Skip to main content
EPSS 0.3%top 76%

Red Hat Security Advisory: RHTAS 1.3.8 - Red Hat Trusted Artifact Signer Release

0
High
Published: 09/23/2026 (09/23/2026, 13:56:32 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The RHTAS Operator can be used with OpenShift Container Platform 4.16, 4.17, 4.18, 4.19, 4.20 and 4.21

Affected software

Alpineghsa
knative-serving
Affected versions
<1.20.3-r0=1.20.3-r0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 07:14:15 UTC

Technical Analysis

This vulnerability (CVE-2026-41178) affects Red Hat Advanced Cluster Management for Kubernetes and involves the Red Hat Trusted Artifact Signer component. The advisory references a security update in version 2.17.2 of the product that addresses this and other related CVEs. The vulnerability is rated as high severity by Red Hat Product Security. The update fixes issues including a regression related to image overrides in the ManagedClusterImageRegistry. The vendor advisory confirms the availability of a patch and provides detailed remediation instructions.

Potential Impact

The vulnerability impacts Red Hat Advanced Cluster Management for Kubernetes, potentially affecting cluster and application management across public and private cloud environments. The high severity rating indicates significant security implications, though no active exploitation is currently known. The issue could affect the integrity or security posture of managed Kubernetes clusters if left unpatched.

Mitigation Recommendations

Red Hat has released an official security update (version 2.17.2) that addresses this vulnerability. Users should apply this update after ensuring all previously released relevant errata are installed. Detailed update instructions are available in the Red Hat advisory. Since a patch is available, applying the official fix is the recommended mitigation. No additional vendor-recommended mitigations are indicated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
CLEANSTART-2026-KT57055
Osv Schema Version
1.7.3
Ecosystems
["Alpine"]
State
PUBLISHED

Threat ID: 6a7f440ebf8831d5395fc38b

Added to database: 08/14/2026, 16:36:30 UTC

Last enriched: 09/24/2026, 07:14:15 UTC

Last updated: 09/29/2026, 18:13:08 UTC

Views: 35

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEReference 1SUSE ratingsURL of this CSAF noticeSUSE Bug 1276731SUSE CVE CVE-2026-41178 pagehttps://access.redhat.com/errata/RHSA-2026:67543https://access.redhat.com/security/cve/CVE-2026-41178https://access.redhat.com/security/cve/CVE-2026-45570https://access.redhat.com/security/cve/CVE-2026-56852https://access.redhat.com/security/cve/CVE-2026-66780https://access.redhat.com/security/cve/CVE-2026-71556https://access.redhat.com/security/cve/CVE-2026-75899https://access.redhat.com/security/cve/CVE-2026-75931https://access.redhat.com/security/cve/CVE-2026-75975https://access.redhat.com/security/cve/CVE-2026-76172https://access.redhat.com/security/cve/CVE-2026-89060https://access.redhat.com/security/updates/classification/https://access.redhat.com/security/updates/classification/#importantCanonical URLhttps://access.redhat.com/errata/RHSA-2026:70826https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/indexhttps://access.redhat.com/security/cve/CVE-2026-73500Canonical URLhttps://access.redhat.com/errata/RHSA-2026:70829https://access.redhat.com/security/cve/CVE-2026-45736https://access.redhat.com/security/cve/CVE-2026-48779https://access.redhat.com/security/cve/CVE-2026-56854https://access.redhat.com/security/cve/CVE-2026-59869https://access.redhat.com/security/cve/CVE-2026-73086https://access.redhat.com/security/cve/CVE-2026-73088https://access.redhat.com/security/cve/CVE-2026-73089https://access.redhat.com/security/cve/CVE-2026-73646Canonical URLhttps://access.redhat.com/errata/RHSA-2026:70824Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses