RHSA-2026:20088HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.16.63 bug fix and security update

Published
May 29, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-61731 — cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:313c0e44208e7fc7d4039f2f22cd01135db0cd3337a258034b774fd7820d8a98_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:37889fd7ec96baeac0ffcafb8dbf903af16d95b413baf1b2fd7710f72cc71c98_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4a2a59a57ae76ff8ff5ee21dd25da4a9da4faae5a6beb8d5e0930f12f679e8b9_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:99f4af491329b3352e86322a56f42cd4588beeda00a2f94a2b82b169f6328fd8_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:561b697db7976a064794258c5f274566dc9c1c32d803603b15ecdd78a0965710_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:99946bcecef29fccd2dc55cc18dfd5cefef1957666c9b8cd4c555ae9d8db676a_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:f4572abc9f444f08ad11d10168e4b9833b3fb9e4814910eff467767a914d124e_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:fd5aee9ac2b77bcab032dfd1bc6f1369f59e1b3366cfa96fa55f9bc18673144f_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0c10368a8cb2450440348e1047d56fa91013b32b690c40b06baea182f04c3625_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:202f16700daa8022d5675bee872db2a776a1f240ce159d17b9ad91cad342bb7a_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:67c0172273e47f9f11072c1b27a028fabcfe29320b3347d58d35c53d9b1f512f_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:7ce75d70b4ffc0c4891ef83f75a453f414c010e387c09f8d7da432eb5543f032_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:6cfa0e42180d0b52c41ef1f23d98443cc4a89afae97d21d3993a5f69bc73e6a6_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:83cbc07e901f31f4f86938697d54564bd4c735ba924d5fd08f43b2dfac46aa59_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:be5d2df0ea59d84b00bc2a1be257b8338c00f0563397b51d7fe86c48f7e6a62a_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:c91a3c588e78a92df5887828fc6cb03cb28580996fbb5204bbc5e17abf93ab8a_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:3570c5968150582d417714eee75c4fdb244dece7812e772c0d60bc937d81d564_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:3933b8a4a90aefb3e645441e8176d340b8e0b23b3f6760083c72d25248a17e67_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:4dd95c213870b3d4ae9bf202094055f0cac5a965422dab852183305b5d85634d_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:e76c636de412eea5835c877ff862e24c5b0a7ab7fb95ece3fcf4dc9d614bf519_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:10864ad3974315fe717b7e22f5d1fb7bcfaf1b601741e4a0f2a643e1d897fa8a_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:61858d0543de564814db6c98407aece822eea202cc1fec3393913d14f75875ef_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:d4f1907759d9532d9659a97d18282e98c54eeffffc33c7de0570213b545aab51_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:d5bdf20ce7f4c5b1fcfd9c2b77410c8a6b9b0c27e6138a1ab54c241763b05bac_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:546872449f71f686be1dc4612f7e03d75633eea75f089c720f87d5d1c6fd0402_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:6e8813370db2a71161ead738ccf909b6997ca6ec452ba40576f8846c22c063c5_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:81c6745c7507d47122280c0d6893a35a4d4adc515e850b2cdc8d23599583ad71_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:d9778a3fdaac8498f6953cf2bf5acee0d8823270442768c9e838dc5b330c2250_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:5008136f5d3e028da656d046f85c83f3ed13d597dfd47bc6808b5b3043297dae_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:0a3e0b4e23d509a31b7a58162a4336d24c9b899a6de9aac2f930f6b558f9e4d7 (For s390x architecture) The image digest is sha256:818c1d9fb15d05bb7d6104e8aa7fca18bb46666d4eb53951680ef445d752f0ac (For ppc64le architecture) The image digest is sha256:6f2c9e2402f4a8b128c0239e3aee44a4b4735a9d558d18f06fe4e3d4f5bc5c98 (For aarch64 architecture) The image digest is sha256:746dd9a75ac3c9ed743d63b32c12de3484f74addadb1b5a00dbb004918406ba3 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (8)