RHSA-2026:3422HighCVSS 8.2

Red Hat Security Advisory: OpenShift Container Platform 4.13.64 bug fix and security update

Published
March 5, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-58068 — python-eventlet: Eventlet HTTP request smuggling CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload

🎯 Affected products192

  • Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:35898248f7a14e2f4945b95779cbacf3ada75ccf957fb9d59c43ea722bc659c7_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:5e74ca1fb7ca13bdfe660c8681f60b1a1b83bf47379b35f6951ab2f5b2cab2fd_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:c2836249c662fa1cb5e015249eb8c16ab6687c7ddc2c67217cf69e28cae0a217_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:ba829a48000d32000fab969e21e82fc8641cd46b5e6d2afc85f72702cc6119c5_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:f4e785f3669d3fb96edbaa7adfa3cb521cdeb7ed5d7993ce9e1f4a9721bc0737_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:fae18193723926211ba4289b50cc375ac3c068c42f6d2b217129800386fe21ba_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:80c130d5174d2cd8dee63f7dfb4be33f469ab59fb6697309b22d21661ce44a5b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:66a8fac2ef6c846b32c9700ec6afcde4e32a21af2d07f7b30659f26cc48706fb_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-agent-installer-csr-approver-rhel8@sha256:8a212f4355a2a8f849338a59da65568844d698a8b3cbb0795434ef4c02d1bbb0_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel8@sha256:083584adcc1c6a9cfc44fd121f6b5a80caf847d6ef41457243d68e832512e137_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-agent-installer-orchestrator-rhel8@sha256:f1e5896ac59d4654c49d24bc10545de1dc7237d19be3fa085f51cc295bba8b9e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:3a5cd797ddbfdb2f582b6983da722786a5f4362461a10fef0ac46f4ac44247aa_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:2267a4a1128b1a10acc478b545eb1468be4272827eb199c29078eae131009703_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:4ce6b9f7acd9845e5598ec60436a09816f88b2394d5faf067092e6b2ad55e6af_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-alibaba-machine-controllers-rhel8@sha256:8dd2047eacd8c4e28ee860ead50b3e2dfe919409cf4f4f0089500673c4c2115c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-apiserver-network-proxy-rhel8@sha256:1b533418cf6e29fd9acd5fec98daa7384db18c113cecd50040255df6fa6c70ad_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:0e7793d19afe307a7fa2754e16c267f410c2d5362139685bb2e4148df9ab30cb_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:9aecbcf45141fa7050adfb9a74f9b76d5087cca447ca9c9a195b10999342b175_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:54b979557a2a31632abd90d27f77310ee866257c66d3ff86ab07f82f6be8a4d1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:7f10c0a4faa2ddd19393b919ccbd318aac29510f393810874b4f2a1b1c97f62e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:8eb433372e8f658534cfe2b078eb9204fd00cb083605e34a8eef0276991e8c9c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:d163535a1b6fa970c89520be9563634fdabb1aa1d34d36d0ae05f10ce863b776_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-azure-cloud-node-manager-rhel8@sha256:5313b5d9ad508eaf0dcda247e2468eea0d6caeb29484ba9b2e6818786a606f28_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-azure-cluster-api-controllers-rhel8@sha256:0e56897a6f11eaffa74bd469bbcac436df28d87ec8c8a196d175d0746f5a9596_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:ad11837c6ed8937a655fe1460b8d15a1e0f5d94a09c93c84feb946d6379630dd_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8@sha256:5a0bf200b9eababf1a55d0ab8719ad0f8bfc572ecc35663805d3155e3952719a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:43b3644d657ead5a217f7bd35e3c4b02e48a5e03eaabe09ff30a378c5652754f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-azure-file-csi-driver-rhel8@sha256:057bb3e3fbd95ce088b357660eda2b3f82ebf5481e6ebccec0462f2bebb3051d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-baremetal-installer-rhel8@sha256:d332f5286418298193a0e99016c44b267c501a9b291db732356a1b0f2f18c8b7_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • +162 more not shown

✅ Remediation

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes You may download the oc tool and use it to inspect release image metadata for x86_64 architecture. The image digest may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha value for the release is as follows: (For x86_64 architecture) The image digest is sha256:a7c362225f22ef51feca9c9959409ffc5f8308a9ecc06ed2cc39b31668327eba All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html-single/updating_clusters/index#updating-cluster-within-minor. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.

🔗 References (6)