Red Hat Security Advisory: OpenShift Container Platform 4.18.44 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-1784 — ose-cluster-ingress-operator: Remote Code Execution Through HAProxy Configuration Injection CVE-2026-27140 — cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:9b4c19f5a96a5387c3476348ccf776e74a77bac2d4486724986c167b577362e6_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:9e448a7b2e0cc64494821d4e42e38a7d70842f568cba8feb6e07ceeb05479f60_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:c034c15f793fa0892c0dce1161bdab6eedd847797ecc477622fe63e0525283ff_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:fd32d959d0c9f69c5c37f862fe2fc07c3a17448c127d68533fb445c1d26e3ac3_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:29319c83c1b32de57d726a33b713a3744fafc02506156648e84a64afcd151b9d_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:318839a36cd0c975b7f966f6d6420dd490829bfb2a4c952d5fedf4963dee3fb5_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:556eddc19bb738768ed3442980213c336b18510246e3f2169d875085531020b8_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:fa662e22f6bb8ba9cc19d5322c3a5a6c65b6dc0df8415605776c7a6c21c353f5_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:40b58541fbe13d43c355406ebd8a094b87b0e64738bf545b7398383dd0c3ea90_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:65e0d4314231e26b6695a6dd3c275b6bbcebd8c2b6878adbea92ed79e0db2df1_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b1415ed3a3c6a4688dcc4b7fadad32a30097bd170e2e0d5abc5a8507d8eb57df_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:dc89d4d2f305f0bbb703ba626f18257df3d654ad6e65b9dab084eb708af31ab2_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0aeee70fcd2f172deddec0253e7f91125bc359176b08a55e6e13badb9a41cc5c_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:15a265743af6c28498f361c82101eb97c4a81a914a4a0fd5ec56eec86e36ec1d_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:9e0878f9b48921cc4a7b0e69b63e0577b8b49d5328caac39fc280833fdaef750_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:a7e50c101b30d6c9a56e94e60d0dcde26c133aad5caf58f51a05ae8da73d19f5_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:14ffae9e29679a7414b87dd79425072b3b0340ba7a2f89a594fce523c97aa276_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:367eda543131d62a1caebffd181c9fb9ef43ae254dde1f1478809ba23c922504_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:6cb52bcf9494c55e61642d2629c8a4e236060e5bd0779b2bb546812bdc7a474d_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:797c8226c1879b9313a7eb692164cc2f77c376e722886cd63fa04ffbd54a112a_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:04282ef0a1ae28b7abbd1744ff3a22026e69660e30afeb1664a88bc9aaa8de7f_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:75bb1db9b46f0d2d62dc2ce78eb5a3d6da7288c90263dbe66b938313c5dcc786_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:8c433d9a8380b69b501f645aa406773a71fe6f8c9aadea30f95eec13ecef492b_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:fb8dc6150ccb18ffd8bf2b5d14907f3db88bfce22a5ed168b4ef6064e1c2134c_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:350b75d9cbd494b8a8cdeeca04e57e8ad28501b2722aa871a23916fe9a246ab6_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:3c6a50b285443b0c5340237e10473f66903581047a19eb51c6707aa870b3f691_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:7cd0aaf53facbcb5397607358423d8b95905ad0a30f006a31a52710b66e18620_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:9eca05e46c6c39e37cfaa6d0f8432da8bf5e23ed3124ba6416a8a6da2adf5b81_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:4b78917fd199072854d5550dd3ddde54e56bbadc007e1eeea92d6be47d36eb1c_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:2a7a95814b1b307813552472d18ef7aee7930748f707d730c4e816bdced1dac9 (For s390x architecture) The image digest is sha256:363adcf59338bad26a33111d98322c8501d16707b295bd4328b30a04d6f1ce51 (For ppc64le architecture) The image digest is sha256:90fc3818102c967faece0374edf50e68aa0d1b6182fcb27793941db409515314 (For aarch64 architecture) The image digest is sha256:f0ce3bc7f47d2bda4696f49eba84569ac87f1b2b42852e9f8756fe0a3f9a853f All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:25182
- externalhttps://access.redhat.com/security/cve/CVE-2026-1784
- externalhttps://access.redhat.com/security/cve/CVE-2026-27140
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_25182.json