RHSA-2026:10105HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.16.60 security and extras update

Published
April 30, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

🎯 Affected products194

  • Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/frr-rhel9@sha256:9514006a33ab484e3135736118c70f51c31f34005629556bc156928db87196ca_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/frr-rhel9@sha256:a656db8efd65a9786fab384a205ece12309615580a3340bb9109bcff8e61f7dc_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/frr-rhel9@sha256:b68a7a5859cbca02dfa05e925af2714227c15fb516ae7cf89d9313348dade299_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/frr-rhel9@sha256:f37f754c6359c687707a86e0a9bf1755041c9af85171ae0599a81dd48c53e2d7_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:02e6dfae6c48696bf53651ad272cc9374f04b20ed24fd6be7c67a087574e48d6_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:06b0c4535f06bae52fc8ca90a89dbb8d5619ba0d7798211028af1ee784d13f5e_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:513ad3de187403dc1007e248428c745eb2d522a03b3a9b23aa26fc65c3d93a37_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:a08c612f8cb22aa5c3efd6ff330642e3d235dfef0b3e827bc985b9ca7eaf504c_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:147c132bafabcef7f8efdab81744d7879385d8dac010dd995b9d42e309817470_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:17ea1ff2373aec50c91d6a3958608f27d16952afd2e75db11cc5c8d44efdb118_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:577777cd08c2c9418331ca7bcd39c3d56de4250e17d45a07f6eab8f5e5c25671_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:8f5142c29e3deadf5bdaaf86c4e47c3849e8d184fa0e94e20f90d8b5c734c1f5_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:0542361aef325e1a07e8eec868aa9bb283c84ad7dbd1efeba4c6184fa2ad4d77_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:16dfc66eb443f912b84829d7eecc7c1f53dfe8472212f15c59791d979fa84a66_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:4082c82eb5fb26c26453a59b22657ddc1326dc3a9ea92ef37b459e6ba8ca6a22_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:7e42f0261d3670ee802686d3dc7af1f0e759e08a69f9af3b470e03fab4913a14_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:01450301456878e9674db2ddfc3f04576fe55c69e99d3aa04eba94ae17b2080f_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:96693f8126646d7059ade26f2c67eee3b7be8578938434357788e657805d999e_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:a0ae51bb6f4d7051ac74b3010716c718cdbaf76a662ff7cd8cd6e0b576805234_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:c44a4d6954452e5bc682afa6fba25ab51dc51d74b1a70cafe0e7cf25ebb0cfd8_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:7f6258266bccbcca635498ce666e66a8507d01e2ba9efaaaf337b57d14f26d10_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:d714bb305f982efa78da071289508ba8db2baf58649a1e2f0ae9b0ddb57a2263_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:d7d0217453426ca0c9575b158abc341103ea13cd67bafd92124f8825bc41cdda_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:f4c42ff98d49337a1cb96f8232cab9b349625de78585279d8942e526be459cea_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:3151eed2a25d88ff78011c11d7c1919a2596fd923895b2778e34629b8bfbd610_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:5d6d2ae0f3181abb25d2c933c13ae588d44878f8caf843b2ef3a48bf5c5080a3_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:a2973d796abe669f4bdc36fd7a9a074446de62e7129e519a137932cab9986cdc_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:a8cc726e618cfe1c7ee8d99172a5006efce6151f45c1658f784afa5ddc807868_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/ose-aws-efs-csi-driver-container-rhel9@sha256:74c8507e18640e95b55a9d1865a5604d5573a6d803b3bd6ad140252116daddbc_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • +164 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (4)