Red Hat Security Advisory: OpenShift Container Platform 4.21.16 bug fix and security update
🔗 CVE IDs covered (10)
📋 Description
CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34043 — serialize-javascript: serialize-javascript: Denial of Service via specially crafted array-like object serialization CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation CVE-2026-42033 — axios: Axios: HTTP Transport Hijacking via Prototype Pollution CVE-2026-42035 — axios: Axios: Arbitrary HTTP header injection via prototype pollution CVE-2026-42039 — axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data CVE-2026-42041 — axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling CVE-2026-42043 — axios: Axios: NO_PROXY bypass via crafted URL
🎯 Affected products157
- Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:15d899f50080b793865170add60d8f1a75c720fbee60a15005d6791af9664176_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4cdcfdcd48f6d44b9e75c1d610bfed3bf7deeea7a6da410e78925a29649a3d15_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:b2b2b4fc5b877bf6e928a10d62b61bd65d18f52b6bf9ac533cc0dafa0b151fe2_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:b2f7f88fa043f9011f321d847ded2554736b76cba8dbe3372bedb7c6537d9b5d_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:594694c4f2008847ba9cb2f42e7de8264e00bb6b7dc8aa3235bd1391b1f527ec_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:931f36de29d8ccf292379629333181d06b9210282b146c5699ed3f4f2074de77_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b07e3d79409fdad72030a6d520d7008d4c838bd44a7af7d3a061458c17aa6096_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:cacd7eb667b8e1f325a41ec54f850e8556bf275a6c3e8295c82ff303559cd9be_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:2cacf34a5f292d0a84263140f8061289102108c7905daf01842052e72992bd2c_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:36b553261335bf4b6ba7d155cde2e54929dc206ae5e7fe56e4a9c44d9e5fc07e_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d1215e5c251c3a337c81fcae4dd111fd22b923aae6e759868909a4d9fa75bebc_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ef730a91932609ef344898f12538947dbd2c13af10c8f8448bf2662d5ab022b7_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/frr-rhel9@sha256:5097acf40215175bef20dbb8f249e4c58ea8cd75684c87cc533d48c6be2a3c12_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/frr-rhel9@sha256:d8d9a0dee7927da9697cd29203689f7c847f3d1b82ca400823d516ea3e684816_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/frr-rhel9@sha256:ddc333602ac2457714015ee718a8674e3f6e805fd0589501d4d4d925eb40a191_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/frr-rhel9@sha256:feea47426eb0922fcf6dbf33bbe619a8abcafce0fc8fb4ae8d8a90412b4900b3_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:29e1e1e1ca44f7caae7ee305313fca894ddaacc9049963caa45af99051a647d8_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:7b45de4a58e34b5904345ecb456988ab5176239e63147ec8e7992315978454aa_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:d64344fd9ae6480774a12844830c347829a60f0d3c7b84f5f05042f7c09718a9_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:f3a6919ff37cd4b08c178c1feea2f978f3d67c54f1bf1007c3b5782a3fdd234c_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:2ec469bebe6c9dff060fc2a224d97e1d8dabd1e867d9ac6404cb7e2ac36e5cb9_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:95780b4def38c93efdbded76fac156c0990f91dc8d7a9595fec452ef910cc3e4_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:b540997592d10fa018c055a56795449f9dd55f21d283800c536c3a5c045cdd15_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/network-tools-rhel9@sha256:cce64b2a7fad21d1bf507d9a600699ac387e44f66154399e96bf03dbd2907ef1_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel9@sha256:1792c8b1258d4fe59797b814ff2708d906c0bc0e19fd85c825197bf1de4b2127_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel9@sha256:2e4af264a75a29439a7e56cb5429d302da3d8ed6433769a0b6426814d7ad230d_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel9@sha256:58e26d6699a22f7816c79880754486b99dc6e74de034c44c2fc1cf4df0a6d282_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel9@sha256:60cc4b55321b15439e708071c706f1ed26f8bf8cfe42b53e3847797fab0d57b8_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:8bb2b459e0dcac980023e9435b6994ac9d9ba4208290218ed487e03c6fb76883_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- +127 more not shown
✅ Remediation
For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:5883651d854e5056a10052cc1b4cf319387b7d96f9fa668e385a49659177264b (For s390x architecture) The image digest is sha256:94c8e01e933758496eb9aed0be3b0aa9b24b112c24f453553e447a43397155d2 (For ppc64le architecture) The image digest is sha256:fb86c09b7f3e249c79b5b8d753a8cd8f419b7dec84c073eab63ebd12a4708798 (For aarch64 architecture) The image digest is sha256:e6ba7c4476044cfd185679675907b8b4c247189a5fb9204bccd3d27c2f05ffcc All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:17474
- externalhttps://access.redhat.com/security/cve/CVE-2026-22029
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-34043
- externalhttps://access.redhat.com/security/cve/CVE-2026-34986
- externalhttps://access.redhat.com/security/cve/CVE-2026-40175
- externalhttps://access.redhat.com/security/cve/CVE-2026-42033
- externalhttps://access.redhat.com/security/cve/CVE-2026-42035
- externalhttps://access.redhat.com/security/cve/CVE-2026-42039
- externalhttps://access.redhat.com/security/cve/CVE-2026-42041
- externalhttps://access.redhat.com/security/cve/CVE-2026-42043
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_17474.json