RHSA-2026:20035HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.21.17 security and extras update

Published
May 26, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

🎯 Affected products189

  • Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:573eb9f2b9b99dc0d5e0b4901a2fef1fa002f52532409c26f4c0c7f94c786196_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:7f2e3d413d4d2857386676843c9bce5b153702cfe277186137c2bbdb19ff48a9_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:c7040abb132449da5bb703f094f4403301b25996268978f9d12eea10ef2cd69b_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:ec07262d349bdf585fece3764dc38fc13493673997379ca5fdcad87b6baf336e_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:2d892209671fed19761d60becfd7e9564698743a25f815dbd1af3afdb50e99e1_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:950f38e3b0b1441e665c1abb48dd26d9f587c9ed831d97a992837295dcf0fa6b_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:e317aa660d22d293773c005d0e7437e57c085a40b24e1180800fdf3134ce15f2_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:e88c7adb221f1cc0979084e440b63334c9f3117b37590d78bdcc40e2ba98565d_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:05bde3d13bacbfcb8329f1569bd0748e7e549d731d89132911ab69407daa8d8b_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:79e5a8e0eb1355b8df9fdc117c1cb64dffade6eb85298f3d0eaf8fcb84d52c0b_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:e4533d634133534886be2bbfe0d7c63a149a282d47018907ec6521e839ab1290_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:e8f4a6735c0922204c86d49dbc63d5b1b20ec1ade0c3e353f1645ac7efa5875c_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:192b712b9d3d91c062e6990af57647b71227ffedce071051def719bd85b55cae_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:29be22b144cebadb3c054540d6a761db9615108daf8762b50605cec4e9a333a8_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:d77cedbe72245db75dd8c87feea08396587e410b015f13f781a4b441202a1006_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:f95ec1998e070d3887f46f8f984d44a9ab1f9edf491eaa38d22ca3d86b8bf0c7_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:3a25a80e1e4669bc552bcd1c7ff6cdba73d2f034cdd9e62beba3784d13eed711_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:4044b4016c2be3d7e359bb5197476a29f4dd56ece7fd3146876fa03d1cc06df4_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:bf7a702c58ba337dd010e453f64082adcca53f9b3a94362b46faeaa4c8822252_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:ff0e88970bca03d5d3bef2bdb1c577e0b552da18728dec789d756859d3be693c_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:089a5b4367e9cd2572b4e4a1832744332ea7ccce3bdeeed71ee516b98d778591_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:08a8194866c555854dd843d9b832fe1d13d805614b7b44f49634c6c6a847b2fc_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:389f1ce665c6d84010847a697dba4e2e28ac8e7873ce97809497bc15554ab2e2_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:f582efa031b20c4a6c7910faef82dca1ac10651a5310a9f53e529b2c35ed5431_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:32d9c4f80c10671a6fb33ebaa37a107efc9150bd35c0c8dbcee104a759a43316_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:615907b7d30197b499b0fd146a0cc6f660a03e955b82dc34c05ef58828798254_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:b970c7f0948627b92696c29c212364f6a2bf029accb3811f74a43dac74e61bc5_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:df7d08478da24dfb1e70c7b06c5d18a7860e6b6f617ed42f3630817f99d73da0_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:411151ebcc8aebff9496e39856bb67966b4cdf7ed9a68ade811ef2437ffc5d02_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • +159 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (4)