RHSA-2026:17549HighCVSS 8.1

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.16.26 security, enhancement & bug fix update

Published
May 14, 2026
Last Modified
August 26, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-33036 — fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass

🎯 Affected products76

  • Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:1f667d61ae5529b52b7537b23a290cdca9e91133864f2ff7518b2480cdbc40b7_amd64 as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:2810bac86702f5bbbd727a12e99da6976f6166f1da9f01eb4d35ae41f381bbbe_ppc64le as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:8f5f80623fb00df86739b4d32fa50fdcffc7a68f0895eb40db5867e76ee8630c_s390x as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:3a9e650dc700faace1b7d599278b12bdf074a02eddbcb1efc2351b6f77472bc7_amd64 as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:4635e9284dc4d215ac452eb152b14009ff239f3ec50eff4e6325d0e7d55e2d31_ppc64le as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:f771d1fea7a88644164e85139f130fc9be24ee6bfce654e37681e0d5f22e5310_s390x as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/mcg-operator-bundle@sha256:44606b5b4632120cefebc7d319957945a7b3612309e0305e0465d5d33278518e_amd64 as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:1facb3f3c57272706e1313a8ce2a4b3764b78e2cb8829082db9fbced2431a8b2_s390x as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:b7f926dbd219b0fed4b4281ca01621512a9a3bdc67278f481892f1ee8dec293b_ppc64le as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:b82562b8ae40af8096c5744223f7c06897a3b271b03ecd9bf1b03c563e671272_amd64 as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:d143712b074ec9605568f4c9a636a3658819438f49de72b452ab4e123d5abec6_arm64 as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:12a906ca4e071316e22b2960931f24da4042267ae78103c52e32e7d7d5e0534a_amd64 as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:1eacd0e1955894ab65a0f3a0ebec0c07ed9d27e74ac30b65404e5a97cfb3c223_s390x as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:4f5f506f9773667fa5fceadf0c1cc96793d1577a48af7d98958f32afba062a8e_ppc64le as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/ocs-client-operator-bundle@sha256:bc27a59bd22a0d899c801e116f1d7c0710e21f9cdba852cf42152f7e5d1bd793_amd64 as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:06f56561d2a470ca2bf03c17cc5f15d0534c80ca600ebddf4f62a8a29ddf0c18_s390x as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:3367e3826c640c0c65ee53d8ef29f47cfba50f49373382b7d8c0dcb6a17abf36_ppc64le as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:3ca101c54a0514e10ae8125002cfb63c1d48d88c8bf49b5fa6f7b96a527f3527_arm64 as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:d6e19cf7e9e1f3011bf7f04f5544cce4bb1c90269d7d912431005421a201641d_amd64 as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:37f2798d3763aae733494ff714156c5e145a936473e4a536badbdfcb673ddb6b_ppc64le as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:6f74c913e7c2780103d9d8bf5ae17044197ba3f83ed46f27a1d557d265410113_amd64 as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:8cfeadba40de68afbd97024f9213d9fa96876493d9dcc9c591bfcf236a1c044e_s390x as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/ocs-operator-bundle@sha256:c8085ccd0d99548e839483b87e69547fbe378bff8b37211ffeb8389531dfe6df_amd64 as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/ocs-rhel9-operator@sha256:7a442df31d13ba3d69018b23d7c4076e9d094ee47ff9c1fc7803affe5e97d007_arm64 as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/ocs-rhel9-operator@sha256:87a3472fcb82be818426331848735f92c789c1dfe965ac7f0dbe4daa870150c4_amd64 as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/ocs-rhel9-operator@sha256:893c35db502f94ccc75da10f156916fec510b98f4eebbc38eed1decde1a47522_s390x as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/ocs-rhel9-operator@sha256:8eb5edd07cdaa478e7ee712b958f0342846584568a77fb3c3327409975c68a1d_ppc64le as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/odf-cli-rhel9@sha256:2e839867cca1cc39a461542169767279c6795b92df43a48532333971c5d09fd7_arm64 as a component of Red Hat Openshift Data Foundation 4.16
  • registry.redhat.io/odf4/odf-cli-rhel9@sha256:5ac89ac1c3ed0f0e742f68ef9c5b34fed7bc1e5bee0b1e7d26e33a0e40c17dd0_ppc64le as a component of Red Hat Openshift Data Foundation 4.16
  • +46 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.16/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (6)