Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:18093 - Security Advisory
Issued:
2025-10-15
Updated:
2025-10-15

RHSA-2025:18093 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: Red Hat OpenShift GitOps v1.18.1 security update

Type/Severity

Security Advisory: Important

Topic

Important: Red Hat OpenShift GitOps v1.18.1 security update

Description

An update is now available for Red Hat OpenShift GitOps.
Bug Fix(es) and Enhancement(s):

  • GITOPS-7606 (ApplicationSet: Bitbucket SCM/PR generator leaks HTTP connections)
  • GITOPS-7953 (Default resource exclusions list not updated in ArgoCD CR template)
  • GITOPS-7955 ([1.18] ArgoCD UI fails when Progressive sync is enabled in AppSet but not controller)

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Fixes

  • https://issues.redhat.com/browse/GITOPS-7606
  • https://issues.redhat.com/browse/GITOPS-7953
  • https://issues.redhat.com/browse/GITOPS-7955

CVEs

  • CVE-2025-55191
  • CVE-2025-59531
  • CVE-2025-59537
  • CVE-2025-59538

References

  • https://access.redhat.com/security/updates/classification/
  • https://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.18/

amd64

registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:f8f99349426e5ab977acdda440c22e5d04187ca43e05f91c8b5bbb823eaf59f6
registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:b0408f958ef20c3f6230d392049b261ebfbd50f5f8e5b0e9776b20726fc9c83a
registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:2cfd5c1921d34fe92c312d0929599207266c0b14207b987edda7eb838728e554
registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:67069d6db9ef08a8653964aa24a13a97da97f2238210dbdb085988014f77e990
registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:2cb3b46616a69b95620a59b43e9aadbe02e98b984434d1a47410a603de4d1598
registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:22f95edd885609dfbf1b606fc5d41f2efa5361cbec1f1918e5d774a030779ea0
registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:f20831b8df3104e7ae3e147ea3df202433d0f20e6b1bfb1259fe71bae8f9c2b5
registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:b8f986a933e626883b0bf03fdf253ce4c74d82931342ede909324de1da1ae327
registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:b756f5cd7270e033a99c1c90c7e63567ee88f40f41764bf35573528d8a275eae
registry.redhat.io/openshift-gitops-1/gitops-operator-bundle@sha256:a27b8dd047e10fbbd6fc49176036c9b5178a1d2841e26719bfde23239ede157d
registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:a424e822277befdf5d414c5aa5e1f5e359d56c5e9fc5da02e451a59244559966

arm64

registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:82b5c2760800ab618b4d1fbd7e713765181f57123636ecb34d0f700af5b64945
registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:cc5b889fa32b5476f29a9d36eb28de80c4288cbf366e86a3aa82fb4a6993b63b
registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:d2d1a76ff456e08e2b217aa01530b7f6b9fb91c40388cee14c0df77245ac5789
registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:d9b83dd9c9a3a76315a830cb1e995964e697dc025b1d552d1e5bf6acd94f7186
registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:d84d629b8e7e99fca60a227053ea4aae2ada53e1720ad928ebc627465e99b9a8
registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:df33bf847baaeff2432a5e2e22853a89cd15fd8a3f14cabc233b38d3e9dcacc4
registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:7f9756472d19ba870990b7348cd693dc850d333ae2202d56dbdf9d7dd0ff01bb
registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:e2fdaac8c55eefe25f63c0742f8bd14066abb33b7a5f746157fad65b5b99d092
registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:702e2376cbe077fd68686ab54f25be3d2b87696b1cf956c48465f609b97fff8e
registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:049800b51d49a8f5320ed013eea46695eb7f0eeee26459f18a51f5d1023e6a8c

ppc64le

registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:e9197abd503e4a97ef55984334e4d0de594d3b9a5e542bbe475322f966b8fefd
registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:73cbdb023ab9abf39602b4a15f9a68515aad37c14a1bbff060b906570ab9d2c3
registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:2fa4d567a4de620a81f1678596b74fa9bcb3dd060e71549917e819ef4b5a80f0
registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:f988a63f8f11e2cbfef19c9d02905a69daf783ac05e6e9c042f13c697e87479a
registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:e03a5803646011ab083c958f52f8f9d7c8025572e95f522768d260961c72469c
registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:dafab1379d8bf3af9d2794a5d249901a4d045b7ee1e129669001b922ccdc9f98
registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:eb5cfcb3d2da257dcac23086cdef0e16487885c14badf5577f36c22b6e9a7d43
registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:bd3eb63c087dbd5f807b9e7cf680c0de1c3408dd9f12b7eb6e98f8221ca28a8f
registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:87bcc0a5bc2f67d609161d346d3fee760b292db0dac42ef7393dad2054700257
registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:05de1e5e8aeb9bbaab90f03fd3cf1746bc79053de779c45ab850f5592f29e094

s390x

registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:5fb796a21d73e4baf25c8a116c69447ef0d5de6db86b0e3b65df68373f4b10d0
registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:1d6f9b5cdf776ef51e96e738f726d3dd797304ab44bc313ded7a6d280fe12a95
registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:3a250c6cf16f5676d412f11d48ca6e84f5681c899ed75c8248e6dd0184bdcc5d
registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:a5bd0b0d1677ffc3b4117082a91588316d5f4cefba1265051cbad07856f99969
registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:e7561d1e7e220cca0cabb9e28a7a9594a1cebf771546382e6302c98a79d82e7e
registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:94793fe05dede5787dacf889f6e51e9385d3b312e7500514f88ea6fa608b0089
registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:cc6ca27fa4823083354c3879efb3a2733f377965528fda892cf1aa7823cc35ea
registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:b0369e0bddef1a52941482bfbe88f72674de51dfcc7f30ddb98b410476ae4785
registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:a2d7c119c287bc7ab8751d4435b7e80749618abf4d98a2704a3f786d239dc86d
registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:9c79c05230debdba71ef6cefc26e39b0a5134fbe00aad9ce667c277aa8e34228

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility