Red Hat Security Advisory: OpenShift Container Platform 4.14.62 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-58068 — python-eventlet: Eventlet HTTP request smuggling CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:39f3e8a9f78d4756e9c681513c02b5574e80ccd7043e7f0130ea1e5505e27cc9_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:7dc4d67c2153b57bd1d0e74e85e21d898acdc5e792ebf3e9e2254e9c243069c0_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:934e6f7aa8dead546ddb258b6753f8ffc577205ed6ac19796a2140cb242497c2_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:d3c8598be6bfcb46c310e881493b8299f126b86c041ba560edbcdcb700430d0d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:1df62178853e8698d9d86da8530144f3cc5671c77b72bd09098faab187f6a78d_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:bfb1ae8157364e5772facba2869c37414fa49fadc0b7a42ade55684e5a93ef0c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c70cb3d1a437e747e1d7d54f631853d611a97278fa260daed6c56f36f885e17b_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:fc89d0c5582c76488c56d471746fc9f8acee50a5d727cdb559623af580389f5a_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:5e1d1c77c595cf7cc63e38f771d7b2e64a4b31da119476238b26dce182cac160_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:d14dd4c11011464adb44f802bbff4820560b56422a8891664de65bc1f8da66ef_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:d26f4f47b5b3447e021d20ab0e6dae7eeeadeeb4f5529b85f8e836d6625dac62_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:d4de045b2177b2abda6b28b814c450961272ab3c982a4c1da29271384aff2f06_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:587c9c3ab23222ba8e4581c20758a690e420982196b416a0dc895071ba13cffa_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:7b806e315b880b6e3fd85f23585d5a8032637099242d0d1abdb7703d67913529_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:e8718288050d418f62e75b956e2d19b285e3513fb70771beff64c7d96b02ad8d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:faaa0f58bae404689e533be4e44817cd8008d1ae4c2999fe1b671e663dd1588d_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:19fbed56d75e69a0d9582fa54d3328fb44aee9a119781a0d9800a1f948b79926_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:2e4109f5e9abff71ace58bf6c904d19bee7c5936d99af1192191ffcf75e87606_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:b703668aed81e1c3d2b3b17c7c05b2453bb7685089f2de6d9e91b9525ef14c96_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:fbcb0389b7f506b044d1b908c0fe8e8eb1fb5509cc006fff4ecc992c2dcf31ae_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:21db1e5da0fdc170417ff618727d1df59d264a27a1fac0df40f62cc6d0b92e34_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:2c7df73b7d4e11ccf47cfe561600541569d7a5daa04bacadd28b601ea9593d29_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:4671fc86a01df017bad93436e10f40c0ea23e27a73a58f76742f8010f60a3922_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:71684546a20bc4ca896f3daea721b658557f992f3b4d9679fb414415713ae8dd_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:209bbc308b2c772b4553e1353d8ff7d79d47fcba4facfae1649eb7fcb9b8fb70_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:21f468b304e0e0358ba70b05bb712b6231601b0e438a4a6d2ecf3239b016c448_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:654ffb6786eaa915fbce588d9016bd09927a204f797ba0104585bbb19de6e15b_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:b71f4aecabf4c609d03b751b55cb94ea717983179b73efb6ff00001a514ff4bc_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:203a0938168df89a72bd108bebbf6be7652794447dd2ccb69f8aeafa28a3d6ea_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:5d84e0f03cadea0cffa8a36ea86f815c4015d18af9e7150dbc4ce7c3b4043891 (For s390x architecture) The image digest is sha256:8482c7b8dda889961377707d79813d14f4283c8bfb93b33767b62f9c08684f82 (For ppc64le architecture) The image digest is sha256:731eefeadb4821a0e9e4572039b85467035d0388bd003b8484324ac7c5917caf (For aarch64 architecture) The image digest is sha256:e116421add29af6e166cbc15891dba184ddc560c5976b424532f96bf0472c2e9 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:2990
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-58068
- externalhttps://access.redhat.com/security/cve/CVE-2025-65637
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2990.json