Red Hat Security Advisory: OpenShift Container Platform 4.14.65 security and extras update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
🎯 Affected products159
- Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-event-proxy-rhel8@sha256:0b5e796bdaed2fd2b6545829dc99380e8366371de5a80bacdc9920d9d7f59ef3_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-event-proxy-rhel8@sha256:698fad06fb69fbc272736d33c0e7d9bc3d40c3b34963a4071cc7ad025bf92409_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/cloud-event-proxy-rhel8@sha256:b61a4a64019869689bbda5290d1e874fa6a7d386e8715284908bf312232b6808_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/frr-rhel9@sha256:0003e6298b68afa698c40bf83f4646862797684b4d0a3cc45ab9413704794336_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/frr-rhel9@sha256:5eefbfac3e08f10ba2de3713c85e3eacc8eaf3ece67cfb02ecec7310623b4e15_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/frr-rhel9@sha256:a79052bd37137b0b83ccfa55af7de66a146707e13277a62530bac2d8ab43fb0a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/frr-rhel9@sha256:c8caad52fbf57bb81fc3cb60dd71c1ea7ce4f9bd842bd73a178125026883b6e8_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:7fb76ff4720d51ebbff71195794dc4cd5b0133312a70804699cf7da381c06561_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:abfd06589800aa397a101c994075b5a050e5aa853b2964afda6dacdfa95e547e_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:c4ccb669b5161578e03fefcf8af3f26586eb2fd1697fcb8f8f4e71181af6fdeb_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:d9a03b3d8a93d890c36d2a840fbde762c5cf7f135961196527bc234b4b415cf0_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:59bbea700d67739070449f9f1c87c3d2bd269716cae6d8e5fd0d4d464c649352_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:96c083ec84a65a23b2c8f1090b660ed20512e5a197f101ba2a062d288ee416fe_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:c86beb6cd10d2385e29024ee32fa08d7381f92a879ad05166c3218dffd12a01f_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:e98e8bbc9b9f173fb753d72a37f9061dfb45d0fce7c5fc47ddc1d7094e5d227c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:1347cb745b5dd84f51774f9e33d3d92fb3c8e24c33ac1a5e330085d49e8b5ec3_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:467e4d4172cc647e0080000f693b514a6e78c20f0eb589831e8162c890cb7fe1_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:9ed35c24d443a2654de98ab60b29e9e92df2814206aacb66306a3d17baf2d671_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:f3c8775044022a26863779fbc888c994637b4781add719cea00a3183b22667fd_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:50b2d90329a5e28ba46375a7d137d6edec33487c4e5939644266c265acff2bb9_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:a0b1aa43f2bf59c68b755aa0bd384d28528abd8ee6e88f41a3eb109d43400c25_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:ca21a4f9e89634abdca9d0984b16e4b1ad1aae8f8cda088a7e1b739df6c3e6b2_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:d146ad51efd37a85f901f536056a42916c0cfca8435cbcf7684856e5ab84379b_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/metallb-rhel9@sha256:1c86bb95167a6f9fb1a7ef0499f58df1c90db279e6214643daff64fd92e8dc48_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/metallb-rhel9@sha256:26120f09ea26547739ca5fb11193495a930f146e59d7d7e7e2759e81ea177f7d_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/metallb-rhel9@sha256:832ecf1b3350150eed05ff03ad524bbb329f7dd5fe4c1e0e51451265268dffe3_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/metallb-rhel9@sha256:9c252c0825af823909b5fc5552abee0407a0dff750a5d8d8118a1812c96a20f0_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel8@sha256:3c105c17279efd1d2c367068a61959c07520e3adc1df934b60527e99f549e924_s390x as a component of Red Hat OpenShift Container Platform 4.14
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel8@sha256:445001e63cb7a2f01b308601bf1a28ecf45869ef7fa8f405ef23fbbc2af4695c_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- +129 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.