RHSA-2026:20042HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.19.32 security and extras update

Published
May 27, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-15284 — qs: qs: Denial of Service via improper input validation in array parsing CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

🎯 Affected products186

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:0492f2136de425ae5f550c630063ea0c6334f08cae366a2e972ef58e5b7df453_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:396d08aaf9e702051cad60c200eaf8f8efdff5d66f65418bf29855633b889234_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:b55391537ed08ad5c14c970f8ae5d4ec0e89a6ec27ab3f96083a553b53a3666e_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:dce770737022468b5377772865a1c3db98938107c0076b42b4be5a3f7c9c6119_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:1abd94fd0df02c43e57e2416b9e237e0db9213c5a086a9fc940e533293c44d86_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:cfb19b06ea2d545b82522a699d29c4291adade0d2aa95b9cc2fba2694ae8f644_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:d60a7ca02c6ade0c134f8a74bdc54ccb317f8bd730414d237f63fecb0b1091bf_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:f864d8f4fc2833a1a58dc4fe5002bf2b3b6caf81d4e07a6ed08379c7570098fc_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:32dd493a4b127dc3e4649c66b93932904270868e00b41e1e039bcdf441c89ad1_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:79d9ceb8426a39db2522f04b3d08730a5a08dbee1b89b8e34bf28a21bc5cb06f_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:8b6d95e8f5c2e68cb6239ea398e2dc2874008783ad43687e267638b7e84fb7ea_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:965bfb5c1d2db83602c124571ecc65064c1634086fc462588e12b79aa40425f4_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:514e73b393ad8a99fdb3b63941536793010c9760315f6ea20403454adf5eda23_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:88fa6fa136540eae1107aa5200c7784ace6789a24aa363fcbb285cb4fa8c05ca_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:a5116459d9ff3b6b610a338abc234f7c9643e785c4d8398ec8196bc903a33434_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:f3921f06cadc4447210a346a2f340914fa208588185af14b871167296f5a292c_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:9fade34cc41cf4eed006984d01ed8c17e581771b35adad13d8849d9588eff559_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:9ffe883b6b2a93c6d9e705d35a2004903b8e598a654335e1c744aa5f86435738_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:f7310301d53f3efac59da8e34822481adfc132751b749ba8864581cc78cbb983_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:ffbce26961ead24294bb533a3d3037496577f09335a9fcd432dc02aa7c68c207_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:22e72023133b56918476abdd1fd56002a778da198f0df9123e282f89029433b1_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:60972294f7d961edf7d8df134006117061072b0522ad23c479da59c57bdcba68_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:deb75808f1e65ece60f876a6b34eea92ed650ab36373125c5dec71e18d12a10e_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:f58015b051fe3d79bb67e1109ed4b4d5dc360612ea07149003a03ebce9969856_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:19e1e4ac831078b2a48f1ad34134e4d0fde03448e3b1d5f76368e0572873614b_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:55ababf314cef27581a63a66d6300c0b74a1f829fa7a641a23969c65417fe81a_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:be9fe30c3cef6ec2279e294eae9416e5875edffed088055caa1b74e0d48f2536_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:dc3984c455b4bd4b8bed0952c895abba3109666177bf9b2ae67a15121c569b8d_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:3946dd00b733ea0f4fbd404a43dca5d06a46136418847ea3a82f3940d023e8cb_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • +156 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (11)