RHSA-2026:21710HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.21.18 security and extras update

Published
June 2, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

🎯 Affected products191

  • Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:5a28f81d91d1302cbc3feda6378990c9a41044a6a4271d0f2d92b7f2af004bfc_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:7757e7829b2989e1ea7f54258d0073d138c573fd597e9cb18d06670f2c0f80f2_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:7c1fc5588ff5f62113cd035cfe5951cceaeabc8dd2ac12551133c69638fd2ebe_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:f01aa9a672f7e0a67940ada51df4830dc240a3ab496d8041f44b4391233a4fab_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:2ed1a612a3182f2d5669bbceb58f52194366b29414e00475ed0bc3443ab2d0d2_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:65f31efc577c5258bd80750ef79cb07bf37572f6bf9292794688883d042eced4_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:9e58618f5a0332c1ef488e858f9e8926755ed38978b48d597a6f067b89f128a3_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:f512e9dc436c44e55ab0b67662a902620765f2e382765780657701fe5fc8a1fd_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:23153ff4810e3c6c235516b98335cbb3ef820d54331f0f21d3ed02aaf68ccb88_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:57faf006f73ef0e5068ebc2c7586f056e17a5a6960c0f4b8bcff520c1b6f6b6a_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:5f0fdec46db1996b581bf9bc7466c3d4972a5e83b2da368d1e8809565301be8a_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:8cef00e86ae9bcd28a0202f8751a750b3a23616ebc4389e2aea1fdef3df9faf0_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:095649b15adaaa403b01b8c6572f922775df452a31c33aa824edfdc57f2a8c73_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:19109a90632d26ea192e56b449e18404f7278da8d338ab53bf1fd29fac500f83_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:3e1f8846653c696e9ad88448d29c9ea3b9b35846d6cde860b6d0edb81ba40945_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:9777a547838b7f8321566443beda0e889d5ff7944a27d2f8da6861a37eed030f_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:3ed9e3d732272b524718d1fb436cd51cf67fe355b6571f882e9cb754150331d5_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:4d2f4107bd19c176f97ad7745d344ae373e5cf2dbcf5579905e92e9836f2a9f7_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:50b5fd460db0156040e3ef222a0bd9288599a2ecff2781778a71ad915570f1d5_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:934cc8ae86e0ee349fc6f3d55020b6da504909305ceb087be5f541acb5e82b81_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:5c5c8d850ffa936886d19c0d0e1740c43c53a9ac7292aedaabf16af9cc1f73c7_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:aa5f388188b2a5b406a91711a90922877ec9e721d10296238d357760590eb2aa_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:aac4d3e0a54227454ab90980c94991d5ed5efaba28443530d8ecac20a2df99dc_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:fea4dcd57738b25f5bc1645739659167a12915f4f94697225877eb37a32628ec_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:01a72f6796bcd94eb596bd5a074bddf8f4d26b29b4e6d1459db28d985731514a_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:80e5b2256a9fbba0d19ba0c923dc421bba98530c5a1e428832b8c23bf3ebd17e_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:dcc4cf61975d834897fcd68494ed65e514a3afd1e397b0e7f4b7ebcbeac0feab_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:f614aca22bc91a64592d8c986ca3644f7b93393633c4217b040e5744a7c787c5_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:50252d63399f0680023a493ced626bfad692b901e8d335551e05b79515647592_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • +161 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (4)