RHSA-2026:36621HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.16.66 bug fix and security update

Published
July 16, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-9697 — undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy CVE-2026-12151 — undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames CVE-2026-26996 — minimatch: minimatch: Denial of Service via specially crafted glob patterns CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:42f8776d04948138d01aa51562b3e856a4cb3aeaa2de6db0f29337435b060220_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:503ce4710d7ceed01f2d997543baf576d75230e0ed331f3b9bd97c9635e93e33_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:90afe5b54818f7fef6d3385cf6e388ef6ff6ceb06b60d33409d66d269388e865_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:fd7f6ffc0b7df349bd9579fe7b3b44a19205c34d5d2e797146f5f669af7dafc4_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:007ee715a08007071d9d4fe844324e232581e22d8b4e8299b7dac05f2b7d1ad1_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:23c39a370d3ffc6853c750530a3242e089a3ccfc0b8b0b13d54dce208fcb046a_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:307ea7f45375885263d721f4c1da979fc5fec54c02fcb01367b52adcbad88d3a_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:c257f402eccb7b20a9ff35c3422c5335db8811c0e5601734c7b1dd00378918a7_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:22a4202044511cb78b3c9eda3669acdedba1465cfba382c80d7a2644422ef955_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:6e1e6678b5d2a8e3adf17deaad061e202b3adf599a1d52852c8e00424278c117_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:94b1dd72748edcd6a19309d6570b0668a3d612c04fc1c8f05fcbbc77f7513713_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:d3b2de529669fe0b78f7f2b70ae909d2fec6519ac81eec92a889918d1637f45f_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:1a3806af4d0d61dc776d28118fe5306c0612613e66a366c1d8b1b030a4a9ba42_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:7872768f3f5ca9f97eb08e5e0c7912ffe38784d9db9fcd2262de3fc83daac91c_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:9a895d823956f9049ea6452d8a934620652552dc4e8379390c1b345a846e4181_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:a1c5e84f2722de4dd89817090341d35daa7b38ef18f344c0bd8a6f9ed7d379fc_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d27cd6eed0145416b66318bf7a7889f094d595a8db844db5e647c29651023434_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ddc415844684e29205b1f2659de8cdcb861007f0f7a952e748f8ab4f0e9d1ba0_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f0add117a131f1b7a23e1cb385bfaecaf911bbb50b1d57ec4802bb9545154bf1_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:fe958a4bb4571efbc575e3b8d3bb9a217b7da360aaede62c7ddbf1ad5c497396_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:8755c30b78101d311fc9ca38c47d2634a0372f75bed11a69753e856d7e71bb32_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:c552e3343b219a3fedf8a78579d3b6f63a6e3b523161dbd7a47d61254c46f2eb_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:cd0318502835d72ea72f6f962e8e5f6299e19d29788eff5049f21f78a22b74e9_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:fab65291376e111b8aafc310e7bcd9a6245e2012f30450991d12b2d4567e23fb_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:1262eb020e17b432f8674169996933b2c297bcac1b539791c8ec05aeadaa3f0b_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:37314267d66d12b748557fac914a14709d74dc26d0d424aa7de1b5550a2829a4_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:4cb63c3e2c10849f35842541d163c927cdc500ad7669732284ca7da889daf814_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:dad1ee2c9345f19e7c8cbc27b82c900b73da284921cc37da5bfd8877897e4040_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:4ca43741bee092023544aab687c8e6737863a793c73d4bd6a363cac50667159f_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:29a257b84ed0c15e4b45fb75fe5c374a3e2a1cc22baa7d092a81568eed83fd95 (For s390x architecture) The image digest is sha256:3ab1b27245374015e035036cf5d0c0f1d84100605f01bdd9f02308ed5c1be5cf (For ppc64le architecture) The image digest is sha256:a9f5be035e9ded0cb40d52516df1e77f8a324e5853b8028c1036c73d23f74184 (For aarch64 architecture) The image digest is sha256:71c1ebf0fa8f125365d8a4e0be801b7c03d6821479be5861574cc77e7996e561 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (10)