RHSA-2026:37585HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.22.5 bug fix and security update

Published
July 14, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-39882 — github.com/open-telemetry/opentelemetry-go: golang: OpenTelemetry-Go: Memory exhaustion via uncapped HTTP response body reading

🎯 Affected products125

  • Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:0693f2a42ab76ef5d5aa8624de80b2ec87d1a758db247bd791f1b10196f79883_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:0ee26bd86d0720e0bd97fd5705751463cce26663b31dcb3f0422466acdf2f36d_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:378b11da3e04153582a2b5c7e7abc45da53222589baf64c870362f1d3b1ea502_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:eb33c1c0dda55cf88cbcc773c8bac28f06b4c7bf4f18e9506fa9727e48dd0abe_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/frr-rhel9@sha256:0318690cbd31984918441080ce5803ff737cfe0d57ae2497996e575bff25e413_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/frr-rhel9@sha256:09aa8ef6a37fcaf5c39c43fa9237ccb81c716d1ff6d26c819433cfc385aa1409_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/frr-rhel9@sha256:b493635fbdfc96d59b40f420f3e7a60c80bb2abcc9eebcb8eb53af90dcf38fa6_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/frr-rhel9@sha256:c1b1bcb459f865610cad8be860a5ed55ee7611f05905c9549bb395ea664f3589_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:071ca3c82c66dd3685da8b5aa89d869a8bd04665c1e9d41c3e1dd5197807233f_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:a19d873be79c836c612e3968e11a771e49ed0db0a3110a17b3f240408e6e15f1_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:c5b200eda02c89dc014b31d5429c106a3e71cc59cf8043e48f6edf8c9db0c051_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:fe888f55a93cf199a2d665513060654722f6d7bf214f3131bd18a37eddf259f7_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/network-tools-rhel9@sha256:12c50e0918d55567f410f1df805d7ba0c74ef295790337ab3eeb15d755ae314c_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/network-tools-rhel9@sha256:1448c1e042a1e487a3f42d73586250f05759f4923973adfbb411fe087d15638e_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/network-tools-rhel9@sha256:cafe79403dddb3a5c12b835ef1db433e60a0cc8e4eae0cebca954bbc7a2f7718_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/network-tools-rhel9@sha256:fd9e8bbaaec4de55d049d00c33f93616cc712d1555626a236a829371d19bc833_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel9@sha256:3bf8ecb4ae038c66f99326dd1729891c4253be141675ebdcabead3f361439d76_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel9@sha256:963df53959c979b0afd6bca0e4e977b3b2992e13b042c7858b90ff203a26ed1d_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel9@sha256:b3ab0b914b263a2ee223196c580e4aa976a16f2ca297af64ceedcdbb7b688108_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel9@sha256:e757d5f2a6aabad69443647c1071aa1f8b666e640fd7805211a064717604f247_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel9@sha256:1fad0188d740681177dcd54eaeae5146406acac0f412efbe225fc355cb14ff52_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel9@sha256:3eaa1b935eb65fe9179ba067fc9920a47e9675a50ae4e91534b12a46b2ed0997_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel9@sha256:dd9a3a1a244d131a917209254aa3d1794afe9c5ff70f8e8c8bae2841ce078f1c_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel9@sha256:f8bf13e2145f2fd31118be9a9faef3482563f76420f7b0dd29b13a78f0ff8ee6_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:89e4d4e4f353bd2a816a9ae69524997d6f10c4e16478a9954553f0a7686007ad_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ose-baremetal-rhel9-operator@sha256:025da1ca44ce44f55e889177c4d010d36b3ee015d594746f38cdf8a9d18b5f75_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ose-baremetal-rhel9-operator@sha256:2460d7ef0e9a631a9692c3c2d6adda77c0bec395ffad2d8b882301b115e062fb_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ose-baremetal-rhel9-operator@sha256:4be19a5733b3441bbf7c638b8816f2a6c0f8e63fa70f64f3d4cddc02feafd864_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ose-baremetal-rhel9-operator@sha256:e21be4f56fc1dee7aec996eac15b01589a7420796878aa2a8e9c45e2b14cd8d8_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • +95 more not shown

✅ Remediation

For OpenShift Container Platform 4.22 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:e6467b367dd26e4c3d49ef8b949dba403df5bb9274fe045faf651377541f401a (For s390x architecture) The image digest is sha256:964635d3371bbb3c49eb15967d087101bd8fcb0d3905b27cfd4b1f2102299427 (For ppc64le architecture) The image digest is sha256:8cc4ba7590119514fe1dece746213984dfa05bf2740186784cb59b01049580c7 (For aarch64 architecture) The image digest is sha256:0f3aa806fc9082f5c3abfc864d51ffad150cd313ecc84c46d40dc9684375487d All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (6)