RHSA-2026:62550HighCVSS 8.1

Red Hat Security Advisory: OpenShift Container Platform 4.16.70 bug fix and security update

Published
September 10, 2026
Last Modified
September 19, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2026-18446 — fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-54423 — openstack-ironic: openstack-ironic: Arbitrary IPMI command execution via send_raw deployment step

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:22cc5fc474aed55bc80c37faaa6669fd2222f76aef003d36f548203a836b71b3_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:367b4955072eecaf6d7d02e6c716240fbdbfaf58e5425f3aeb613d868438d3b4_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:8ae1008ee22447b5554abc5693786fff0cf08b11c9c90efb26f063e81382701b_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:9c9382e36a4042b56fbf0191c687cb098615cf3a397247acc04dabbb1241dafc_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:14ef149e2bd403bca00cb1d10f5d33d064145d59dd236a0b6120597b316e0e13_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:2ad4b2d63469a46b4ceda7259fbb4a282aad69d770a39f1234ab47ede733eab2_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:768928b469ada96053a01d9898742e9209835d0716588ec87daaa1342d490745_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:8b98b1544badaea31e5eb4e4bbe8457180b3cb5e743b79f5d0ef4f8c02876679_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:1bc95920f2e12356ef9dc4a75ff8692aaf8e9888ae08e70b825df87de8a757b1_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:32edd438e4cdff38ae7a62793dd7fe6c8b7d47ae8f79b0dff615689ba332834d_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:3b4e3351c114b7ead71d52d045a25ca1a38f011e3e7103767e6c14046023823b_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:9fe507111fb5c933342fbc23ac60a2f49c7ad1ba6f8a4ba95860f13bd0866295_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:176c5b3de11f12f075e4a4fead2a24f90bd364b69d80a3ded5268885df8c60f5_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:7ec755d7f102df4f81618bf3ac4347a1219bff7c13a01f7e12f350571cee852d_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:8cb980ec9d858ab93ad331a4d7e0dc410b6c6c187a8ec5f053c6f014a1ba420e_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:fc353eb8127267bdb7e8094f7a9e127f86e4a4241306debeccc8b22a582985cf_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:5534cda530f1597b874b2cd3c2ebd14be6cd8835ac1796682dd2d8e9991e5022_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:5b95f2fd47d98dff254394803ecc66e37279cbad485fa85d379b226d35ae7897_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c0f9e8f53174c9f0ebf8f32c9025b40dd7e3698d64ff5d50d4b455232dc45ec0_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f0cc975003ad1c4bf6407863742a7ba595fd64214c2561f3bdb650b484c3669c_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:1f64ffb4b7a273f6680861b0db52266d979a234991f1a168f0aa0b9cba781156_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:21e2e36bbe5e4e4da7ce845a176136a9f8fa2a4075f30608bf8c6ed097f2eff2_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:e671d2581ea591b9235146e280caecdf85a22a52247814557e9acf28a4381d12_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:fca6c9883c341a915a0a29a9bad597c8eac7697fc1e371f5f3c510ebf9e8dd83_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:8b8efe9e040bad07f19a1c18c16d1aab4ee66e12c57cee3d983d6a1f9ba15608_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:8e459ccf5190a99e8ee1e678b8f40e2ec9529726d307624a701402071b6232dc_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:acdf9dcb9a8fb59aca5db696f1ca383513f6543c80823bde1a563f01d18ba015_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:f857af31de65647bdd080463c53d10e075db513f11d282edaefb8b46618ecb69_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:0b49cc6b16030e418f640d0b00ee5c67bbdeac12f54431575574fc0f4d41e88c_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:077bb2d0f053cfadc673374237b206740ab78f2663d3dbd1b49713c2ced88994 (For s390x architecture) The image digest is sha256:a46bf8cdae866571521a66b6efa1634db5109b020ab9ed6d8de1caf815bfe25a (For ppc64le architecture) The image digest is sha256:6e0b33f7d8db91651807aabffce25e1cdf27f90a6240ac49bd651c64b05464c3 (For aarch64 architecture) The image digest is sha256:e76b87d63f7b8b2960353d5cc3e7bf427b65edd8e95c8c51fbb7c12a6ea4fb34 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Operators can apply the upstream-provided patches which add a blocklist forbidding use of the IPMI send_raw functionality in cleaning and servicing provisioning methods. In environments where the default access model is used (lessee capability not enabled), this vulnerability is not exploitable by non-admin users. Operators who have explicitly delegated lessee or owner capabilities to project-level roles can revoke those delegations to prevent exploitation.

🔗 References (8)