Red Hat Security Advisory: OpenShift Container Platform 4.19.29 security and extras update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
🎯 Affected products186
- Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:27045aabfee1bef5a0e5fe7c8d87998b5d085e90914cf0cc879be88a0b289f32_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:c8c5207f1784a5357e087914354fa0f77b8f315809a88562ed2c27c1dc1693ba_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:d717c8260a3499f114f146efe58afc1137caa648dc2c57791fa31bd6554ae458_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:f1ab962fa8e19af109094f673b205461b1b1a4ea26b7620268d15d3fd1b8ecd4_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:4c598df247745481bfaea4aba7598496d87e6407e1c080b59384b3a04c43ca0e_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:816548bd51389d5cc6f6354d3893d252d3201e4bf96593e91259104e81d67759_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:826d0571835e3585f7709f36b8319ef8ddf4e8ef8a529e89728b20f35399f1dc_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:d27b8222063a442039c3fa5e960c256eef2c7f44c91ebc17686dc596595f1d14_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:241f11e567990a11f25ebbcb91cec2d5698ac736fa7ecc3bf5d6505c2e590b5d_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:893e94bcd1ea377a5f2bae00dee9030dace7eef11fc6e54229e00472ac210ec2_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:8cde7c931c746c4428bf22d9dcdd8caf518e4273bcc2b88c8c3cb025b445fbec_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:ebccab85b2775fb13e29872d87985ab69a774a4aa6556402dc1e4478232dfa4b_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:7284df8190c5e8cc412917b22396f6db8a09f932851e94b934dd73fea6b7e9e9_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:c042aafcfd8feb67684753e52602431b1181621acdcc9e61fae9601961637ff6_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:cca78bfdd762f3413ab1762660ccd5e0ee61da1f83fc2179fbb803518011819c_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:d1f7bdf7807d6d0741275d3bb9510eb892dadae930826f3d2c24a55e9782d5ff_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:0145eea7baa031331c188b69ddef4ad0765a5c9ca37fd27d54e2fc30e3eaee47_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:445beae6bc5a6295d12310bee6bbd6f3a48011c95b40515e6382e27b2421aa9e_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:64edff7956f6b9a8e508080dd1ff3db9dcf4646a5945e4f5a568ff9de8479598_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:849dbb2d6396654470d6dcadc0754f6917bfb7cb41f339d9a9d07009fecebc06_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9@sha256:2dcfefacc2e1e3253cd017d52e099ddabbcc122f133455fa9e445b73ac3ac083_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9@sha256:ab33e7aa29a7001f8d86575f885e9b6d38ba4d7f0954539757817aeba480e524_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9@sha256:be6abecefbcb3a36db0535262987171a032ee22a824880a4d41922808a0a0bc5_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9@sha256:f8b3c8686ffdc3c6d92e46fe5246566cefb9d12e355e3edfc82741e9888dadd2_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:1e9f84c94a6f2320b18d426e34ce5614585a785b0d260706fb7b3e2ed653df5e_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:5e1d0d8d79e70eb5ca5bc971b767a108244edfdfa08aa4f9b1a1a7ea714b11e3_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:ebf8bf1c22cc0adc2a59b4f8eaeb1b81191587a94aa816d6da666a261719af08_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:eca15f37d0de3827cbd8456edc10124c849b423928473902afaf54aa0bcbd624_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:51f179d88b85e36f646435828302d67c8ff327d5560866c5dfa1b7bba5c0a5f4_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- +156 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.