- Issued:
- 2026-07-21
- Updated:
- 2026-07-21
RHSA-2026:43038 - Security Advisory
Synopsis
Migration Toolkit for Applications
Type/Severity
Security Advisory: Critical
Topic
A new version of Migration Toolkit for Applications (MTA) is now available.
Description
Migration Toolkit for Applications (MTA) accelerates large-scale application modernization efforts across hybrid cloud environments on Red Hat OpenShift.
This solution provides insight throughout the adoption process, at both the portfolio and application levels: inventory, assess, analyze, and manage
applications for faster migration to OpenShift via the user interface.
Solution
Before applying this update, make sure all previously released errata
relevant to your system have been applied.
Affected Products
- Red Hat Migration Toolkit for Applications
Fixes
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- BZ -
- https://redhat.atlassian.net/browse/MTA-2782 - MTA UI - Importing invalid questionnaire shows wrong notification
- https://redhat.atlassian.net/browse/MTA-6211 - Analysis on Gradle application is not raising issues on dependencies
- https://redhat.atlassian.net/browse/MTA-6371 - [Assessment Actions] Action buttons are flickering every few seconds
- https://redhat.atlassian.net/browse/MTA-6478 - (QE and Docs) MTA 8.2.0 Release Activities
- https://redhat.atlassian.net/browse/MTA-6553 - [CLI] Proxy argument doesn't have affect
- https://redhat.atlassian.net/browse/MTA-6597 - Application Migration in MTA 8.2
- https://redhat.atlassian.net/browse/MTA-6722 - Kustomize
- https://redhat.atlassian.net/browse/MTA-6723 - Migrate cluster-level application workload dependencies
- https://redhat.atlassian.net/browse/MTA-6833 - [tackle2-ui#3042] Preparation - migrate components depreacted in PatternFly 5 to newer version
- https://redhat.atlassian.net/browse/MTA-6851 - [tackle2-ui#2172] Upgrade to PatternFly 6
- https://redhat.atlassian.net/browse/MTA-6855 - [tackle2-ui#3044] Improve e2e tests
- https://redhat.atlassian.net/browse/MTA-6857 - [tackle2-ui#2856] Remove unused code
- https://redhat.atlassian.net/browse/MTA-6858 - [tackle2-ui#3111] Jira ticket not reflected in UI
- https://redhat.atlassian.net/browse/MTA-6859 - [tackle2-ui#3131] Migrate single-select typeahead
- https://redhat.atlassian.net/browse/MTA-6861 - [tackle2-ui#3132] Migrate multi-select Select
- https://redhat.atlassian.net/browse/MTA-6872 - [tackle2-ui#3202] Migrate to current OIDC library
- https://redhat.atlassian.net/browse/MTA-6873 - [tackle2-ui#3212] Replace duplicated implementations of the multi select pattern
- https://redhat.atlassian.net/browse/MTA-6882 - [tackle2-ui#3217] Check only for HTML in the negative Jira connection test
- https://redhat.atlassian.net/browse/MTA-6883 - [tackle2-ui#3223] UI | Add pages to manager users and roles.
- https://redhat.atlassian.net/browse/MTA-6895 - [tackle2-ui#3223] UI | Add pages to manager users and roles.
- https://redhat.atlassian.net/browse/MTA-6897 - [tackle2-ui#3224] Inconsistent verification of isues created in Jira
- https://redhat.atlassian.net/browse/MTA-6918 - [tackle2-ui#3247] Automated PF5 to P6 migration
- https://redhat.atlassian.net/browse/MTA-6936 - [tackle2-ui#2840] [QE] Get nightly CI tests passing
- https://redhat.atlassian.net/browse/MTA-6941 - [tackle2-ui#2840] [QE] Get nightly CI tests passing
- https://redhat.atlassian.net/browse/MTA-6957 - [tackle2-ui#2509] Application inventory: Bulk change application source platforms
- https://redhat.atlassian.net/browse/MTA-6984 - [tackle2-ui#3237] UI | Add /oidc proxy route.
- https://redhat.atlassian.net/browse/MTA-6985 - [tackle2-ui#3238] UI | Permissions instead of roles.
- https://redhat.atlassian.net/browse/MTA-6986 - [tackle2-ui#3248] Stabilize newly migrated UI
- https://redhat.atlassian.net/browse/MTA-6988 - [tackle2-ui#3255] Migrate static reports to PatternFly 6
- https://redhat.atlassian.net/browse/MTA-6989 - [tackle2-ui#3258] Adjust art work/UX design after the migration
- https://redhat.atlassian.net/browse/MTA-6990 - [tackle2-ui#3259] Fix Monaco editor double scrollbars
- https://redhat.atlassian.net/browse/MTA-6995 - [tackle2-ui#3262] Revisit and update e2e tests given the new OIDC auth flows
- https://redhat.atlassian.net/browse/MTA-7026 - [tackle2-ui#3287] e2e - update the initial login test and login beforeAll to work with hub oidc provider
- https://redhat.atlassian.net/browse/MTA-7027 - [tackle2-ui#3288] UI | Support token revocation.
- https://redhat.atlassian.net/browse/MTA-7056 - [tackle2-ui#3336] Update e2e tests to create users from OIDC APIs
- https://redhat.atlassian.net/browse/MTA-7057 - [tackle2-ui#3337] Update e2e tests to create users from OIDC UI
- https://redhat.atlassian.net/browse/MTA-7058 - [tackle2-ui#3338] e2e - Manually test patternfly 6 UI for any misalignment and any UI issues
- https://redhat.atlassian.net/browse/MTA-7059 - [tackle2-ui#3339] [BUG] Login loop with hub oidc on fresh install
- https://redhat.atlassian.net/browse/MTA-7063 - [tackle2-ui#3343] Add the remaining tests of architect.test.ts for OIDC changes.
- https://redhat.atlassian.net/browse/MTA-7085 - [tackle2-ui#3349] User cannot edit their own user resource.
- https://redhat.atlassian.net/browse/MTA-7086 - [tackle2-ui#3350] :bug: Token scopes array parsed as string.
- https://redhat.atlassian.net/browse/MTA-7094 - [tackle2-ui#3359] The scopes column for api-key tokens seems odd.
- https://redhat.atlassian.net/browse/MTA-7101 - [tackle2-ui#3366] [BUG] No confirmation dialog shown when deleting a user
- https://redhat.atlassian.net/browse/MTA-7138 - [tackle2-ui#3397] Add login pages.
- https://redhat.atlassian.net/browse/MTA-7177 - [tackle2-ui#3428] Use tokens/:id/revoke
- https://redhat.atlassian.net/browse/MTA-7219 - [tackle2-ui#3425] [BUG] Success notification is shown twice on editing a role.
- https://redhat.atlassian.net/browse/MTA-7220 - [tackle2-ui#3445] Adjust scope handling from `/permissions` to `/auth/scopes`
- https://redhat.atlassian.net/browse/MTA-7241 - [tackle2-ui#3445] Adjust scope handling from `/permissions` to `/auth/scopes`
- https://redhat.atlassian.net/browse/MTA-7336 - [tackle2-ui#3129] Migrate PF4 tables
- https://redhat.atlassian.net/browse/MTA-7337 - [tackle2-ui#3130] Migrate single-select non-typeahead Select
- https://redhat.atlassian.net/browse/MTA-7338 - [tackle2-ui#3133] Migrate e2e Select tests to use test IDs
- https://redhat.atlassian.net/browse/MTA-7339 - [tackle2-ui#3134] Enforce no new linting warnings
- https://redhat.atlassian.net/browse/MTA-7340 - [tackle2-ui#3135] Increase the number of e2e tests run on PRs
- https://redhat.atlassian.net/browse/MTA-7341 - [tackle2-ui#3141] Skip all tests marked with bugs in Nightly runs
- https://redhat.atlassian.net/browse/MTA-7342 - [tackle2-ui#3142] Enable slack notification for Nightly runs
- https://redhat.atlassian.net/browse/MTA-7343 - [tackle2-ui#3143] Move all analysis tests to Koncur
- https://redhat.atlassian.net/browse/MTA-7345 - [tackle2-ui#3200] Identify filters by IDs based on categoryKey
- https://redhat.atlassian.net/browse/MTA-7346 - [tackle2-ui#3207] [BUG] Take assessment button flickers
- https://redhat.atlassian.net/browse/MTA-7349 - [tackle2-ui#3302] Include offline_access scope to OIDC client request.
- https://redhat.atlassian.net/browse/MTA-7351 - [tackle2-ui#3354] Fix CI failures due to auth token
- https://redhat.atlassian.net/browse/MTA-7353 - [tackle2-ui#3405] /auth proxy route missing.
- https://redhat.atlassian.net/browse/MTA-7355 - [tackle2-ui#3425] [BUG] Success notification is shown twice on editing a role.
- https://redhat.atlassian.net/browse/MTA-7361 - Enabling insecure Maven repositories doesn't work in UI flow
- https://redhat.atlassian.net/browse/MTA-7381 - [tackle2-ui#3461] :seedling: Configure explicit permissions for workflows
- https://redhat.atlassian.net/browse/MTA-7398 - MTA CLI introduces reorganized commands and subcommands for improved usability
- https://redhat.atlassian.net/browse/MTA-7399 - Hub OIDC provider for built-in authentication and authorization
- https://redhat.atlassian.net/browse/MTA-7400 - C# analyzer provider uses .NET Compiler Platform SDK (Roslyn APIs) for enhanced analysis
CVEs
- CVE-2026-13676
- CVE-2026-25681
- CVE-2026-27136
- CVE-2026-28684
- CVE-2026-33079
- CVE-2026-33811
- CVE-2026-34993
- CVE-2026-35397
- CVE-2026-39820
- CVE-2026-39821
- CVE-2026-40110
- CVE-2026-40171
- CVE-2026-42266
- CVE-2026-42499
- CVE-2026-42504
- CVE-2026-42557
- CVE-2026-42561
- CVE-2026-44431
- CVE-2026-44432
- CVE-2026-44727
- CVE-2026-44843
- CVE-2026-45292
- CVE-2026-48526
- CVE-2026-48710
- CVE-2026-48746
- CVE-2026-48990
- CVE-2026-5422
- CVE-2026-54283
- CVE-2026-59939
- CVE-2026-6322
amd64
| registry.redhat.io/mta/mta-analyzer-addon-rhel9@sha256:1e20ac649ee7fdcdad9930b1f0384e10c8794db9a2f211d4e3d1679c0c10cc53 |
| registry.redhat.io/mta/mta-cli-rhel9@sha256:d466bf042711b13fc53cbc561b70e4f58cd77f8a05d1d4ee10c10a6e1c201fe7 |
| registry.redhat.io/mta/mta-discovery-addon-rhel9@sha256:a72cbf7b2ba6420e31ecca15f7d3628a671dd642a6ccf4610c5a26462a5d4b36 |
| registry.redhat.io/mta/mta-dotnet-external-provider-rhel9@sha256:794180378ddb9a88001d76b849df305034924683a79ef145f744fe03bee9c32b |
| registry.redhat.io/mta/mta-go-external-provider-rhel9@sha256:8e5ba3659ef5f88b81c1c9d795b6af6048fd7d870493ce5f013efcb9fce90b9d |
| registry.redhat.io/mta/mta-hub-rhel9@sha256:2e251b0343327f2ac6e60d2888da526be6a82a355310f1aea93011426cddc485 |
| registry.redhat.io/mta/mta-java-external-provider-rhel9@sha256:e8bd699e851fbab4466d1d25e3a08e2bcf8997978cb7f19f509c627be42d03dd |
| registry.redhat.io/mta/mta-nodejs-external-provider-rhel9@sha256:12883516af95bf0f6abad1556d22896f16a087c1e4191fedc1f5d689cf6d67f6 |
| registry.redhat.io/mta/mta-rhel9-operator@sha256:3926f791376886972749cae0f8eb635af67a088811214066c6deb010c6b762f0 |
| registry.redhat.io/mta/mta-operator-bundle@sha256:94f88bf557a036c54b348c2689c699a720d5d347b1bba141feec273e624ccdbf |
| registry.redhat.io/mta/mta-platform-addon-rhel9@sha256:f421044ff3d6911097aebcbabfac87ddad74987e0e5f18a96dd89454f46a4cdf |
| registry.redhat.io/mta/mta-python-external-provider-rhel9@sha256:4f46867f5ff78e9e970bc572a1a625080ae8faea29dc098d3d7d4355e8350ca1 |
| registry.redhat.io/mta/mta-solution-server-rhel9@sha256:21fab4b77580795980fd60b24ab1d6a3cc159a9246beccd1c19938bca94edd23 |
| registry.redhat.io/mta/mta-ui-rhel9@sha256:a77f5a731c20943958b5f654bf3147b690d5dd608b794bff261a23dd89f785f1 |
arm64
| registry.redhat.io/mta/mta-analyzer-addon-rhel9@sha256:907c0c8c40c1fb494caa5feac439b90754160bf3f79d8e76cf2dded63f549db6 |
| registry.redhat.io/mta/mta-cli-rhel9@sha256:ecae0c1053637d609a19773757c0ea8b336b645950a42473015daabfe9677fab |
| registry.redhat.io/mta/mta-discovery-addon-rhel9@sha256:7377a2c2f16ca436819cbbf106fc27d3a8c44c7fca0a44108ccc826bf8678ace |
| registry.redhat.io/mta/mta-dotnet-external-provider-rhel9@sha256:b5d66f8d4c6d6680886e631296c927c9502817fbb823a680f1dabf1cc92e0465 |
| registry.redhat.io/mta/mta-go-external-provider-rhel9@sha256:8f91d460985e1a97ac6892d26c0517f39871d94d1b3bfad005d58d424bed2b0b |
| registry.redhat.io/mta/mta-hub-rhel9@sha256:0223927b9e584f302aabafdbf015a779b14c9b5816cf0baa0cb1bfe0b1cc3415 |
| registry.redhat.io/mta/mta-java-external-provider-rhel9@sha256:60c4a45085db3517f6a9bae32a4b93fd2dfa799c3e957776ad2d8ab0777507c2 |
| registry.redhat.io/mta/mta-nodejs-external-provider-rhel9@sha256:a89c4d19ff39a406f3279b4ffd6f8d2a2a82a78ab3e9aa1dc0f2c385a24fa844 |
| registry.redhat.io/mta/mta-rhel9-operator@sha256:957a553608cbf9ed108c22f851ef809ed348cf592610851c3a554f3342ba511a |
| registry.redhat.io/mta/mta-platform-addon-rhel9@sha256:647ca556be4338749fbe7cb18580466ce6155bfce17c96deda7b7c037fd16240 |
| registry.redhat.io/mta/mta-python-external-provider-rhel9@sha256:25618ee8a690f336e1604a1b1ca9dd5197bbdea5cd02cfaf588fbd950a8fd228 |
| registry.redhat.io/mta/mta-solution-server-rhel9@sha256:f8c8651cc5fa016003ef4105f28775e0b225472d2c3135e5f37d1e1f748c515e |
| registry.redhat.io/mta/mta-ui-rhel9@sha256:f59dcacb1eed9bcd539bc6c26a630115cf35378d77075247fb42219836e2adb7 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.