Red Hat Security Advisory: OpenShift Container Platform 4.18.42 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34043 — serialize-javascript: serialize-javascript: Denial of Service via specially crafted array-like object serialization CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object
🎯 Affected products89
- Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:1a90ecaa0bf5883372bd0e744961369fe3b3064cd151e8972a6eaa5fc327b1d5_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:6c9025e27fe5e5bac0d0df4b57756df52841ff5d27cedceccd2a9c98949814c3_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:89b7cb7f468a0f3373c1b18481e9d79c8dbca881b66cc9b2750d0f05e2ff3760_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:f965feef38c32aab05431a9a9ca6617e04507e0f85693569ac24a7d09d28e57f_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:2cbd01ac79e20044a3fdd6cd774031d624029bef2a8d46628e3ddbc69936756a_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:3039e9f2faaf13dab2908306147d55ff2bb7697ed60f065a53bcd9889e9dac95_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:41450f48c4386595d9c9d1b9bc587cef1ded0547fb7ddbe7e5f12cd20706cee0_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:68703efe53ec01ce95f1252c5d654107ea2bc81f5c8d176e13457ad7c7cb973c_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:a3935320e319694994b1c916f1d80d1da7ef833b81870786de2a6a7e0a06a871_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:a807cf31784c03fba9904cd051f01a2d4bfb4bf1b06993718e003f04eb6e3be8_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:b0a054194fb388308cd6d320a82d7f0578f430dfdc112517ba95ff3b89aa5005_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:b59417e757d796cc81231dc86d718b72f5512d8dc265c7dc489e3ac44a7ed41f_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel9@sha256:1970c0068a78d44ebc89bf11e6bedec15507a3499299b4e095720be7e5d248af_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel9@sha256:898d1fb079be1005cab8c3f5358811ea62d6189906a1b579486301d55bd13574_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel9@sha256:a971d70dddcf30f90546e1f075d3c8cf808b5a18e0674fc302623ebb29219931_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel9@sha256:e0f5cae9c8813d16e48902aaccb621762ba5a781b85cffbf497550dfb27a149c_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel9-operator@sha256:5663332b1280c8eb5af7d1a447d7d133a9ed7145fee3e4b8fc8782eb6628b866_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel9-operator@sha256:acda71f659e07e77c2088e40ec24e013481567d1222efd24431e777fdd611d1b_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel9-operator@sha256:72ae22bc4a3f4cec5544d8662f9090093a02f15f8b6efc2abc6f4acc2a1abf63_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel9-operator@sha256:9ac5ea6ebead6465c8f6c258caf477fdef2024b5ce2bba33e910e43e91660e1f_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-azure-file-csi-driver-operator-rhel9@sha256:6581ddd902d56312a4915019c5e01deed3f14ffbad508d9f8572fdd9137dd931_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-azure-file-csi-driver-operator-rhel9@sha256:fda5d6016e13bcf2bca64a4b95cb5dac85d589816a8ba87d0cb2a26d5a81a0a1_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-cluster-authentication-rhel9-operator@sha256:6969f18060750e317df386d4e6aa3fdf7f5c5fa7be6e8ea1f2f7cac542850d59_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-cluster-authentication-rhel9-operator@sha256:82d4e26355c6b270ed71536b369a285466c9ab4afbc7239ca11789bb33627b9c_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-cluster-authentication-rhel9-operator@sha256:b69f9dd1fa1cd042bfef80afbfb12e12aed6ffa8ae53918b7dc10203a280ac66_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-cluster-authentication-rhel9-operator@sha256:ed973b1f61ba3ebc8b6c3ae5fea43dcd5b89558b6158ab285b37cf616237e903_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-cluster-network-rhel9-operator@sha256:ca311cf0148946d0dfd9d181ae7f7201ed672265a21294e27a899f6248f84084_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-cluster-network-rhel9-operator@sha256:d7adf333ab0b6a4fc2e73cbd74c2c8ea1feee75006b489ad06d8537324300442_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-cluster-network-rhel9-operator@sha256:ddcec9825e939afabd744e758603081b6f42bece280058dfe4e7113d9343e4a2_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- +59 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:6d06289d04fe358bc23dcadb3bfdc46b3aaadf2d189a0fecbf3e521bd740378a (For s390x architecture) The image digest is sha256:c5f9c801aa2a73a41654d475fa41b3c05fb27a4309edc9e647b2d68d82f93f48 (For ppc64le architecture) The image digest is sha256:535d8eb807614d87f2e1173b067a2d28fdab25111bec3ed39dcbe937397a853a (For aarch64 architecture) The image digest is sha256:f4bcaf145f146d33ed51280516edc9dce03e27917c073c7a825a1506963f26ac All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:17448
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-34043
- externalhttps://access.redhat.com/security/cve/CVE-2026-34986
- externalhttps://access.redhat.com/security/cve/CVE-2026-4800
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_17448.json