Red Hat Security Advisory: OpenShift Container Platform 4.22.12 security and extras update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-73088 — browserslist: Browserslist: Prototype pollution leading to denial of service CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results CVE-2026-73643 — js-yaml: js-yaml: Denial of Service via exponential parsing in flow collections
🎯 Affected products171
- Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:49ee39c3414c87c9228dd2309692045eb1db9183c4fdd14495404ded6e35fd56_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:555efbc2c6d906939abeb4695fb83b05075a25155c35fdd00e20362a67b23eab_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:57c71bcd94ddd5c47682e1fbd576efd6e14ce130c333ac686f1c42bdd6e70d3f_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:b2d1e9a2019c24b529bd8f380f1e3b6e729d564965e104cf46c26dff91c4bc7b_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:5fdb723ee9696073b5bc33b442660b7ea472e7f0b98c09170d400b4cbbea0eb7_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:b0439cea5e3ccd92884547fb3e3bef39a62d0b02ac121bed447c05fd35920154_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:f40e2ae5ebd9e29c5d5456f0dbf625dd294035fdefba953709ef5f7594dbe992_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:f7df45e3b21a051d6ebef948e319b4d27c5e851ae86d136b7d5b333011760d37_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:93df40b046a8cdd8a18b293555677590b20107b6a8183e230d83c70a2d8cef10_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:b8e9a799a76bcf988cc67a81585a572cc364403a2f68922cf4246aa4941e824a_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:d66813a200736155eb980dc03ebd92328a53022db45bde90a4dc24cafb91b82c_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:e88c5b56bf4731485794c6090beab57648675646b13ffe4cc60d4a7a2deff374_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:0ede06f472ca1d018e94aedafaeef86a5fd99e4d99deab285383d4094461ff47_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:5baaacd79fc3fc0745320a49b5011cdb84139634134d8c7a2e66492bc0bde3ba_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:da030293e0dd3af0d6ffb2f309283cf304d1706db3e392080b81d84eda5dff88_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:ffe2c0738198e95e5be885b4f3acf53d60e76956a6a97e4b381838c95294d5f0_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:428b7995728aefee9accf4bc4268240ecfd0f959e212e494e6a15bc7f5e52a15_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:4da759ffc234e479f762b0b6ecba623fc18b43446cfc58b989ea55a6126b62b5_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:7b652b38b1ac0354d92197125b3d94abb34edae2d82408e6bf64d148c6b7e360_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:d961a56481be03cbaa42b5ed1bb3366548ad8e4cfbf271932afad1a36b2620e2_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9@sha256:1466ed5cc5880fa9817cee8d72d36d57f9fd04005b5772d9ad7f290b37a6e0fa_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9@sha256:6ce3948ddaf2bc90828844c5f4529f00c422fedd79f4970082604b85f0bd6816_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9@sha256:d2808a74cb945300b7a57fe2ae0e8f873097b2ef23a526463dc36c1e1c4799b5_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9@sha256:ea4552b53e6a31eff8ec9d298cfc3c013ffc335b46f45517d7332bafbca69226_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:205ca5a8758ba92dbf620b48604ffda442e16433c7d4324e85f618768b08265a_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:7b7ba3d37ef3ed4a0fc2f5f6b978db8a5c04712350b1b9ca6ab400bbd995f8dd_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:8e68d608ee821184ef295da76f47829c3c1e2e7ad77e0bc2b59af851d0e18f4d_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:fa7846efb5b41d1fd76f44ae0379e7a0da53c950ef0a0b884b4a54e0b48f0fcb_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:02c4c7f4dd20fa5a1b89502e1a4018d81cfacb0710c14eb28e4faaa1d48dc984_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- +141 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, ensure that the `browserslist` tool processes only trusted `browserslist-stats.json`, `opts.stats`, and CLI `--stats` data. Avoid using the tool with untrusted input sources in development or build environments. If `browserslist` is integrated into automated pipelines, validate all input data originates from trusted sources. Workaround: To mitigate this issue, restrict applications from processing untrusted YAML input with affected versions of the `js-yaml` library. Implement strict input validation to ensure that only trusted and well-formed YAML data is processed. If the application is exposed to external, untrusted sources, consider isolating the application or implementing additional resource limits to prevent complete service disruption.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:60442
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-73088
- externalhttps://access.redhat.com/security/cve/CVE-2026-73089
- externalhttps://access.redhat.com/security/cve/CVE-2026-73643
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_60442.json