Red Hat Security Advisory: OpenShift Container Platform 4.19.33 bug fix and security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-1784 — ose-cluster-ingress-operator: Remote Code Execution Through HAProxy Configuration Injection CVE-2026-26996 — minimatch: minimatch: Denial of Service via specially crafted glob patterns CVE-2026-27140 — cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:45c594587b6df1aba8687382b9416a77a7ac931326d6a7e00e00403104339bba_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:50660ebed0614f6f1287cd8fccd372e6415864c65e706a1d664f73f8eb0c98df_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:8871deaabc7edbb722be3521f33fa107e11d42fcb755efab7350099d3c992af1_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:f6767b06b9ab3d43510a6a519a9e8d4b8256c17cfd2dc0596e740ee21c36d824_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:3c023c8e8391e3fb1515179fd048a803526da0ca106c18aec9d8099f15ef3b9e_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:8545140910c14b9dd873243c5ab138cd2d783a6bbc2d621c9892337f11f2b99c_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:a1c4c54d8d05af607829b86418a4243898c74d18b244e5144c323a63b5861a18_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:f1ad53e9e2b0de9b0e8bfdc3c767d579f85793a26b59f3d28da5b96373dc2b6d_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:44d767da4c0a2f947371736faa848f8bfdcb0dbc89a14966909fa857767efad3_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:661a500b691f99150461de9d9f30257edf9ede30d06c0ddd144a7bf1d4bc7d15_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:cded2642d3223801117318033ef5e98890cfba52950b2365985201c4fef88f30_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:fd4f8223c9240c580458e210b1fb1256c62dd95aae5b16436a59f71107b5deb3_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:29e2c22d9d671e7d56ec8acc1306ae5092d7c2129f9c0b5f5594f456d5cf62f7_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:8556ffb5d714cdebb45a9f5392efc55c5cf374384baae6cd8cb284b13e15bfcc_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:939a0cf5553b4e6c638d02bd63eebc0acd377b2a06a8430dc9ec0d1e07018f97_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b52080b7d06b40de69452fff7e44a20cdd6912af397f6521a3cc2902466842e7_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:59a124a0c1dcf6f38d294fa5b487e7f92628608da406ca7f3dd3a4e151e0f56a_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:7f55cc6db4e48557943b08bc46db7bd083f8b403c57ad697cd0e63070b8863a5_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:e12f1ffe655d9652965149acad9fcebe43824d1112fdcccce4d33da9796c136d_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:ea5da16c8fcfb2203103e6db1c1ebd013b4db8c43b464c8c6a5bef1b65abc652_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:6c02fa209230f491502c307cf24eb2b543c06d39d145dc90f0c714d93f130dd5_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:9d1afab8285a3dac07cb9ba998e1fe089035d407ef8324c47d58400355887d99_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:aad2ed4541305224da02e5f638dd490dd79e769bd6325307285a5cfa0229a157_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:be3f383be21c968b6dc6253811f8fe904666c73898357017762dd994aa7e8395_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:76c3ff2547395db809e14f5472d5a2ee2f94603684793838164a803317ff97a1_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:a2c409048b995254dc823ba3a5dce7540e416293aab251b463ce4d123f4fa6e7_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d044d64d2aa9af3d9edbd7a0e84ff8f183f5eda681813afeafae5047582199fa_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d54a4146de02111a4fab6a4dd2ccfb334f804c069f360b8ecb38947aa22aa671_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:1143dc00b5d03046f0f337e8aa01f5c5a9f6d8427c4b4ffad361a89a5d0e54e9_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:f7c8010c24807273c8b9e77064d4a7089c8fcf6585749d864b55b98176ba745f (For s390x architecture) The image digest is sha256:093b7cfbad0f920f6f5668c9edfa120a5fd43ed24c71020464133dab18d4394a (For ppc64le architecture) The image digest is sha256:8121257742990c3b7d3b1dc4661f6029cf694a7f5f85d7497a466a019b029b20 (For aarch64 architecture) The image digest is sha256:d73df62e9d3254daccf3fabc888e4081a67e39048191517292fdf0b60c19c7b5 All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:23246
- externalhttps://access.redhat.com/security/cve/CVE-2026-1784
- externalhttps://access.redhat.com/security/cve/CVE-2026-26996
- externalhttps://access.redhat.com/security/cve/CVE-2026-27140
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_23246.json