluster. Additional vulnerabilities addressed include denial of service via uncontrolled recursion in expression evaluation (CVE-2025-68156), unbounded memory allocation when parsing GNU sparse maps (CVE-2025-58183), and SSH client panic due to unexpected SSH_AGENT_SUCCESS (CVE-2025-47913). Red Hat has released OpenShift GitOps v1.18.3 containing fixes for these issues. The vulnerability requires authenticated namespace admin privileges, reducing exposure to internal threat actors. The advisory includes multiple CVEs and bug fixes related to privilege escalation, denial of service, and memory allocation errors.

Potential Impact

An authenticated namespace administrator can exploit CVE-2025-13888 to escalate privileges across namespaces, including privileged namespaces, enabling creation of privileged workloads on master nodes and effectively gaining root access to the entire cluster. This represents a significant risk of full cluster compromise. Other vulnerabilities may lead to denial of service or unexpected client crashes, impacting availability and stability of the GitOps service. The attack surface is limited to authorized internal users with namespace admin rights, not external unauthenticated attackers.

Mitigation Recommendations

Red Hat has released OpenShift GitOps version 1.18.3 which includes fixes for CVE-2025-13888 and other related vulnerabilities. Users should apply this update promptly after ensuring all prior relevant errata are applied. The vendor advisory confirms the availability of an official fix. No additional mitigations are specified beyond applying the update. Since the vulnerability requires authenticated namespace admin privileges, restricting such privileges to trusted users also reduces risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:1017
Cve Count
6
Additional Cves
["CVE-2025-47913","CVE-2025-55190","CVE-2025-58183","CVE-2025-61729","CVE-2025-68156"]

Threat ID: 6a16096ae29bf47b5062f6e3

Added to database: 05/26/2026, 20:58:18 UTC

Last enriched: 08/14/2026, 21:53:52 UTC

Last updated: 09/10/2026, 19:36:49 UTC

Views: 98

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses