RHSA-2026:2921HighCVSS 7.5
Red Hat Security Advisory: RHTAS 1.2.2 - Red Hat Trusted Artifact Signer Release
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-65945 — node-jws: auth0/node-jws: Improper signature verification in HS256 algorithm
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:2921
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.2
- externalhttps://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.2/html-single/release_notes/index
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2025-65945
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2921.json