RHSA-2026:17599HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.17.54 security and extras update

Published
May 20, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-24049 — wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:3fbb20fba2938bd8cb694453491504be9fc79d8bbcba8a6c1feb9e825cc96724_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:5dfdc0780b1d7374e03804d73d80d078a03223e86b368bdb533abde1cb93100f_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:8329629d25a54f20353e2710e6270d1befdfe41ad7713be680200917535af81d_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:8d7256b0b8efa33080465f67f671ef6894d95ee1d59086c486521a5d9b547422_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:3e14e9126bbf014a91baabcd84329b8d9ce9f4cae1507dbd36af425c7ec4e66e_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:739bb0da1dd04a07ebb83078f3d066ad84e77b19113a8136a119c52d71061f24_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:819da5ec766f12bead4ef828918bb4ba33f4f81d125a000463c606f4ebb9be0f_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:fe351ecaac736a275d3aad0daecf32034805a2d37ef03333cb19b7c28b6ff829_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:1fb16efc55da3e21a9b6930ee1040b0d2c12b89cd61bbd9bd41107d4222b65e5_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:5bc2486a07329f9074916683f1146376f9fb7751c94d0b5e76dd24559f6793c1_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:8b4dc202d0a6f5edef298a5bebf2fd923aaf5d5e021d8566c915856ddbd82db3_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:eaa5e16e9bfa0dfebb2e881940488cc39da7f9d36351b53f3ca2a84598695d79_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:05c00a99057a2a5d415d0d580a66631d4ca633556473f73cf3a1aa2b2620344f_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:06527d96dc9b77876e99f98cf30459e911578757015008fad077723b7bba4583_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:231017c7163ededa886396f7b61036f619fcc20dd0a8244a4608da7814708699_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:cf54e391130525f4cd045516ec51b4768d1afb67d29668c41c7c01a67f172167_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:2a5487d6811d46a202b02607ae37dcffd18af05956ee98c136fe7c49820f9e80_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:37452cb9e37677a89f38e44bf109bf080ddd9926dfd0e86fd0dd34a7ff8f67d0_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:43c8d408e17840f667279005615261b8f8069a1bc43c79a70a049f9c322af1b8_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:b230e930de7370fb0dcc6d45d06c504ce65995113fcb6a9701abc526a228c4b8_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:1728cd941f1292705619cc65075866d12b2a8f89bcdc3f42f839b42c8c6b0af3_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:28c7a2f7eaf222a682e40858c2c4cf6b337b97cd3bc20d1a6fe40376e141771e_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:2f267dffe47b4ce68be6cb8f7c5c2e5055b2b4ca52d32d1dbcf63873e2cacc0b_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:ed3285d796933d9de4e72beed352f4a2f129412d3dd0894c7753fef01cca0cd2_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:2e39806832955df5bdc09bd74ddce57f8eaca09ec31fb2ce9f8b9b3c3636d9ea_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:62573f078c9db698ee4860412568e5d046a404d54b4c197fcc415ae04f3447b6_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:884cfa9faf7b106f3451cc25a38b16c471322221576b193698e48be113ac89c0_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:f0d5e9e7cabdda534f75ed2a79ec8efa7c3518e87c3e4e1cf76a38107303e291_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:27a2c7482978047fd3e20c69a0426ee95d99e3aef7d422a1d6194c00a096bc13_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • +170 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (6)