RHSA-2026:37580HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.19.38 bug fix and security update

Published
July 15, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-46579 — openshift/router: openshift/router: mTLS client certificate spoofing via unstripped X-SSL-Client headers on HTTP frontend

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:14bfc8def44597f97e7f2a2874079d7af655ac0be13455925949376cfff60626_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:366b968f5952f3c44ac9ea684892c0e05f4aa3b1d3e082a499f80328bc208905_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:cc2b037baf0e5283d4a3133421c145852894e61efc903c0b12e83e7a40b5f21e_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:cd1936c486445f7cccaf54bbde4de59eb819adcee44a95b23bfbe15cbe43e0dd_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:3a4a7aef453a167e68dbb841519fd1edbba2228dbe3821e3a57e7cfe01e1cafe_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4a159962283e419d0944106978fee626b41c7f36db457789de334f1fbef2a543_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:a0735c828db0231fbf81c2ea499eeb8bf817ad66a7438c3ee4b3508d75befe99_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:cce1258b2c12b0fd38536f1fdaeb6168656b055c6f72dd04ebbaa3865ef2abd2_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:4e5942bb7484b455f5bab98513ca8451357c3f12831cd546c409a80f51f26fe9_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:5ed47103e5c6faee667370b77ba1dae3337b43136a2ef32357ee74eea3c67d82_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:81bf39827bdb52f3acf84cdcd3056d94709d00e373bbda351ee3af6e3116fd35_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:fad51a5047a7ed225cb50411d8a44e6ebebfa4741bbbb481125ed8d979a0dd6a_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:335029070b23f14e44594ec026073eed1968cd062d618dc589616d555b785d27_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:541759edfc64d991d4bf56dd05da45fc2954ae6e931cd67a7c406cc9e3390eea_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:864f00815f4aca448022b34bab09692b274da0dd000afd55834bffa5667d07e6_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:bf45b4c5af5abfad971b50c0d9292e2e8a9c12465615eb2bd83acadc171bc3cf_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:5d1d2035629672acd8f953a5848a31e94b80d569926e073368e0e83c25b2d28f_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:95ea424426de1740eb9d7a65305b206942d978cf5476782ee7937870218c6ec3_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:c7de55987b25a12856217966fca88b58295b2c3c93ab2ca135b184ce2e78620b_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:e6532b7d09db8e8069b452d3c569c1539f0d2f27f482e5ab1ee7fcc9857721bb_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:34b55c6b95286b9c5393f208f6de87f15b6c0888d41cf1d5a4f42298bf2cb711_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:751be599a879780629152fd095d46a6858fc5b6ca4b88fad1980e71f309d78e1_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:971159b52ba92e5bedbf7c385950b256293e2d6c98b6304ddb49369ded061de0_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ecd362e273d88ec3452a974ce19a6fa4e31a16ec223e000016a391215313706f_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:37d691ef7f3a1c97243d11563c58c3c18b43ed079535900908606f09d98480c7_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ccdd2c2e3330e851212170d3ffd4120619a35e361c6405cfa6fe4704f376d4c3_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:e89af18c9284d47fc0f3ec8877676c0266c2cfde7fc3e714bd2169fbf8ee5108_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:eb6759c6c19ebd9e9d7a73c0cd77b2fd7998dd06ce24d50444ed484df6fd5872_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:386b096a49374372a490ab9b8a0c8425fd4f9769b5e796d21aa0db48b71f37ce_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:87473063c81e800d10bdb98e20859d8faaeb1277ce71b1c88476f3dc3ceccce5 (For s390x architecture) The image digest is sha256:752dd497d9a8e4280d3687aa76a1f92cdd490e996114dba29b02b1e834a7df32 (For ppc64le architecture) The image digest is sha256:c8d717ebaab3295a6398dba0bbbe320049a2e52750cb91fb018031d6834b60d2 (For aarch64 architecture) The image digest is sha256:b01d49472c90941459fe53cac028c458e331c0bd94e5dfbfda15842ddc8ed2bd All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (6)