Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.6%top 54%

Red Hat Security Advisory: RHTAS 1.3.5 - Red Hat Trusted Artifact Signer Release

0
High
Published: 06/08/2026 (06/08/2026, 12:55:36 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The RHTAS Operator can be used with OpenShift Container Platform 4.16, 4.17, 4.18, 4.19, 4.20 and 4.21

Affected software

Affected versions
Red HatRed Hat Trusted Artifact SignerRed Hat Trusted Artifact Signer 1.3amd64registry.redhat.io/rhtas/rekor-backfill-redis-rhel9@sha256:bf6562233da1cdef3dc7055a7323dcae9fcf336b83ace2f2cd8d9f8452514e34_amd640

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 08:50:47 UTC

Technical Analysis

The Red Hat Trusted Artifact Signer (RHTAS) Operator, used with OpenShift Container Platform versions 4.16 to 4.21, is affected by multiple high-severity vulnerabilities (CVE-2026-33815, CVE-2026-33816, CVE-2026-34986). These vulnerabilities relate to memory safety issues such as out-of-bounds writes and incorrect buffer size calculations (CWE-787, CWE-131). The CVSS vector for CVE-2026-33815 indicates network attack vector, low attack complexity, no privileges or user interaction required, and high impact on confidentiality, integrity, and availability. The advisory does not provide any patch or remediation details, and no known exploits in the wild have been reported. RHTAS is a self-managed on-premise deployment of the Sigstore project to cryptographically sign and verify software artifacts.

Potential Impact

Successful exploitation of these vulnerabilities could lead to complete compromise of confidentiality, integrity, and availability of the affected systems running Red Hat Trusted Artifact Signer. Given the nature of the vulnerabilities (memory corruption issues), attackers could potentially execute arbitrary code or cause denial of service. The high CVSS severity reflects the critical impact on affected environments.

Mitigation Recommendations

As of the advisory publication, no official patches or fixes have been released for these vulnerabilities. Users should monitor Red Hat's official security advisories and update promptly once a fix becomes available. Since this is a self-managed on-premise deployment, organizations should consider limiting network exposure of the RHTAS Operator and apply standard security best practices to reduce risk until a patch is provided.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:24479
Cve Count
3
Additional Cves
["CVE-2026-33816","CVE-2026-34986"]
Cvss Version
null

Threat ID: 6a27320be29bf47b509be62f

Added to database: 06/08/2026, 21:20:11 UTC

Last enriched: 07/30/2026, 08:50:47 UTC

Last updated: 07/31/2026, 22:28:24 UTC

Views: 73

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses