RHSA-2026:27004HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.19.35 bug fix and security update

Published
June 24, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-40895 — follow-redirects: follow-redirects: Information disclosure via cross-domain redirects

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:39c836045dd74b5660ffb081492f66692c130c349cf1d06df22892c7f903326e_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:84b8e6533185ec7f0f1bc522e22700f9d823095c03b184d0554cbb169777f652_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:8622f9769db33c15734ebdbbac14d354ebf9c3cc508229b8de93fb77652a5439_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:f5dbdb6e850161f1436eb1df39e47868fa5f7340e64621f8530b334dbcd5c6b0_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:1d45f00caffcc5c12f5d0cff5ff72ff47f32c04a02193b66a899e8cf2099090e_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:449ec7a645c00c676c9d3d5c73f4384bf196aa6781d2414d9ebc7769005c5b02_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:54c0eed8f3c8a1ebfd30d3982f5f64ae5022c0ec6804a3ed29bbe2b3db48aa61_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:956b56da404da008aec486cbea63008019427e5c95c2fee88f8922b19ca5f346_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:39eba720cbf26ddc56f8ae6011bdef91b3bd1d3ae8f44b32d25a6a92f4897c6f_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:4b21645b7e796b1fffd92cc02e065877e640edcca4ef8a1cdf1054e58f27ae8a_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:9b97dc391e5f3628ea3368e5a986c11db4a0a2f44a52b60cd56323da8deba488_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:d00faf1d961eec8202f9f6386f6f7f77e68a37e6f13ae5e636b046d6974fae73_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:3aaadafcce86f1934dad2403fdd066f5b9b03ef193b92c41d22d0196a1044119_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:6f504033b7c57eb17665570600d7afac8cde0af8b774af64a53954bd9fbf71d2_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:7dae78af16880c22befcd3d8241566074e9c2fc4efeb7e0b2157f774f98e9996_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d8a8fc00de4fd6477a7fa6ed29deb1ef2a7856a0adaa101d687eb8a979ad33fc_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0fa0f7186db839b460f5315ae183bf4388c11118ba0fc0f961b8a30033efe9f5_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:377e3cb12e9e530130ea9645280493a3890115b594909371ec147462df0fe908_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:57e048ff8a7d5e9d60bbd49c0dc7b031e8ef67bb10151e3d8779ef80b53434f6_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:b09cceb0d2082da89f3981e6c2dda344e3741a4ae818adecff33588bcc4d4ae3_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:5fb628fac3af57cbb8daf5064257051b7f3389d15ac56c176434d130483cd6b5_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:aafe2ffaf3e26b14e4f1dfae9ffb936c789f712b63aca989bda1bffa5e7dc5d8_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:c474edddad3c61e96e019a005e952642e3039ed1b23435c1e9bafe6271896fcb_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:e507fa913f3b3eee67c05d1a813c51332096354bf7009517d0a06ef89b38566d_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:13b1705b8e99ddb611f8f51e152caeb1a05f03ee2d32bbd0145f2a30e70c1869_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:3c9141874f0a032bab193d944f0e81eabe1a94c21b14858e8eafb9de62f95d09_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:91785df8a570ca4255363a5c73e682fcf0a9674cf7a20f71b71c00cd15ad817c_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:a12765c0449b0ee1d105b231afd18eb43ac49193727b2759b061cb133bd08cc5_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:859bf66f2b8aa5684ca95687b0ab9fde3ac93b2f3deae3148e1c5de05bf37a9f_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:dc19d36773923353af81ddbc1dd8c46f83945cdbedabdde23b2b666714d2b27e (For s390x architecture) The image digest is sha256:c2eae1e42edf4f9c9992a1488118d2b9430b4407c7cb81bbd69b0516658ffb7c (For ppc64le architecture) The image digest is sha256:54338e3717067df3d8e9395c0b3da4e1f6fc2b75fde4a1913ed4ee8d8286f3ad (For aarch64 architecture) The image digest is sha256:574803abddc08338e22c2033b122f8b40dd942da47983fe2aa71927f015858e0 All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (7)