RHSA-2026:17598HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.17.54 bug fix and security update

Published
May 20, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (12)

📋 Description

CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61728 — golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip CVE-2025-61731 — cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive CVE-2025-61732 — cmd/cgo: Go cgo: Code smuggling due to comment parsing discrepancy CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4d3f29e853f08fc1340ce799cda18295a3d78a58c4be2c1b8521695061dacff4_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:c882b23a713a2fb8496de74d7cba1d11b46933d1ccdc75a603a4a8d54b2b7e71_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ea1aa758ed01194c6cd2e4cd758c9bbf933b5a808fb9a41b9390254d155b5f10_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:f44acc6e6cfafdcd7ab2839c67167e10d777e7fc692ea33ecc7dbbcf1d29488a_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:09994f0e8e85f40b6b727aebef3dd226d4992d14f5a4943cf983a1539a387c5c_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:6c4a3e37025b19011bef745a1f8ca17ef0cbfaeeb547a67d5117b6eb6f33633f_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:9a93dceec52a64c01a0d15a7ca8a11abb2886df11a164da406ba33d8c11674e6_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:ff87ede8468d589c40c74be1612c4bdc6671449f67d0966bd7f6daba8189750f_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:22f072047b6652847a142ef454f9f2203aa5b27ba4ee363b9f9f77d47ca1ccd6_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:46603bd410dd65aabc6529abf9b854a3ee9cb6241bfe7144638b308a7198221e_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:db05a114c7e2ae1e60dc04c48a39b16fef4c5bd101c309550b83aaa765e85750_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:e8c58b867e0c1afe501a46fe8ba8dba7e37f19fd7debc7f4cf14afbc4b4e40ed_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:1bbf209c6a30147eedee7e2874814e35419fe734d8485f1a299c2ee4d6d27154_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:86ab0322c34e166c0338b0aeba62eee8e5796b17f851e1c34ada659523ef889b_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:8c42329a4b4214d27b5cedb6e8c35bce66e443f40cd4fb39054a9fb91a86e19b_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:e90246d944ddf42502ded9dd28b740f92766e19ca6fba875d2862167fde79791_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:2d76c30feb371c8c35bbc55afe940985d49ee82e9f21a57eaecc9f0617ce2ceb_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:6486e6a9e19fcd36b9cc80eefa4efcf6b5bf8211240d7afe3eac9150c962b2ea_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:9f9c9d9ffec1703e2b34efc61f1f40d9b91b74614319b6aecd9b9d918c1e0b3e_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:dc72365fd58fa4c55190d9adeb165f66ee30e207265179443d667d18554dd026_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:3ff249ba9002eddfb23d20337126e5696e3ef1778d2259b8c02a39b18ce31719_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:8b678d1aa700153d64ed1de3f81c019646eb823a1aaeba22832df8774c612299_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:bedc147a57bd75f377d2d51912a04e790c9a6c2cb101199301b391f0d1d0cf2e_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:ed70fdc4c7d86e98f09284cac230d1b34b38944524461aa080bfd26d9980f6eb_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/frr-rhel9@sha256:0c1f86263c19354f3b60771c9b48c5ed9054ea41f1d0d6f50dc0030e4ed7c3ca_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/frr-rhel9@sha256:409db66be5b4c06bec6a5e9d6b1e7eb3d4733618c35378f33e53b7314bc9bb66_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/frr-rhel9@sha256:c3aabbfb3ea64e9f7b6d3754abace887e728e4f2df602bf8db1b2797ca830472_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/frr-rhel9@sha256:c7a329a2f8e1607b551d21773b20bbd18a172e24ec36ec18008c8060a27d7b6d_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:0d9d982295f7e40a8117ae0e37507718c8fbddecbab6d8d168fba7b8c40d9d04_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:09a398636aed764ab301bcfc26a2426b245960573b3dcf6df7773688f3b7f229 (For s390x architecture) The image digest is sha256:342e23a21943f52b0ba49f84a0a5d5f24dd725dfa3d199d023c8248c6782e71e (For ppc64le architecture) The image digest is sha256:373f67f086138dc5b0c17b17ec480bd73103b55d2b6e9bc448bbf8b857ef32df (For aarch64 architecture) The image digest is sha256:878e99170a31c5474304ddefd7e86042d2b60459a4291c4bb98cc8bf3257d44c All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this vulnerability, implement a timeout in your archive/zip processing logic to abort the operation if it exceeds a few seconds, preventing the application from consuming an excessive amount of resources. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (15)