Red Hat Security Advisory: OpenShift Container Platform 4.15.64 bug fix and security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61728 — golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip CVE-2025-61731 — cmd/go: cmd/go: Arbitrary file write via malicious pkg-config directive CVE-2025-61732 — cmd/cgo: Go cgo: Code smuggling due to comment parsing discrepancy CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload CVE-2025-69873 — ajv: ReDoS via $data reference CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:07c9197d299d5550268a2837f6f4bfc6c3b37b815e282a090cf4e4d709a3b773_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:5db90628468b13f697ce76c5e509fc1faf679dfaf434a1712f0203eac8752b16_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:7910705c7518491e57aff99d04760f49f35602f310b1fe69361d15e204b5eded_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:bf13a71b8f301073cf482106dba17df47fbc4d40f4aaebc15851cdb2d227c330_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:15fa9e6114f09896276d93f56bd3c215190e61b1c309b8615f1f74fcf56a30a6_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:2d00d7351ae4a6c3e86f0e686d582416326175b986eb55c9bb186a7bc44b1b99_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:588a92c14f5000731041f435f8e1ae650b8c5308c9d6a6d3fa51511dbcf6826c_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ac1d26d7e2844a59cd61bf984629c9b72d5f1d5107b264eceb5876975a72edaa_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:311d88781e7798ed008331e40592fa73a29b03e17d5c9caa6645cab243efa217_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:6d56a21c0e0261a2f7e85f90af9c65190d6251ef57cf07a1f6e0cf51982bd6e5_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:c62e9ff922de557e024be11503e90df4065887d30c923f160acc2c5beea6f6f4_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:ceab4a2c4cb545445a787eec12a5da5df0bcadd707c3f00c09336c706869cee9_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:0d8472fec420bf91117b3f1516e3c0b7810e4c65a696fe5215bfdefecca7895a_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:4eec87bf9eb6d979ff17a31e5ea0aa609c1b749602b2573f2dc970108536ca41_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:9db5fb21aa5bac9a4735699112b22632d4116b59ea5a9701ebfd53e4cf9060d7_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:c96d9cb0b0a1263ce73042c92f1253fa9574e3393f78252b682e40abd79c650c_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:03cf622ba30acf01845314e0ce8c3ea61009c006ce31b49d4b88a52f835776af_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:49b67719b7dbe40b3c05c1c6ffcdd365d0690b49e819517bef8c8df2c211b7ef_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:65b0ac6216820b3fed7a5f0e3ce6dd40e7f22ba31388c5511de117baf3070575_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:fae52771a05048d0e80a89288317e12805a7ecb8bafaf1061699149652b55799_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:28f1efb600e6328c3d979c6340fb3df201a18d46f79f03b0d9fe82a3fc6b86e0_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:4a66b35aea5c789f00fa12fdd738a0b3ed5c0fd6a5e9318ad1eea6a493628769_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:6fc7498b91b7747c756781f6933957dc306baad9f815a152c9253dfc3a93300d_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:ff947ec7be161c78a0ec2d9387493ff8756d1db9bfcb3118ff7ee925dcd0a748_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:1f723bf35950fd5e2a59eb8d4a42b7001bec5fff0b427f3ceed92ff7c77e9284_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:2e35bfb3b654e5339dcde24782645683728f35b02ae5fd8f9150732c9dad6f3b_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:9edf32473e8f743b5f2a17b9deabcda31c658831d4bb2701ce6625e8cdf24e1e_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:d9086167c99e49908b8d805991a197994825f9d37146ab5bb32647d55318c17f_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:39e04746fb8a9d52738c23815978946ddc38b5a264c1193ba44ffd1508fbccfa_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:20b5c12f3ca21aecb8a8b0208cc0c1e91b979f31e2dff4d7706eacc87afb9136 (For s390x architecture) The image digest is sha256:8c7f987d305edccc45f5e8646b436b17e1ed663cf44f146eb31b16ecd721309b (For ppc64le architecture) The image digest is sha256:0479a675177654d15cd698e7b27b18a4638e435fd2476e198602e4865bd68e8b (For aarch64 architecture) The image digest is sha256:1079c0d0e47ebb0e9a9c95842c52caa8bf33105c579b090dd307639abd0c9d79 All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this vulnerability, implement a timeout in your archive/zip processing logic to abort the operation if it exceeds a few seconds, preventing the application from consuming an excessive amount of resources. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability. Workaround: To mitigate this issue, disable the $data feature if your application does not require it. If $data must be used, implement strict validation of the input fields that are referenced by the pattern keyword to ensure they contain only expected and safe characters.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:14774
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61728
- externalhttps://access.redhat.com/security/cve/CVE-2025-61731
- externalhttps://access.redhat.com/security/cve/CVE-2025-61732
- externalhttps://access.redhat.com/security/cve/CVE-2025-65637
- externalhttps://access.redhat.com/security/cve/CVE-2025-69873
- externalhttps://access.redhat.com/security/cve/CVE-2026-25679
- externalhttps://access.redhat.com/security/cve/CVE-2026-40175
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_14774.json