RHSA-2026:12119HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.18.39 security and extras update

Published
May 6, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:455fbaafaa9d43d8776c23166ba78a9a8f8fa825653e6eebfad15bd2eb836019_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:5cb85447a61598de631f0eb31e535beaad33e821a5953f6cdef382ec8dbc8e4c_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:b5ef3b8873f207ae68f81999fab754281998963e79666f9d39944760b49a7bce_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:d375d0a5fe7c02dbf87f51a47f00b1fed2d202fd552671ff3f66122ef30e6ea8_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:3ead270b5e651ad28850f0448d701079a339859421ebaaa8dfb3ec074d996f66_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:7ad9d506193bf3141ad8acab798af3c2d8a90610e1952b7d4e26ae57688f0245_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:a081244f2d6fe252edcbd0fc683e8f001a0e020f6ef8bcb14840b72524b4af1a_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:c9bbb3e9eb7c035304a040a8feb2d6aee84090fe23340910cff1ceacf61e4056_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:7a8be0226312f99c0e028a335a3d3b41dd4368ef2ae7e6374b4eca456ba28dbd_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:8a5a9c868892113c74a7adf2c89a7fa65fdca420df0f6b474498884db86016e5_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:ce588556f1a6468421940461d64f183fb35f0114bc0069a07929389fd031d1bb_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:d3bfdac623653bc0484af9bfac2c12f5145fde4f857a1b93cf9973ceeb74bbfe_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:193e3faba2100fa7d606cee1c359e84a2085583343a878baa2ef5f728535a979_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:59cc354fb6bb76d6630bde1156639d4f37a405652fec479567b17c46441d8358_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:f48c6c941f9dc0858a59dccf0b1f4b82e4a7d52ea88e408f0a18951c4d2550cd_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:fea585def705ad83f5e2b0cd8fe6c3fee507e7c1a3d41c1af6cf11586266b719_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:2b53bca42b2e701a6bec306460fd2d796f01af733b84b28c7e4b93e35fcbe17b_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:d07443fdb671662032a4528bb2b06420aa74dca3b607ba2e3ac12d8a6389f462_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:ee32bf86d010ea8d3b0ba9abcf68f76e47f3a9229be3a580872e228fcb23dd36_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:f91d4765a64bd3d60836375612dca174c869496b4213bbbb123fc5324b733afc_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:25000077776757fd46aa82464b734e6d0244770bde809d7fa43465a563d678e1_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:49bd0b670bae19a31629e92805fd17416d99f6a56e68c19d8ace6157387e6063_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:5e577eca87366470b2ddae310fc483bb3340606eea4ea3a7bdc414640a2c1ede_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:c969254151b9347fb9cb2454d8136ebd3b7e7ec48abce1f852a2aebd297af2c8_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:27fb5a54aab6d8ed2f8de013cd693c584a2f5dab3babd42de7275b2b62f98a70_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:bb176062a65a9f71b9d0ec30fa48020aa180b27ee34d65d3557e6e6ef06d529b_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:ce518bb2be4e0919fe10bc6040c0a6b2dbc051520e7eb90fc8e54749af1cf242_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:fd719e9e29a4bc8b2f439ba4fe4496d48b6e10896094c21df592275cf7ce4437_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:04da30c2bdfecb75f1cb613dae6373972d3aaea635d765fb7b470842886fa7db_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • +170 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (4)