- Issued:
- 2026-01-28
- Updated:
- 2026-01-28
RHSA-2026:1488 - Security Advisory
Synopsis
Important: Red Hat OpenShift GitOps v1.19.1 security update
Type/Severity
Security Advisory: Important
Topic
Important: Red Hat OpenShift GitOps v1.19.1 security update
Description
An update is now available for Red Hat OpenShift GitOps.
Bug Fix(es) and Enhancement(s):
- GITOPS-8080 (CVE-2025-58183 openshift-gitops-1/argocd-rhel8: Unbounded allocation when parsing GNU sparse map [gitops-1.19])
- GITOPS-8083 (CVE-2025-58183 openshift-gitops-1/dex-rhel8: Unbounded allocation when parsing GNU sparse map [gitops-1.19])
- GITOPS-7849 (Cherry pick Repo Type Fix to Argo CD 3.1 stream)
- GITOPS-7992 (openshift-gitops-operator-metrics-monitor ServiceMonitor is attempting to use a bearerTokenFile configuration in its endpoints definition)
- GITOPS-8225 (RC 1.19.0-2 : haproxy replica remains 1 with HA upgrade)
- GITOPS-8249 (Prevent argoCD from automatically refreshing to gitops repository )
- GITOPS-8411 (CVE-2025-55190 still blocking due to github.com/argoproj/argo-cd/v2@v2.14.11 in gitops-rhel8:v1.18.1)
- GITOPS-8535 (Show All Namespaces or Current Namespace Only option)
- GITOPS-8591 (Reciving TargetDown after upgrading GitOps )
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
Fixes
- GITOPS-7849 - Cherry pick Repo Type Fix to Argo CD 3.1 stream
- GITOPS-7992 - openshift-gitops-operator-metrics-monitor ServiceMonitor is attempting to use a bearerTokenFile configuration in its endpoints definition
- GITOPS-8225 - RC 1.19.0-2 : haproxy replica remains 1 with HA upgrade
- GITOPS-8249 - Prevent argoCD from automatically refreshing to gitops repository
- GITOPS-8411 - CVE-2025-55190 still blocking due to github.com/argoproj/argo-cd/v2@v2.14.11 in gitops-rhel8:v1.18.1
- GITOPS-8591 - Reciving TargetDown after upgrading GitOps
amd64
| registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:88d3d7cfa9a703b161eb6155eb959afe9ca3608214a58c11520bfda255b2adca |
| registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:d00bfd094c7b46d6064b45f4b090a668fb1fa00ef0f324117637734cc0d183de |
| registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:1724c0b60ac2dd07f86544c8763c4566b4dec34cff2062fceab044f0d38afa13 |
| registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:3b082f03e5dd81d480a65001c7e30c58f3ec6fef0080aea257c6d956e2742a28 |
| registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:65756086c381a16c062ee3f42fa5b89fb2f97c65a28be74d4a3b59a44d6f1f87 |
| registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:5e89db8a8bc3f942e04a0a333de8fea6dffb8fbbce3ac8b8110bb17a72ad0fe0 |
| registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:b451af584644ba4abf602c79a37ed746bc11b4649dcb51178548b3162e40985d |
| registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:d4ee2ee1f25325eee5d67775f84e9d9f7c15f64fdbcffac3a7a6d9a6248d680c |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:ce76e17c80b57dedc63863c4a25a23c097a4a39b45d44e4ed8fb28e31f9e7f76 |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:10cb0b9ed0879212430be4cfeb7279ea3ad33da03606d4d4074865bd7191d260 |
| registry.redhat.io/openshift-gitops-1/gitops-operator-bundle@sha256:b5429c67a872f0d75e927339451bff0a646f55f3cf0ab98f68c1da2cd610fbc7 |
| registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:a1f84fc45c1a771f0927daa1b6eeb8752c21d7afb52f61a8e1861182682892ba |
arm64
| registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:7759a9f38e0870710bafafb9c20c678cda481f1be3293ac2b05533e882916ba2 |
| registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:33856c2a7babc0b55f47ced41d94617f25ccc9611f701f88238b7c4099677a77 |
| registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:5d7271b447c099a9c283677369bbed47cb4b90199e502759726bafd228c98ba9 |
| registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:df1b6884eb846d6cb1fb926963cf6029da3317e87ad618f0659064b3beab4166 |
| registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:dcb742ace3daafa0a67e846ba85c9c3f72a77d1e899623aa89870fa68e16dac2 |
| registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:19f2655fa02dcbd3790cadb89eb3f1d68611a69b1741c63a233567235512e0ca |
| registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:35f8db26ea413d78191362567aa644c5032ba98a30562ca1c3308effb6845b11 |
| registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:3b157cc177ad7cc2e542d6fea0ca0cab023bd69c34a3ebd2625140e86528f64d |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:372f5994380f1ac617e1bc7d3204a19f17b7adda6ffa5b0f0d9ee6f302593b06 |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:2ead8a381bd0f788960da6171a330eccdb18ef08b6e59ac48541ee0439b5f253 |
| registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:16008b0fba09e1fe31f5ded30e8328fe5eda22dc425d3057398be6861f3f6c42 |
ppc64le
| registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:7a1d93b6efd2284984998859de08b44f1d44108ccd90f4f445e769dd228de59f |
| registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:0a21e0f0b30b568deda84fbe54500fe6f3d9f38e66ebf9714ca5d41d7b1ee797 |
| registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:fc0829f0e0f1c67c0bee823936bc5c810ae185b83aee9cb9498e3752340443e3 |
| registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:3b58b1773e11173cce748d2a2272f57176ae234df9757073d3ccd19252c573f0 |
| registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:798f7ce557d6ea32e7bd352bbc08a04d79647041272f249f97f2494e4efb59c0 |
| registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:6bbd09a5c58a72a52512204fa56e644cacfa803a49ea0156a7781a74922bacaa |
| registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:f9b39b2f8f8a3940b8e4f04114d885ef6cddb25a27b9883ebdf369ee8f2f7944 |
| registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:54a710c566a6642a8bbd073d6c5e1d7a83f7eda86aeb57e48ae7b9540944129e |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:6dd634b648ecb6b81d105752cf3ff828d5ea30273ebc7a83858b7018704adec5 |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:53c83466b723be26b0e662b34564c1455dc547f50a3f4414b32b09df3d7ac7f9 |
| registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:b0a527df75185d6a81aa428a240acb7dc1038dd180d25caccaa64e0ccfeb201d |
s390x
| registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:f54fef4154d85375f9705b001b4aac6fb5ea51bee62970d218c3837fdec3440e |
| registry.redhat.io/openshift-gitops-1/argocd-rhel8@sha256:eaa9c06f5c981a446234152ac20c1fc0015588afd1e800c5276678a2ccae02aa |
| registry.redhat.io/openshift-gitops-1/argocd-agent-rhel8@sha256:7f05064d5cb0133a91e5f1503bd886191375bd1fd510d87ecea920e134e6ab35 |
| registry.redhat.io/openshift-gitops-1/argocd-extensions-rhel8@sha256:3c156d072f3f6c4decfdb07d4373037eee46d86a85086da963f01b9f8c74ddce |
| registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:b2780b4049e679584e23f86b7ba5f5d8c06d034b7143608579fcba4717d0a0b4 |
| registry.redhat.io/openshift-gitops-1/argocd-rhel9@sha256:691fab71b855295cdc85531c591e6fe991c624849cb526e525e768e3cd70ca43 |
| registry.redhat.io/openshift-gitops-1/console-plugin-rhel8@sha256:7d7d3de55d0f77b90cb36100a2d4dc7c28f916331e102d4ba75fad5474b51ea8 |
| registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:d1f43091715a743516b2340504f9f085066bd788f0e31cacede7c1268aa2732c |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8@sha256:e7bffd143cb74ca3c5271a7b6db5c0350f06c09ec4ca5975f16a6a4e22938a6f |
| registry.redhat.io/openshift-gitops-1/gitops-rhel8-operator@sha256:c627dc7566bb1fa65090e9f9e221b00c79ece92be2d8a7278e560aea8357c3bc |
| registry.redhat.io/openshift-gitops-1/must-gather-rhel8@sha256:11200c396dd2554843664e54ccef829e15711728b66dca4bc2099ba3c67110c0 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.