Skip to main content
EPSS 0.7%top 50%

Red Hat Security Advisory: RHTAS 1.2.2 - Red Hat Trusted Artifact Signer Release

0
High
Published: 02/18/2026 (02/18/2026, 12:11:20 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The RHTAS Operator can be used with OpenShift Container Platform 4.15, 4.16, 4.17, 4.18 and 4.19

Affected software

Affected versions
>=1.2.0 <=1.2.2Red HatRed Hat Trusted Artifact SignerRed Hat Trusted Artifact Signer 1.2amd64registry.redhat.io/rhtas/tuftool-rhel9@sha256:054e35934fb23775cf46ce0e3683a991170b2dbc3148354f75e19b9e3f29bc02_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 17:43:54 UTC

Technical Analysis

The Red Hat Trusted Artifact Signer (RHTAS) OpenShift Operator versions 1.2.0 through 1.2.2 are affected by multiple vulnerabilities, including CVE-2025-66418. This CVE describes a denial of service vulnerability in the urllib3 Python library, where a remote attacker can cause resource exhaustion by sending HTTP responses with an excessive number of chained compression algorithms. This leads to unbounded CPU and memory usage, causing service disruption. The advisory references CWE-770 (Allocation of Resources Without Limits or Throttling) and CWE-409. The vulnerabilities affect the integrity and availability of software supply chain processes that rely on RHTAS. The vendor advisory does not list any fixes or patches for these issues as of the publication date. The affected versions are explicitly stated as >=1.2.0 <=1.2.2. The product is a self-managed on-premise deployment of the Sigstore project used to cryptographically sign and verify software artifacts.

Potential Impact

The primary impact is denial of service due to resource exhaustion (CPU and memory) caused by unbounded decompression chains in urllib3. This can make applications using RHTAS unresponsive, disrupting software supply chain operations that depend on artifact signing and verification. There is no indication of confidentiality or integrity compromise from the provided data. No known exploits in the wild have been reported.

Mitigation Recommendations

The vendor advisory does not currently provide any fixes or patches for these vulnerabilities. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should monitor Red Hat's official channels for updates and consider mitigating exposure by limiting access to affected components or applying any recommended configuration changes once available. Since this is a self-managed on-premise deployment, vendor-managed remediation does not apply.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:2919
Cve Count
3
Additional Cves
["CVE-2025-66471","CVE-2026-21441"]

Threat ID: 6a160972e29bf47b5063a93b

Added to database: 05/26/2026, 20:58:26 UTC

Last enriched: 08/17/2026, 17:43:54 UTC

Last updated: 09/10/2026, 19:36:51 UTC

Views: 64

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses