RHSA-2026:2852HighCVSS 7.5
Red Hat Security Advisory: OpenShift Security Profiles Operator bug fix and enhancement update
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-66506 — github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token CVE-2025-66564 — github.com/sigstore/timestamp-authority: Sigstore Timestamp Authority: Denial of Service via excessive OID or Content-Type header parsing
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:2852
- externalhttps://access.redhat.com/security/cve/CVE-2025-66506
- externalhttps://access.redhat.com/security/cve/CVE-2025-66564
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2852.json