RHSA-2026:29854HighCVSS 9.1

Red Hat Security Advisory: Red Hat OpenShift API for Data Protection

Published
June 25, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-27137 — crypto/x509: Incorrect enforcement of email constraints in crypto/x509 CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33747 — BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend CVE-2026-33748 — github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components CVE-2026-33810 — crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object

🎯 Affected products42

  • OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:17af493f7fee34d568b9d5619adfd7e087c28a8038e511d254a3999c37c58ef8_s390x as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:374d9e4e00b261c35289aee21a1d890b516d0fb83078b3b52817f5c5385aa084_arm64 as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:ad53c993e7afabb98c66f25e8093851fbca592f030ed9c6e32056492958162d0_amd64 as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:fa2b4d9faf775d51f0ee2b8db7081b982a1e50172a004307e80bd03ca0fe3d1d_ppc64le as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:4490beeb9fdb719cc93232301a83637a1b0ce702bee0fd910ccd3cd4c11e50d0_amd64 as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:b3331c129826252d0b92fc27246597482bbe75e8eecea9bfa64d56be490c8d63_s390x as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:b8975f3cb3ab52842046e7a060e770de5ab3df539410825f8028db402746dc49_arm64 as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:d766b160ca81c2b7ad6b6d5c6915b3a92c6bb673cc9a8d06e9092b9760967d85_ppc64le as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-operator-bundle@sha256:fbb56ee11f594426137e348722879c5e82dc54f95038166a1b4c4f4ee81e894d_amd64 as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-rhel9-operator@sha256:143ab7980c82934a76ad7bd868132b74701c5551832b28791848527ce8b03c20_amd64 as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-rhel9-operator@sha256:92c0fefeea6b853dbfff5ec75e39d1fcda373dbf7c57970800b0b37178031238_ppc64le as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-rhel9-operator@sha256:b6eac0b65e002fd41dde04e5c674b5993ea6369524e8c0140e916aba485053d4_arm64 as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-rhel9-operator@sha256:cf465717f1180127489d07808818760d194e04e155d6eb8eff2724505fd0f6cd_s390x as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:30831d901c1636053558d0ac31de96e2580c30c85d9084b5d93080f5e96eb66c_ppc64le as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:ca9f1af1a243a4dd74f75345e5e525393f9ba9fb797fd970ae2280a39f57b772_amd64 as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:eacd5a9c1c16fb73e5b0097ee93e82bac7950dd2753a7d169a1a24547b6174ad_arm64 as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:fb527f9ac9fa160a71a503a3eb82aa3f9ef1585a4bcdead6f035185b91c05334_s390x as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:5d98839c46b3c0263b0eb19b4d06d46fa65773f8244cdaabeed873f123995576_arm64 as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:85b050dd45621a34f14dd6b6ab867dc4ac84964c02523ee865480713823dd390_ppc64le as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:db5d67e04f26424081a96ce90ca054dd4fc99b638c93a272a7af7af85ec4c0a0_s390x as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:e213bf8473c54562605ee9f6e13399a7cff1ea2f50f037b909d8a9ab59575964_amd64 as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:356fafc9176aa3386278ee1f719133b1359e8a5f2f5de91c8ca9412a991f9b55_ppc64le as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:3a5a8bc8aadd7779a08128cfb59f50e1991cc0251c2edc9b0f953cdad195ae0b_amd64 as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:a080e8ffa4ee1f3c99bb4df919bbfb29def73095a0bfd7a839e2091217d68e28_s390x as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:f83df5c7657049f90eaee42cc5dead19fcb48c6adeaa2f9812e5420f0aa00d5d_arm64 as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:d5c683e4252c17d06bf3945f3af4c80ef42f856e9dd6c1a6d08a4e54babfedac_amd64 as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:ed0a47c5e0320e84d995d99236158cf686b9c2443f6eaa5e47cb3e69b01c23e2_ppc64le as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:f12b8e98ebdf05f6f91b1eed3ff3dbbedefaac55fa8fc41943ff91faed46bf32_arm64 as a component of OpenShift API for Data Protection 1.4
  • registry.redhat.io/oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:fc597c5c4c62c2d87fd68e884df4c9d7634898dd7579e1d825daa2fd08ea35b4_s390x as a component of OpenShift API for Data Protection 1.4
  • +12 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this vulnerability, avoid using untrusted BuildKit frontends. Restrict the use of custom BuildKit frontends to only those from verified and trusted sources. Do not specify untrusted frontends via `#syntax` or `--build-arg BUILDKIT_SYNTAX`.

🔗 References (15)