RHSA-2026:20041HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.19.32 bug fix and security update

Published
May 27, 2026
Last Modified
August 30, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2025-12816 — node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-66031 — node-forge: node-forge ASN.1 Unbounded Recursion CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-27143 — golang: cmd/compile: possible memory corruption after bound check elimination CVE-2026-27144 — golang: cmd/compile: no-op interface conversion bypasses overlap checking CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34043 — serialize-javascript: serialize-javascript: Denial of Service via specially crafted array-like object serialization CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:3a6d826fa907f481582a0a5ee70af3ab32ff347146333c343fd8927dabf06bf7_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:61cbb8c450a7282138f9d845ae84dab9ae9d03993e0a8575030d9e2a121340c5_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:84a9d9298c3503cae467b5c7bad0e24b1b36e96fda27d4a80fbc95b51b0abc09_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:9cf5dca791571a5639f164c2800f40d7e65c57f920e0fabb320153fd6ec74baa_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:05c268b029694e74ab331cd4d3eb2b676f6a763edbc3ab4b0f6c4a5634d613b5_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:0b263a9728df77df251390b241eafc49baa796b872218eb61fa1b39caf110996_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4946ada67861b0e978f93d2883406f5d007def53b4384086665160a0ef78bec4_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:871689bbbc8014c037e3b6bf7263323d7c33bdcc7e341c4c6bdb2454d97fea45_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:10c2a4af974dea9c5abcf6cc47651bcf667a12ab3a4e2d1f7f1d8eb86252342a_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:5749313c86fe2bb59d6b550829ca30b3de908a96a2c92ea76674a5ed9f040fd3_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:8541ede516234b075163fe98a357547f2d4b28d042b01a3858673e8d252ccf86_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:90ed55fbc35f89c0acc8fa778fda1f8a4cd78ef1eb2c0969a402f4f9bb7d9e39_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:02d39c48c3ecaaea7d6d3854845c498b53f2ef644d83c2c662f2ac15fc9ad907_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:3fea13d209e8d9b93def03754a47d96bab7aaafa919bcccb08e5c7763e758486_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:548c3884e0a29efcb4ea063a38cf1b3d2577c577af1d7d6a2212f7858ed8b35c_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:7cc717f2987f963e2f5b8f1b852dffa3cf16e40b9e967a1e7e173d27ed556e1f_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0ef2befd60f29a7fabe92c69458cb4597de763467b23aed41e4e641fddc079f0_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:460c45f766753aa5b77203ddba29d388a24e60f6fc61d4460ba03862c6470acf_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:9c46ecc3628d32c0dab618134682e6da59619d362221d84cf7ec8ca0dcfeddd5_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:c75237fa9db2881b5ae2b585d4427c9589ebc167f484c649ac268778cf286c9d_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:1c04e7d8b41ad8933f9e18e7fe7ec7895eee8e3e3d1f4bc8374ebe9822596bb5_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:909ab11809989b5091668209fb749529c9f95e87fa960050cc12dc0f7597d78c_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:a465f5562d2257c8ce032142afacbf92a865363e9a273f073a70ef912beab7f4_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:c87a26dad6744f87d20e097aa7e2bd972ec37a6af0709b82dcc4b9207200a6c4_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:05df8d4484b4f2306b541938ec4650c8c9e6d6b0393e7e656a03d5e8c38e7a6e_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:3adbafb885fba7b6d1f90f3aae103f70bec4b67f261123d45fc09055986a2735_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:929bcbde88f9df9043e2e550ef0451167d9ae72a985e3045959ccf16d2430551_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c94dc8c370431302b3c36569a9b1b14b27edc435063841597f70259556aa87bc_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:a5d47e17ff1b49b71305d12b9adf8414d1af706129e0694117e72deff33e5763_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:1bd5ad0745f446a798a4038e4d04cf651213f71bc4e76dd9349f5c6968135f9b (For s390x architecture) The image digest is sha256:c0b1bd753ef517c8636c84deee39f659075cd5dc8df654e6c1bc3f2238fe0a25 (For ppc64le architecture) The image digest is sha256:5fbe6fe21a35a4541ce893b558425dc362678b74521a8cc3ead986f4e7a8021c (For aarch64 architecture) The image digest is sha256:34e28f68135a822d581cb955afb867f600d83e9ed8dd4284847df24e90802d6d All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, strictly sanitize and enforce bounds checking on any untrusted user input that influences loop counters, iteration limits, or memory indices. If there is no integer overflow or underflow, the out-of-bounds access cannot occur. Workaround: To mitigate this issue, review code that performs memory copies or struct assignments. If data is being passed through an interface (such as 'any' or 'interface{}') just before a move operation, refactor the code to use concrete types or explicit pointers instead. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (17)