RHSA-2026:3825HighCVSS 8.7

Red Hat Security Advisory: Red Hat OpenShift Pipelines Release 1.20.3

Published
March 5, 2026
Last Modified
June 3, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2025-12816 — node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-15284 — qs: qs: Denial of Service via improper input validation in array parsing CVE-2025-66506 — github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token CVE-2025-66564 — github.com/sigstore/timestamp-authority: Sigstore Timestamp Authority: Denial of Service via excessive OID or Content-Type header parsing

🔗 References (9)