RHSA-2026:3827HighCVSS 8.1
Red Hat Security Advisory: Red Hat OpenShift Pipelines Release 1.20.3
🔗 CVE IDs covered (6)
📋 Description
CVE-2025-11621 — github.com/hashicorp/vault: Vault AWS auth method bypass due to AWS client cache CVE-2025-12044 — github.com/hashicorp/vault: Vault Vulnerable to Denial of Service Due to Rate Limit Regression CVE-2025-47913 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-66506 — github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token CVE-2025-66564 — github.com/sigstore/timestamp-authority: Sigstore Timestamp Authority: Denial of Service via excessive OID or Content-Type header parsing
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:3827
- externalhttps://access.redhat.com/security/cve/CVE-2025-11621
- externalhttps://access.redhat.com/security/cve/CVE-2025-12044
- externalhttps://access.redhat.com/security/cve/CVE-2025-47913
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2025-66506
- externalhttps://access.redhat.com/security/cve/CVE-2025-66564
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_pipelines
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3827.json