RHSA-2026:5907HighCVSS 9.9

Red Hat Security Advisory: OpenShift Container Platform 4.17.52 bug fix and security update

Published
April 1, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload CVE-2025-69873 — ajv: ReDoS via $data reference CVE-2026-22797 — keystonemiddleware: OpenStack keystonemiddleware: Privilege escalation and user impersonation via forged authentication headers

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:7d17650f80e7bf782a7a59fe0672f593cdf9dfde775b7153fa5a5c4ed8b86e2c_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:bf046c55304478c82791a67ae0dfeff89af904d9b56cd63a29b261cd02633798_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:e6165bb623041db07759616b297f0541fcc87dc3bbb91cc77399cebe96c1b647_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:f47af1eb3413e739f7e219ea89dfa0f09bc31f18a771e49ad36b32f8219d9112_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:34161b5f6663f9408d7ce5afd4525442f41332a9501f658238f3eb6568eaf3ab_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:a4116b2262af10fc2c7fc40800501add9f5a9c671907f3eee75cbfaa37d47263_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:a8dca289390dc8556a4cf3cda46e5cd45bae33fa2b1a88ca053626ca3e3339e8_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:b43e298d73fb723ce446344fac3e136b0d3347b38e7d199a09d2bfb85c231249_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:1ec3135a01ee2bce646338cc6d71d35c8adce9f3603f0f07ce90dd88dbf3c4db_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:94c42af9dd8afefe53de729d8ec8b5f9103cdd7f80c96999b2863bfed030cfcd_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:a80acaac8c10d6cce0815ddcf0bc296013e97d2cf69d1eb6ac1b7f3b35b40d74_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:e4c52bbf17f055890cf9968da78045295f6e37e52e3f4be5807db679ff63b874_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:28f2daa782218c5fb085acb774bf1d8c13a208b8f29f4a12b372db2c446ada76_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:2edfc9e18f365bf2ffecd7ad45b5693b493de472fe7abffe73ff4375bc6d2af1_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ba51aa38b39b8f57d6908665938870cced5541b831756f4039047245e0f2a8a5_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ca246a844bb6fb906816e4008c922a0470c82bfe6a736f3a926de3def6aa0597_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:07d09ce1d5c97a717dc1c0f540e21fbf7fc2ae0c27be6fd0869ce0dabc0591fc_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:44e3c6d5b98dd6655d38e3523fb34ed46dc89e97ef8a86f908d72461cbca59d4_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:81e7e1cb47cdbab3a46bf8bb0ebcdd218f46aaa94236ef250fef0fd143c9204c_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c318da767c7ef1f2452bb631e2726084f48a640c962f8003467c72ff48225b56_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:0b26257250fe3542640ce1a4f5ca71f90294c307eeb477f1d1e4d61e3ef233b2_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:0cbec11d17abd89ac4ff332c238f92fc49c19f3e1575c26c6654cf2668ca9e66_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:2554ae05f488567b3c752c16c59f852ecfcb90746a47d48bdd39825aede43c21_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:af26188e6f7326835340b99be42189550233a7bfc652375b0859cc058fbbd0a9_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/frr-rhel9@sha256:31460b57b3986f0d6c84406eccd1801eb3a03d176fa510978311d46390828020_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/frr-rhel9@sha256:aa730767af15fab6facc460b6e418bbfb0555933b4a54b01d34cb83c1148b8ca_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/frr-rhel9@sha256:ab43b9177badda24d20e8830f375132854ad313b46e27ffddb8d68b6543d8007_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/frr-rhel9@sha256:ee7eff8564ad522223787fc270f1f4d4233359872c994981619f1c10b3dfcaf8_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:0d809a095a0d86c0b149fa0e28f852c1633c2904d7bfa23b6900617ef7ffc2d3_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:51723b1449a55cd6489cd60689b42d4c53ceb6956765ff51087fa90f806ac65d (For s390x architecture) The image digest is sha256:e463f5f9a9cb41a172c0fafcd34e48fcfa24f92dc4ddf7b1ab0c8ad909233d0c (For ppc64le architecture) The image digest is sha256:4736dafe11d3ac46f8f6126de474c7030a59e75636d023f20048c6894d783338 (For aarch64 architecture) The image digest is sha256:b78fb9415afb4d73e22c9d8f7ec9de1729023913a11ce4c85bae1e0e71560daf All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability. Workaround: To mitigate this issue, disable the $data feature if your application does not require it. If $data must be used, implement strict validation of the input fields that are referenced by the pattern keyword to ensure they contain only expected and safe characters.

🔗 References (6)