Red Hat Security Advisory: OpenShift Container Platform 4.19.29 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-69873 — ajv: ReDoS via $data reference CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:3198e3a7911d65997d84ae2c4a4756213bd6169408f8e5b4d4fcfc1312ec221f_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:75b581b7faaa791148cfc9a5e5b4c87faf3a809d2baa0fbcec38bac757007b49_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:af1751213d6286401c0e1d177bb2952715b50a255dd0072452cfcd1a239c9be9_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:fdc295c04d946e1294cbc811e5ee20827cce284c7a5358c9c6c926f5afb5fc7b_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:1fbf0bae66e3d3feafd7a5d800ffdc203ad1171d41da344c7bc899fa9df0c439_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:a83b03a6cc820386376a5e0b5ac0bc43147338cd0f77ba6b20284b93cde06b63_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ab5dc4b258e7a47d4a05f2f4975324ecdb53481bf591d41dad10543be93ac59c_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:f6fa7b17816eb0b9d73c00dbf4715a26458d784e65858ebba255b032a5a2b3f0_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:565239690ed2974560e390d87055eb74f793a4d2abe8dcfcf0d40c4b1d3e4334_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:5769b6120ec44707f7b98ec0ba5e90dc8dee0cf14a2795a0785435cb01711fa1_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:9640a22ea7f43b46c281d8271b89480a9df2b5c9ef500b3b9600c5373ebdade6_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:9e682bfd352c260c9127e3f2affa6dd16af28b3abb8ee7303753eb0ade31c1e8_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:1a84a096bab105b8e51bdc5f2d93c011a8a6a32e0ccf5b3a5ee2cbb2abeeb2aa_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:1ef77e97f9b16035db985cc79029fc5c3bcd6004ecaee9fec9c05e354ac1e599_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:5f3011e69a519014b7801d2acf0897f95635dbe17492a09216673ebd4a1c791b_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:eaa84214ab82626dee31c0f652f6d4d980065a920932eb8e69f2e078c8fc16b0_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:2684c0efc9838adc240b08c8b263d829bec71acd381dcb4147d8c45eb1d08d08_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:31b01092a5183808a2a97430743d04941f034388254cc7007e74c4ce3083df25_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:5699e966b38060569e298ccd084fe89bd719302ca70e2ceeb4bb9b6ca5be8991_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:d052315ad81d7689a02be445c9a1df8d296fc3c32a33e3975dcc4297fffa2bfa_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:4b16fcfd326efb0618351bc9ddb2c3206b18e189c188e5c9fcf27f3ca8f3afa7_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:511bd02437b2ab8480a54dfe2ed3e8c11c3d9d2b332212cb455c8540678665da_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:6d971be6c49127312d1568f9619c9f4684254c64b77a047f6e24e1caa83e9416_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:7df6d4e5830f60779a607ad0ce8716034f168d5d9c6b563bf098dbdf3b2fae05_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:274d4e7ca8dc6003a3d18d931e63a4a0b4d5f80582351fadccef4195de8b847a_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:2bd57947814981b16996f8d12e40d5a5670dad3eae9fffbd57e700c39c1b1155_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:7339fa5d4a95cd617046d6dc06a2e97b78c2448353f2ee464095e787a3a2fcca_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:cd93cbcc8568e8bc3965cfdf4c989a91782a08c38c6affb64a0a3121fabb7075_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:04e57127605538ba40496972299b81737cc2e5197a2ec97fba0b34d74fc9ab5f_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:4e97f1a9f5f5e751c7795ab6638723b064447106845f3d75d35b03a1a6c9488c (For s390x architecture) The image digest is sha256:38ce542dda6ecfabbc74da4052af74b63a2e6e00ba3c58ccb2e8610ee4fa3ba1 (For ppc64le architecture) The image digest is sha256:1dc485424fa4a6fbe7864c44d2b527351d53b9f7d7bd24d349e6b25325624bdb (For aarch64 architecture) The image digest is sha256:4f700acd8ac54c1ff151c27ea9042606fef35a7874204732503656bc88e19fda All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, disable the $data feature if your application does not require it. If $data must be used, implement strict validation of the input fields that are referenced by the pattern keyword to ensure they contain only expected and safe characters. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:10093
- externalhttps://access.redhat.com/security/cve/CVE-2025-69873
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_10093.json