RHSA-2026:23234HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.15.65 bug fix and security update

Published
June 11, 2026
Last Modified
August 30, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-35172 — github.com/distribution/distribution: Distribution: Information disclosure via stale references after content deletion

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:37d11c57600f597bfa14565b8431f463c4fdd71ca9f97314011be1999cf4cb65_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:92c79379c3e9abe2be3d8f7d10fd60e3c1a284d39af60089356da2c253c19130_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:ddf39f66b60dbd596dc46859e85d94bd401c1b7d333704d679d44791f2bb23e5_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:f0d5fb47f3b97b29b58cc06bed59549da4240c121640e182cd6f28a3df7fecfc_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:1f8df4611db3e98d0faf71ecd9161290ac37caf3aabffe655a11808e43796f74_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:509cd0524603e1fd2bb51a10f182905b75cc8dde90cff340bacb7d8b983950ae_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:6aa02ae4c8604eff09a09a2640e38532e3535352ea94b303669ea377058f9bf7_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:988da51896bbcb8186849e58cba97930578bee523dae3398d43399eceae74d19_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:1d280a964e59826aee370c7a2d26e0b8429cf22fb8513250af4e98f5db80d03c_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:843c33cd64bad8771a539a7f9938c98ec147c5bfead95f95b0dc9046dbbad01c_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:a179b77b6453c2b1c13d529398fe330999c03fd8b55744e945ec174775af2c67_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:c4398e6b5dc06abe3b27a6ed946f8a7184dd579bfa39bdaeb79d68da97989e18_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:052a4fd280e65ad3edf580e243a23d75deb4d0c6807ead17b9be1d1e936a0dc0_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:637759c253e593d03a1f476c367afed8398d5186c565f217d052cbfb8e11a18b_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:7a239b2338b47450b8d047b200c9889337a7f6ebc0fe86ffa5a66ce2e962b762_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:7fdaf710978a097165da38d049baa4486a76047e9da2c4cfe9bf254f44bac06d_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:189dd34c954284027ad0519c3a6bc335ba7ba14604e12208b6dcfc8c25b8d320_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:52c3970d34ab29b4607a3667ac4ab1e6f6822b2a70503a7c6ea6bf84bc524e9c_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:577d4cd6f9dc7d70c68aa019288210186171aa6a786a5c2319da5252905ebda4_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:8e4093f7726f6cb2f8aba94e8d8da628a46ddd2283c454b36a89ce5e782ae812_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:19c53b9d9c0903c1ade6911f1695821ddc85ea8dcb84e4713f9bda526917f559_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:543bfb02708ebe2511757e93ff25e704739f97a511143a54d65b5e760c5a2c19_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:924585e1d2cdfa58ea121a48ba646f385a3e9acbb3eac734f0b581673d22f86a_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:e9e482520887bd06781fdc63fd9b1d54a1842755ca3d33d5e2e792a908787a2e_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:73b7154e3d997d3e8c4e20a04ee4e03c31e8b79f1bbede9b743e36b7637b021a_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:9d975ece99b7d955095445e65cf6c727a31384bf4d0225f67e90ac45ff8eb13f_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:d78cedcad0974883c2c02fd4e996b1a8d1c4ccd19cf135835d0edabbcd89d23e_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:d7992dbc82bb2b1b5e0c4f0aa7f6b7e811ea4c2026ca8c3b81859ce55f23a746_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:6072b8760e62e3b46ff26f0ebb9900738a964f99fd19c6a3f8241edb7d27d401_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:5bc12d09997fd6b86a5d7ab2a5bf482474cb95b624c22a4d05607e3397302cac (For s390x architecture) The image digest is sha256:10bccfc41bb95736b0d6a1a91e3fb1c968771e3f023019abdb7480ac7de1a107 (For ppc64le architecture) The image digest is sha256:9adfb17a263640a6c55c11fdab9ae0ccb7ac73e421fb674318c17d616c4ae4ad (For aarch64 architecture) The image digest is sha256:9f35e9b44efc724d4e44a788808e0192d9710a993a4e0b2f2993a6444201f896 All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (5)