Red Hat Security Advisory: Red Hat Edge Manager Version 1.1.3 Security Update
🔗 CVE IDs covered (29)
📋 Description
CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2025-69873 — ajv: ReDoS via $data reference CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-4926 — path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-32141 — flatted: flatted: Unbounded recursion DoS in parse() revive phase CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33810 — crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-33816 — github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
🎯 Affected products29
- Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-alert-exporter-rhel10@sha256:46f199ef17120950d7e93c7a961f84d2323d8a5c43f5011e6ae627d345e0b068_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-alert-exporter-rhel10@sha256:776d29cf3b89a8c3d64dcc489ef61d27b9f60564959bdaa63a672c92db9cd04c_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-alertmanager-proxy-rhel10@sha256:28ea0930eb02313f5263f324d1a49660b33fb5591f95b40f31bd759617aa1907_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-alertmanager-proxy-rhel10@sha256:4bf6b54a4bfe93f97263a6b2c58f70caab13535e37190c62c87b1feac543ff64_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-api-rhel10@sha256:54a4afb838796f1ceb3da0b6e1b0ad3c97e109f9b030768d69d9ee5a86da7095_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-api-rhel10@sha256:fe6e2a256f7f3f696f79f79ab3ce7caf3a39f32f128542c102955dacfe8c7b56_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-cli-artifacts-rhel10@sha256:307b95e668b576c0401be69c0e795afbf289d6e62df98aaf02fd2f06d8da3bbc_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-cli-artifacts-rhel10@sha256:8a9a634943f7d87701b385e546fe4e8e76b1ec70c39d38db1cd5ea688c6d08ce_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-db-setup-rhel10@sha256:53b36674b1276fb57c70fa059771d627e424a575e82f18fb04d4c955544595ca_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-db-setup-rhel10@sha256:fdd9f525cc859eb6c0d110c9b0d366031789060b5b7ab149087f0676e8619ea8_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-imagebuilder-api-rhel10@sha256:413b2e31d26dda7222710a7c917708e30eb8e28c99b8eccd742d19b32da88460_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-imagebuilder-api-rhel10@sha256:9740ee00386011c4faa90e5ab073140351889615a4bca5721092a5c0f65cac99_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-imagebuilder-worker-rhel10@sha256:1f0cf97cd192812a11b6503d014eff731122c88745e0be01ad9eb16be400e66a_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-imagebuilder-worker-rhel10@sha256:910062b408e6a38fdc619446da9ca46a2388715a3fc9daf9966942d6318ea128_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-pam-issuer-rhel10@sha256:c91bd430b3716a63dbfba125b71f76785a946e2c4a8e95e912a6e9a4895e6d05_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-pam-issuer-rhel10@sha256:ff588e0f2607fe83d49724d0f6f8e8211a8390cbdada721cf7b9a6a8e48dd459_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-periodic-rhel10@sha256:3c88db541868675a34ed865d5915f9017b135bf63414a9b646732ddbdb7954bf_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-periodic-rhel10@sha256:d788e558e4ae745a4c522f66cb20deaf7cb05ef687d48200b35ddd814d631ed3_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-telemetry-gateway-rhel10@sha256:6b48127195e694b31bb715c95967d3048fe873b0e73b66d1951f1a37b3447fd6_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-telemetry-gateway-rhel10@sha256:7b392b0e21d3893efb23c1de0fe40353bfcc84c8ed02b839fc842f1f43216942_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-ui-ocp-rhel10@sha256:15376bc6e9cc4c3b15a3df153f0589c18ced018ddb61d268bdc36071d7e5ca33_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-ui-ocp-rhel10@sha256:a2e646cf23af1fa2f286956775706d420f25cd8980fd559e4d2b6034aa467272_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-ui-rhel10@sha256:722521b8e67bfab1ae2c9d97efb09bdb39036c2d90d0ff95aef9178d2bcc8d67_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-ui-rhel10@sha256:bc6a86545ca397ed034b085f3c3f18dbd1d92e2bdcabe034d98cda9aa5eb32f0_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-userinfo-proxy-rhel10@sha256:0888b7a9a22d46339efe06f579b1e9c355211f6ef559fadad57ceb5fe8018ba5_amd64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-userinfo-proxy-rhel10@sha256:c1dcc4930b147562e0eaea24d1947afd66aa52f2c4330a583defe3955afab45b_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-worker-rhel10@sha256:464d0b617c3cc12d3c9b08b84bd9b42b1ebf2903a677a15565caedecad4785b3_arm64 as a component of Red Hat Edge Manager 1.1
- registry.redhat.io/rhem/flightctl-worker-rhel10@sha256:f7234afa82c317b5708da4fc5113949846ca9e67387c06d5f33758aef391db53_amd64 as a component of Red Hat Edge Manager 1.1
✅ Remediation
See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: To mitigate this issue, disable the $data feature if your application does not require it. If $data must be used, implement strict validation of the input fields that are referenced by the pattern keyword to ensure they contain only expected and safe characters. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, limit the use of multiple sequential optional groups in route patterns within applications that use `path-to-regexp`. Additionally, avoid directly passing user-controlled input as route patterns to prevent the generation of maliciously crafted regular expressions. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: Upgrade to a fixed golang.org/x/crypto/ssh release via updated golang or package rebuilds. Ensure SSH servers use supported public-key callback configurations with source-address validation as intended.
🔗 References (34)
- selfhttps://access.redhat.com/errata/RHSA-2026:40945
- externalhttps://access.redhat.com/security/cve/CVE-2026-4800
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2025-69873
- externalhttps://access.redhat.com/security/cve/CVE-2026-13676
- externalhttps://access.redhat.com/security/cve/CVE-2026-22029
- externalhttps://access.redhat.com/security/cve/CVE-2026-25679
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/cve/CVE-2026-32141
- externalhttps://access.redhat.com/security/cve/CVE-2026-32280
- externalhttps://access.redhat.com/security/cve/CVE-2026-32281
- externalhttps://access.redhat.com/security/cve/CVE-2026-32282
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-33810
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-33816
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39832
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/cve/CVE-2026-4926
- externalhttps://access.redhat.com/security/cve/CVE-2026-6322
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.15/html-single/edge_manager/index#edge-mgr-intro
- externalhttps://access.redhat.com/security/cve/CVE-2026-46595
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/managing_device_fleets_with_the_red_hat_edge_manager/assembly-edge-manager-intro
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_40945.json