RHSA-2026:12283HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.12.88 security and extras update

Published
May 6, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

🎯 Affected products41

  • Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/cloud-event-proxy-rhel8@sha256:1b496453f14ff6cbeedd159d4fd542e0b573a060d0df163c263e721972fe38df_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/frr-rhel8@sha256:a64102de8fd6afd927b7b7447899474239bbd45a2fb15a9a7d5d8863390113d7_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel8-operator@sha256:1f55aeadf10501d4f1b0203733de0e298167ea0e8a765d7f5cd6a6e938e15c3b_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/metallb-rhel8-operator@sha256:f21e3ed5bc984691b76fe47f28bd13adc7f661f11156b15ff9ca50ff51f9a1a0_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/metallb-rhel8@sha256:dac2f649404b353348784bc97a93b734676fe3e96413e2e9843f3ae8619d4024_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-ansible-operator@sha256:7923d3669cd041fa666e12ce5f3c38e4b1d0ceb0b5c49d78854736f308e7adfd_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:ea086d5f11dd98f70e94ae57fbd5b880b5dccc82d6c51bae894cf297440d224c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:be49270cb361b07b00aab644281b73d0aca467708516de05dc22ba5117722db9_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel8@sha256:1b496453f14ff6cbeedd159d4fd542e0b573a060d0df163c263e721972fe38df_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-cloud-event-proxy@sha256:1b496453f14ff6cbeedd159d4fd542e0b573a060d0df163c263e721972fe38df_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-cluster-capacity@sha256:5d05452ba25ddd0059c0a06953cdeaee1577d1e5c344321f8877973ec27f5f87_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-cluster-nfd-operator@sha256:793403b2d98a307b2611c50ba405bb21bcef0fc8e8bc645708b3dd2973c86179_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel8-operator@sha256:3f751feddc375429e69a7b240f3b81c7408582896d22a4d27eba3b628c9f093e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel8@sha256:c0c45d10c29890379eb7cf63abefbbf674152196cba7b5fb9a899004703a0f18_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-contour-rhel8@sha256:84c7cada326a320c3476d6f351e0cd292b8d10bb6235984ee39bbc201afd387b_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:1be436b65026a3e7627fdc76ecc0b68c88a8f3fbde1cf854acce96f9be75fa46_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-egress-dns-proxy@sha256:788efed82684dd286752afa830836185978997f8be00d5cd527f0ec7d42fde34_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-egress-http-proxy@sha256:5133069a13a8090f9f98b24c1f628f2dba5af9d52c1010332023042c273770f7_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-egress-router@sha256:5a5f93f5b9700bc2dd71b2648b162f9633db6fb185fbaa37f9a6a5667b6f371f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:8057b5373886d7c3d57039277570ffb6ae3aa61c713ddfa6cd57073edda231bb_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:d7e89f01fe01e4410336264a50f9d91e1b3500672a284f38b38016e0cfbef26f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-helm-operator@sha256:a170db3b598fb54c0d157c1bef529fa5f2d3cf415ce9c8ebf0426c683d45dce9_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:9f103bd2a7049c2d4ac2d524e167f7e240df769fa3f5588a67607bb475c19a75_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-local-storage-diskmaker-rhel9@sha256:d8617b979e3a22683dfd4979703c57d88f7e3fba32658ec18ce396463d9e7f79_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-local-storage-mustgather-rhel9@sha256:617cad317fd1772036fae5b818d233edfc2428e2d7a27eaedbf4c4ff465d2f54_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-local-storage-rhel9-operator@sha256:88fd28ce7dfa7198ad0e6ce113733e96bff41c141b1ea056365dcdebb7fe1bef_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-node-feature-discovery@sha256:39f45779cd6b60fcabb8cc0a56bc9c7b39902861af8eccae580900e5298c9733_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-operator-sdk-rhel8@sha256:0d822179c274d9907e7d846a49cce6405384451b67b37a9115c38a20b3e08d4e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-ptp-operator@sha256:597901ae2d7bdf7a8ab384b7295f2dcf303e865abdf772159ea8b43a61761fad_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • +11 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/release_notes Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html-single/updating_clusters/index#updating-cluster-within-minor. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (4)