Red Hat Security Advisory: Red Hat OpenShift Builds 1.6.5
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33211 — Tekton Pipelines: github.com/tektoncd/pipeline: Tekton Pipelines: Information disclosure via path traversal in git resolver CVE-2026-33810 — crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application
🎯 Affected products38
- Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:092c9b4af55870d904beac952acf0fd914a2e784472888bb9f2c108548ff4906_arm64 as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:25a9ca58f1104d83e0e312baf241f3eb048220c22a0065eed70106d9991faea4_ppc64le as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:2c6b079cf3184539f06634afcb35784ac74110c04fec36dfa80c2b0789d9099d_amd64 as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-controller-rhel9@sha256:7b579fdc1d1dca3f32c2172eddb899ef3f8ff39d7af5cbed854d48e1d9e27675_s390x as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:2a33081f6d32826d53821e1aea686e1a6e8cb30fea8e601c00729c06511b98c6_s390x as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:31af187e314a843c4c02edd119d5edc2c260baca4d9a4ec2347f80f5511d6d3f_arm64 as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:355cfa27d099cce3743ffa8432d2070ae3f21a446b560f6c1c5146b7351d116a_ppc64le as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-git-cloner-rhel9@sha256:64d5bfb3e3a9861b3cefdb49c0f9b286aad11ccb31867092de08e48630694f82_amd64 as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:3d20f5041cd11c838fc15148f60650ae0824b4c7816eb50152a28693443b0cd0_ppc64le as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:596cfba3fdac5cd9ee725f6b9e0bc640eaf7e933d019d9d57ea840592ec72f23_arm64 as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:a22a2cca1f48ee743a15c68ca22d1d76943c25b2069e80a4bc1275c8157284db_amd64 as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-image-bundler-rhel9@sha256:a9d691eec41e370daff6737ed9d0b8c018b5426ff195b77897fd579846858e39_s390x as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:54890d05d56aeee46f051f42959500e00f2c748e9fdb2f1100226d8b4b976a47_s390x as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:549f2d54aaa66f9ab68e08f49e4f0cd95ffbbc93607ef7a112b74b177e57cfd0_amd64 as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:5664f48403387a9e64370337d3ea5eb30ec27336f6e8f47a3a8a3ba0fe96741c_ppc64le as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-image-processing-rhel9@sha256:c95f763b803f53276670cea4fdf289983e472361a00a6d7da0bb56b3e857a935_arm64 as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-operator-bundle@sha256:60bfc1aeb95ff74fd2d8bd29700994594c92b93795b63f02fd0d7bb2d3d6fba7_amd64 as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:1c0d155195bfd251b40da10e153c8a738250f14253f337b198476740cb7bd81a_amd64 as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:26fdde499994a4be0eb277bbbca899061384f20673672ef30ed301d792b3108d_s390x as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:5d08c7ee6886747dc077faa7f1e4e696b5ad29cc4dcc8fd2c4f3d7a434f47f9b_arm64 as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:e1cdb58bf2783a9a50346e1690f51b09e175c8ebb737b11332658d85bcb645e9_ppc64le as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:c5083edbd43692dc5ef5b0cf14417eea19412c0927ede39a87ade36515cf16f1_ppc64le as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:d56042518051b3e4dbef3da9f13d74fd8e8a6b9ad8520965052f1522247b70ef_s390x as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:d6401dc97f1adeafcfb8a34e3c1fe8230cd2ca6bb7c4245ef875a4b3fa35b014_arm64 as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:f54ab8388a0f593c2426c240c7d50fd7f3f2263e1c88f7726dbbe2ebbed38896_amd64 as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:0d629bbf41a55434b40545e12c5f0d95e357b0fd74303feec657918b90321642_amd64 as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:7d6aecb4a7e98dcabc77c3043e214bec9fa521af9c6a048ece876ba9f294dce8_s390x as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:d69d7290c5e07301e9397df551e97d8d81795ba7c711d95f60bd178fc39f1434_arm64 as a component of Builds for Red Hat OpenShift 1.6.0
- registry.redhat.io/openshift-builds/openshift-builds-shared-resource-webhook-rhel9@sha256:e095cffba13badc4aab65f9920f8e618c9fe4411d6d53d8b160716a31fe2d6e7_ppc64le as a component of Builds for Red Hat OpenShift 1.6.0
- +8 more not shown
✅ Remediation
It is recommended that existing users of Red Hat OpenShift Builds 1.6.4 upgrades to to 1.6.5 Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this vulnerability, restrict the creation of ResolutionRequests to trusted users and service accounts. Implement strict Role-Based Access Control (RBAC) policies to limit which tenants can create TaskRuns or PipelineRuns that utilize the Tekton Pipelines git resolver. This reduces the exposure by preventing unauthorized access to the resolver pod's filesystem.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:11330
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-33211
- externalhttps://access.redhat.com/security/cve/CVE-2026-33810
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/builds_for_red_hat_openshift/1.6
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_11330.json