Red Hat Security Advisory: RHTAS 1.2.2 - Red Hat Trusted Artifact Signer Release
The RHTAS Operator can be used with OpenShift Container Platform 4.15, 4.16, 4.17, 4.18 and 4.19
AI Analysis
Technical Summary
The Red Hat Trusted Artifact Signer (RHTAS) OpenShift Operator versions 1.2.0 through 1.2.2 are affected by multiple vulnerabilities, including CVE-2025-66418. This CVE describes a denial of service vulnerability in the urllib3 Python library, where a remote attacker can cause resource exhaustion by sending HTTP responses with an excessive number of chained compression algorithms. This leads to unbounded CPU and memory usage, causing service disruption. The advisory references CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-409. The vulnerabilities affect the integrity and availability of software supply chain processes that rely on RHTAS. The vendor advisory does not list any fixes or patches for these issues as of the publication date. The affected versions are explicitly stated as >=1.2.0 <=1.2.2. The product is a self-managed on-premise deployment of the Sigstore project used to cryptographically sign and verify software artifacts.
Potential Impact
The primary impact is denial of service due to resource exhaustion (CPU and memory) caused by unbounded decompression chains in urllib3. This can make applications using RHTAS unresponsive, disrupting software supply chain operations that depend on artifact signing and verification. There is no indication of confidentiality or integrity compromise from the provided data. No known exploits in the wild have been reported.
Mitigation Recommendations
The vendor advisory does not currently provide any fixes or patches for these vulnerabilities. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor Red Hat's official channels for updates and consider mitigating exposure by limiting access to affected components or applying any recommended configuration changes once available. Since this is a self-managed on-premise deployment, vendor-managed remediation does not apply.
Red Hat Security Advisory: RHTAS 1.2.2 - Red Hat Trusted Artifact Signer Release
Description
The RHTAS Operator can be used with OpenShift Container Platform 4.15, 4.16, 4.17, 4.18 and 4.19
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Red Hat Trusted Artifact Signer (RHTAS) OpenShift Operator versions 1.2.0 through 1.2.2 are affected by multiple vulnerabilities, including CVE-2025-66418. This CVE describes a denial of service vulnerability in the urllib3 Python library, where a remote attacker can cause resource exhaustion by sending HTTP responses with an excessive number of chained compression algorithms. This leads to unbounded CPU and memory usage, causing service disruption. The advisory references CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-409. The vulnerabilities affect the integrity and availability of software supply chain processes that rely on RHTAS. The vendor advisory does not list any fixes or patches for these issues as of the publication date. The affected versions are explicitly stated as >=1.2.0 <=1.2.2. The product is a self-managed on-premise deployment of the Sigstore project used to cryptographically sign and verify software artifacts.
Potential Impact
The primary impact is denial of service due to resource exhaustion (CPU and memory) caused by unbounded decompression chains in urllib3. This can make applications using RHTAS unresponsive, disrupting software supply chain operations that depend on artifact signing and verification. There is no indication of confidentiality or integrity compromise from the provided data. No known exploits in the wild have been reported.
Mitigation Recommendations
The vendor advisory does not currently provide any fixes or patches for these vulnerabilities. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor Red Hat's official channels for updates and consider mitigating exposure by limiting access to affected components or applying any recommended configuration changes once available. Since this is a self-managed on-premise deployment, vendor-managed remediation does not apply.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:2919
- Cve Count
- 3
- Additional Cves
- ["CVE-2025-66471","CVE-2026-21441"]
Threat ID: 6a160972e29bf47b5063a93b
Added to database: 05/26/2026, 20:58:26 UTC
Last enriched: 08/17/2026, 17:43:54 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 64
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.