Red Hat Security Advisory: OpenShift Container Platform 4.20.26 bug fix and security update
🔗 CVE IDs covered (12)
📋 Description
CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-40895 — follow-redirects: follow-redirects: Information disclosure via cross-domain redirects CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name CVE-2026-46579 — openshift/router: openshift/router: mTLS client certificate spoofing via unstripped X-SSL-Client headers on HTTP frontend
🎯 Affected products94
- Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:3bbdf23c749d068f766d18fccd5e5ae23ff90a5565d8f5101b551113cfb6c123_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:979314a23724ebc8de0be49aa32b8f420179125c695ca48549f541e59337e1b2_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:98636cb3a8c474d6564ee277234bfa6f8bd4bc74a8a5327c4eb21b26c2c9d626_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:f7cbd75d0671200c3af39c481f36478676c328f47692c1f2c1b46429470eb9bf_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:3cb1ef218d08069307b9cb1013d1a3814567df8ec55f64ddd9b72f5790a03f3c_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:450a1c77d36771a98dfa96bb128a066192871becc7ff3edd5da3f9839de5b87b_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:647e915e236daa81b0001b61dcfdbea5cb999a844ec0d52f7d0dd4e224cbcbb9_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:bf4b64740a63a1f6e541d92128c9237fdd813a52536ed1273983946e3c215f7f_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:203ec72895a613490e467305fd2ad96e620d4ea8631b44117be4f7227cb3d162_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:86e58cc04993c9ebb62ff13f8c9e38fcb1dd1bbdd7f5474a8c6de3a73b628492_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:89275d5e3701e681b789e2c80377bdc124c617ccf1fea892fcd9342647ee4e13_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:8ec539591813dd64b6e220480649aceb0f20ac8dbaccf29f5852805fe2d653c6_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:06e3ee0cbdc2f1b3ad5e51bacf75c05cf7f156f8ab0ab451ae0d7849095c35a4_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:8dc3a7e099280b53633b6dc3bddcade1de7720e6b26689b99b13f146675c4f5b_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:e926f2b13e47bf18d2109a39fb2023f112df68ce206f797f60aabe688b203bde_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:ecd2f1b4154e0e1a82956378e620ff618383e341b7ad7571c4c1fbec55a2db5b_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel9@sha256:29d98fcb36f650c7bc94edf306894f4add6d8470dd75ef1b9d2f86a96f7eeefb_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel9@sha256:b3a9fee448a212907122556f9d2b6441122cd09f03fd85b953db0f06527cd841_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel9@sha256:b9a359fca4093efb9deaf581963244e67abfc7afc3ec6df558cc1525adaed085_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel9@sha256:e6d546338774b75c347f1c00f01897d2c18bcc02aae73801c888a1c0bc7159a9_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:fe589677a60e47f089add4a8662d7a5bb018d149bd40951450afcad9459d0868_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/ose-agent-installer-utils-rhel9@sha256:0265e523cbb12746ce518597e1f2ae8dfed5a4f108410d74a284429511d7dd80_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/ose-agent-installer-utils-rhel9@sha256:06833bd27e40dd3a770cac2b4bc943cbbcc005409df8bcb8da465c2f4cfe25e3_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/ose-agent-installer-utils-rhel9@sha256:3e44064c6c2f51f5d59267cb3be081e525227b412f84cdf982239a7340c5a0b6_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/ose-agent-installer-utils-rhel9@sha256:89c39898050cee289a3d05bace758ad4551a9dcb4b55467dff1b70ef304e227a_s390x as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/ose-azure-file-csi-driver-rhel9@sha256:7b5d98fb5c01c84f70fdd05e5ca4ea35f580eacf123fd70744dd207e90ac8ecc_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/ose-azure-file-csi-driver-rhel9@sha256:dcb687dac46dfcb5190a00860a358b63304e344ee233605c69442ae784df50a7_arm64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/ose-cluster-ingress-rhel9-operator@sha256:5571dc60fd35ac8fc45f1632859804ec7f6b261b131bd8a1f68ab4de49c79a08_amd64 as a component of Red Hat OpenShift Container Platform 4.2
- registry.redhat.io/openshift4/ose-cluster-ingress-rhel9-operator@sha256:638bf4691fd54f1854134c0a350a18956f2d4e33367775c35882bbffad8a085e_ppc64le as a component of Red Hat OpenShift Container Platform 4.2
- +64 more not shown
✅ Remediation
For OpenShift Container Platform 4.20 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:5a2bec1f74236deb9519ab5232146c57d2afdb8f8db6773abbb50027150eb8ad (For s390x architecture) The image digest is sha256:168bf6fa86ad2dae55203e833352d47a1284c4db4f42a87bfe8555da97a4f5b3 (For ppc64le architecture) The image digest is sha256:df8f0087646c952daae01c4f5ab625bdb95b317cfa790f6841309e8d131c6f89 (For aarch64 architecture) The image digest is sha256:2e98640a8f567bb8aeab95719d0fea4048658e7edb093377d9ca08262d4e53f0 All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2026:27063
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-34986
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/cve/CVE-2026-40895
- externalhttps://access.redhat.com/security/cve/CVE-2026-44486
- externalhttps://access.redhat.com/security/cve/CVE-2026-44487
- externalhttps://access.redhat.com/security/cve/CVE-2026-44488
- externalhttps://access.redhat.com/security/cve/CVE-2026-44492
- externalhttps://access.redhat.com/security/cve/CVE-2026-44495
- externalhttps://access.redhat.com/security/cve/CVE-2026-44496
- externalhttps://access.redhat.com/security/cve/CVE-2026-46579
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_27063.json