RHSA-2026:2136HighCVSS 7.5

Red Hat Security Advisory: RHTAS 1.3.2 - Red Hat Trusted Artifact Signer Release

Published
February 5, 2026
Last Modified
June 3, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2025-47913 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-66506 — github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token CVE-2026-22772 — fulcio: Fulcio: Server-Side Request Forgery (SSRF) via unanchored regex in MetaIssuer URL validation

🔗 References (9)