Red Hat Security Advisory: OpenShift Container Platform 4.20.24 bug fix and security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-26996 — minimatch: minimatch: Denial of Service via specially crafted glob patterns CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-41674 — xmldom: xmldom: Arbitrary XML markup injection
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:0a3df673b88932dca4e45598f4c2045119e68d3c1f2e7a223c05dec94cf06bd9_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:705aaf7c7a6f751c6a661de7556f6765662846b3f87766bd9c2f25b8ced86914_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:b33f5383a6bc9f12b720f71ab513f08c825182ca2c780186ba11111d6eca6960_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:f573528ddbc512f274ddaf60405b7377aeb934586e5c9e763814f11d4e563ca7_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:0e687f3dd4f7b74cbae872115c03d448a50f684f2dbb611c6ddcd0456b8cc93a_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:110e8070be58db62224155a9f7a0e34921f68c53526cb78c8ad115e850a69e71_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:359bf7ede4e6891821f0e2f28c275c4d6c13b7c4476f4a21cc20d1676c14d5a5_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:5cad2263312e15bee4dbf5e77735ee5c6f0b24be002f7ce1fd749d1da499be88_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:5077d261a301ff52c933c6772086d1b6bd82fa65063724059c7ea944cd902bcf_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:68c102a3016115109e479c471bf5ff8b1a4bbc27c830d5d020f2f7fef82cee3f_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:85302a78a0851c3f65364e6c14e590f45a340f45a567035539150482bd4dd8a1_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:926f9a82c9f96778e103e0218476cdb9b1bef8b53484ca4d38ea34c091be794f_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:1dd34fb17e32f5212425ebd6c4ecba9ffe15be128758944e51e90b388fc956df_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:5013fb75f2b2551bd0398ea8b907c57a56ae83a597257a563b27af3d0c36163c_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:c8359fb24ce81097c43b42848371a8ebdfbe20cb54cbebac7a9037f42f5a6ab7_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:c95639051bd96f293a30b7924fbcaae1b3a65c75110a073e61dcc6e825e93c4c_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:4a15ab817ac11cc0ff609ead4ed8ab5ba055d54e426b388d29a5681442be376a_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:7d56e0cdbc7ba19ff32661e7b47bb42907543f5dce5d88b5a3b5cc68451ffd29_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:d0e0fbe1e4c4488de543f472fbc93440ef22814d38e4ceee292d4f8aa476a05c_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:ec4a02ec06764e1a5b7dbf05dca5d72b035d44ff901305a36ce10dc11375da0a_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:40e7ce5ac46bac08a4fde9d48523223ef13ae46d952887ae770b4e44bf564d62_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:5c4367e4bc30d65605f90e96de0c936b1a8605b8fa28ecc9af52ded82cb48bfe_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:97899b3b08fd9b8337a7e67a7f1dfd22f3ca8e9634ee305194143e77a7d2a2d3_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:9f7a4b8f752b713c2a7293d1b9c278f33b63119f35a307c5802a791a905f059d_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:3de325c11e4028d6daa452bda2e607b50023994bf24ab7fbf9c89b3589bcb2d5_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:becccdd3f5f85efa3fb10d05bf6f016e702efaf34fc88862a81996243af6fa77_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ca31c28ffe19b0344704849a8fd28b70f8a13e8329a96e5044a95fd179460d96_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d1e941ec9027bc9787e8bad216ac0368378e6f42b4db425af6746fbbd7fa6e1a_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:12c36b222ea6e81c10a393f47a45ccf42061c5ae0bfc38ec8d925d6311844852_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.20 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:27c93d3b308e9c3694dd7e448d71f61e4e3c033ad8905031736bd1912c1f41fc (For s390x architecture) The image digest is sha256:588f4ba99d745826e618e72a66b8f81f671f7714263a5fc5e830e1f66942ca55 (For ppc64le architecture) The image digest is sha256:b96960dd4a50eae41f43ed029dfbdbc53737f72ef7c4d0a062d0fd2802875bd3 (For aarch64 architecture) The image digest is sha256:9cbee5f3e59dc3431ea30d2e337668f8abed821be651936afa99e6767cf39108 All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:21703
- externalhttps://access.redhat.com/security/cve/CVE-2026-26996
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-34986
- externalhttps://access.redhat.com/security/cve/CVE-2026-41674
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_21703.json