RHSA-2026:21709HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.21.18 bug fix and security update

Published
June 2, 2026
Last Modified
July 30, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-26996 — minimatch: minimatch: Denial of Service via specially crafted glob patterns CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:17408f54d2afb09ca531693b18261add8a827cf7f9afdedc612aec1052e3d59f_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:407fa5b3937d7e1bf3ef83a31de963555b2719ee19a45fe4a30bbf04a9d89330_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:cdd5cafb5ba514d34b5396e19464738ea7cb4ba662e183f15c8c3a113cef740f_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:eafe6235017eb45baeeaa139d9b709b09a437129372a5045cc8895b28145a58d_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:1b3314f3c46c86863a6bbd2b1d7bc61a5fbfc634581dfc750c7e0822f16329b7_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:3c64e822e5aeb9d63ca880a8143e9bff6b76dd9dc5edbbe8cf43cc5be3a46995_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:594fb9232dd4a3fba648af5741db04a7d102f6ad19cfd276dca191c3af156914_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:c8e891946f9df185a5077172a52f83e55f10c42c95d8f8dc8ce803ca37816fb5_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:0039d5aa7a97404185e81107bbddb330b1b94ea0c2548f96148d280b3cfc58df_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:0c20b09ff504c526a64bf50e04315dd5f19f718eae6558ec59417208a8c6a1fc_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:131d96dbd856b26ea4807801112662a1180bf78921a4e05edbfaeb7f68028be5_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:7d0c9884002bf287d4135cb8ba681226d9f6630ac1d3be5b6c2c0f938693b0bb_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:12843195f50a7cee51c9a6973e777e69ba31e580271b24b092bafee83b0aa74f_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:1b376554df90f4a4d62b28e9b3818eb2e5cc43b4b17d69435946bbd8001cc5e9_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:7d8364af051527cd68921ead67e1b6d29a9786771160c7744e9d0a3c4cf32619_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:c615e4cac78f1f2b13493a591ecdad03a6cc006c311453c14fc8f6746a68c288_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:102b3c552096616499f77cb1809980ff8e20b1759c96cd1d580348f6f1851068_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:4aa4ea9828f5882549c13a229101eea6bb486bb5ce1592515ba3fa10609a71f0_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:5c0b9cbc49e33b23c14ba7ba4ae668261e33f0fded127ad7c89f6c84b6c3eb7a_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:5fb6ca2d3dceb1e0d963d4916b417c0e15a720b016cfaa3f24ac3cd19d12438b_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:27d9c2075a202aa7f2450047b9feb5155324c181a7476f75e1e7b75854b1aef9_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:708aafff24a8b5554a34d97b35fcc3960aec93e1ec5be6746623c17c2edc3d2c_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:730ba8dac30502f498e8fe0ed140377c4b30c0c6eea99eb69a8a7e22433eefc3_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:a00ea252ec5118b50d43ca9ff0ed6044ef538f07c4a9b0334414555aca422de2_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:52af821153a736cbe6de87e18c2df5a00092049433c8e0be0be3e8587ae0d25e_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:674825555c1bc1b01e9b3c9c2649f1218bbbba11497062f8af7afddbebd8e72e_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f454f0a46053fc25a4e70f4aa59b4289d1c4d4c418c84fc681357a4112dab416_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:fcea184ef87e864901fc1e5956f62e95a9c3608a199df63d0035cd40ff431387_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:132df2044bcef27893d195cd2c670ff4a6ae70b35440a66fbfeec6b2ab455811_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:81071b95d587ae2bb8f1d651c0d537d408fc4c86a5d664c7be077edf8ca99603 (For s390x architecture) The image digest is sha256:3f6187bdaac8dd225d87416237c2b61741d12eb56ae8042563e851247d39d448 (For ppc64le architecture) The image digest is sha256:0cd31c10b0d84d415b4fe035cc9a7bcc88f195c85bbd55c1c058a87e8e469e1f (For aarch64 architecture) The image digest is sha256:400c31a6bf0042e625fadb528ad0fe0bfcb03aeb31893bee18f77a9b59139d1a All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (6)