RHSA-2026:12118HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.18.39 bug fix and security update

Published
May 6, 2026
Last Modified
August 14, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2025-61731 — cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:1603e1a021f3c0e49013aa2b424b2177d0a611651b00c6ad928eec414807998d_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:55452d53492a609285d27c9333474dce3ea4377fc136a7b1a41031f3cf1fb1f8_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:5dd3b77ce805dedc3f52a69331250dbc566c3e5e37d4d48bafa8e90d4dfddbfc_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:baa4911638112c305a50a64bbd60562097dd6a1b085b0d89a9df64bc1b3e7125_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:29338f4194f88c0dcd1a63bdc4e096a6c018ad9a4d428dd26eecd2d63787a767_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:567f9bea7d7c8da75d4643150232baf43a76bed2c92357ecbc231b3bd4f7a435_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:76a91dd7f638376141ddc7028bdefa97c265a22c3689ae6ee31056bda351643c_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:b179b98053c20b0765a1521b6b81ea037ac71f008ca5df2524d2ddfccf5449fc_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:3e39f80c9a81db7496f4822d24d18c7a7f9de46e86df5eca2aef31ba53c891bc_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:818d8658ab902e693f4de7b346b472295dde1ff3e76605ea32323f8031783e93_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:a795ceaa18133211034e5bf6bb3c7ba557e5d581c495dda2d80b24c8c900b2f7_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:c04c6e273154683893b523e6c8710fe07cf587a050be656ee8508eef1d5f3672_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:22b9397ad3e0104a5e81cfdbc0c568cd745632d93fdf2e5d2977daf396ac4475_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:63c901b9e76cf2faaa937beae2f93d122691bb85bcae79f12d4df12ef2edb25c_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:7759a72e395f54badd8c4f7bd9a3be7bf44c55dfbc1af59f905a677abfa7f5b1_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:7e385c956fc4abca156487eb55026a5af088a1ab43dc142767bf5855db481677_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:7ebd22fb19b406a24444d4427575931fdbdd620c272adbe7fb074d61180424a9_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:98268cf4708c262fefabe610cb99ab936bc350554c394b3d4c6d6fb4429c6fae_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:e8d44af7cf9a6537825ed45d5728a3f78d38c7cc2225cd859f3063e5a644c8f1_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ee1f9987bdabe26ba807763d1fd2f58b3c42d8ab037ba183f697e1cf66f83be8_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:326d2a6e7e3a0ee55c2531bd22056d3c6ba3565d0e9454407bb70799407c32b0_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:4ef4c69f04a3d6fef37dbf00f6a2ea96a621a094a71a672a6d464674bad3cbd2_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:cba330f17db481f5eed89bccabcec2841c9986c81bedc80defa6877f7cd0812f_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:e7b6f8e33c1d0ea13b6aeeecf55d17c2f36d99e92e6dfe4f3609b4d8e2ecc03c_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:47ee66ce291d19ae5c4cc1f951b701eafc5a9a0a475618df05a63e93e7fd3126_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:6619d97e0984d5e448c39a53a1915945360fc63e658e98425d1b84e16206fce3_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:708103c0112b367946879894c05151f0fbe1c295fa6166d24cbbc447ec0acb20_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:caf0d588f0945b618109b1a91c40d58af16d6c79c7e7618745dcadd7858be1a6_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/frr-rhel9@sha256:76648933962cf15d386355e5d94f3a4bf067bb1411553e83af580737e5516a44_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:7f01fc38ab2019240de14a093b1a603ed5817b5fffb4a8029325395b1d071175 (For s390x architecture) The image digest is sha256:65283a2e0fb692b38a66bdb7b960e7c8173b3825695190799b62d06d273c9c3e (For ppc64le architecture) The image digest is sha256:8443e22b36b2e389440a0ba92ed042f8634d89397748a48d3428d14c75e740a3 (For aarch64 architecture) The image digest is sha256:8fa4a520389d078169b042fffefde905b965f09014b4ce706288e08a64219ec8 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (7)