Red Hat Security Advisory: OpenShift Container Platform 4.16.65 bug fix and security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34043 — serialize-javascript: serialize-javascript: Denial of Service via specially crafted array-like object serialization CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:7e2d8b16a20e873d3936acaa4efd4491449f5d1dd2281fa4eceb8669733c67bd_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:96559504690cb136feb006697dbc87beef1bd98a8e7b72b287e486a2cf88e683_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:e53ecb614f56d4ea1637cc11e97153adad62e2bf7bf432d5053b049741782253_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:fe86e36e7ba07a76344ca75578df95f0723f35f3725a46c92b2d5f961ac55328_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:0d7f06db34e2e4b8f60745ce410e401cbb3081766495801b45546dd0656e6cef_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:154f01cdef7a059fd6ae2997faf29863f7382c7f55d20c12d2ac483b162cfbb9_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:176a57250b6da5829f76ec6daf914b92d4ccf3d0e7a7e2cb658ff329ee9c703b_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:5a772f38642d25fd20b2ca3bb09e0dab4182335f5d7ff20643faae3a2006ac5e_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:1bfb7621fa373ad5743de82c09a2a291e00e75a7549e3d664946fde82472eba4_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:36908b57350e9b45fa5e7a904df192f3a0ae6c5fea9fe79f12bcd15788c9fd0b_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:a7b43bee0fabd5ef4324cd63ed63c8325ff54b6026b7f3b3788d1576921539d9_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:ba9e1c0ddb355bf4b2f79835fdf0eea2810f278f9d841e156f8f1e5b8f533eb5_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:0f29bb5e5adb8c9a926eb714d579fe57a7f9159ea5e01ed8e10b7daa9404fe64_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:651cae7e99a740a91598b409fa003ccebb151622061115e2405017926c742748_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:6c3a8e656f2c08dfb4faeccb2f5dd50e7b832a7e517a8e919c076a8aea209bd3_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f1ed5b9e1705461b876e262bec30d7998588f9e2307644d8eab730536a35e010_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:0631d59565a610d1dd260be6519e7c4edb45c478ede09a7e22c1d23a3f349437_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:4e84a829c352550ff4e8aea39dfedafb4dd7cec264c5de21be8b971b6b256a95_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:7692a1d89c7083964c51e8b8d8fab0c4a28049323d59f3aeaf05201722a7df37_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:b7f414eb090f11562c4d3116d45c4f256ed2798943f88eb7ec0f71cc1a7bef86_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:05b9cc47186b2ce292576954d5fea2bb20b000cb9502152f7af01e4546a047b4_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:1ba8ca57e9d92346b5e0b84c40ecd5c302345b639bef7c33cdbd52eeab881caf_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:b1496b478e74fc1cad7181fd20fc51a051b6edecc2bd1c61e5ede15495cadc11_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:edca8d042acc80ea3913e1d90fb1bc971046279a97784ac0961c6c750073b4f2_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:090740860bda49551a1bf0389b9a1db735e91b587948587c850c4418c3bc7cd8_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:2088a0198499101f6ae4472319e3e616c8b0dc8dd4c7d8f972c2d7406db0621c_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:3857c062e514fbf29da743d1ab7c9be2b2229f41c905f37f9014f5925ff7e7cc_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:9118335c4b96390dcf932bb602b4fc4e4ab77c8d12f2cb21182e1563485f6b1a_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:638813b6ac620f868fc272e8f232082f5ce0228865272f4a1b773578ecccfc7d_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:f97848303f52c86e6ccb87612f9a8dab42891a8036ccb2965255630b9253aee7 (For s390x architecture) The image digest is sha256:efd62b8834a5f387038640564cd3dc8e177d2abefab932c994ae568259f884d7 (For ppc64le architecture) The image digest is sha256:e9bb0b7314b853fc2a963877fccd920cf96c44037cc32da96b2e53ec709684f7 (For aarch64 architecture) The image digest is sha256:2ca99084579eed9160c76af9ae2a144ac0ff70462ee5d5ad0875b6cc14688ef9 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:29082
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-34043
- externalhttps://access.redhat.com/security/cve/CVE-2026-44486
- externalhttps://access.redhat.com/security/cve/CVE-2026-44487
- externalhttps://access.redhat.com/security/cve/CVE-2026-44488
- externalhttps://access.redhat.com/security/cve/CVE-2026-44492
- externalhttps://access.redhat.com/security/cve/CVE-2026-44494
- externalhttps://access.redhat.com/security/cve/CVE-2026-44495
- externalhttps://access.redhat.com/security/cve/CVE-2026-44496
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_29082.json