RHSA-2026:26413HighCVSS 9.1

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.19.19 security, enhancement & bug fix update

Published
June 16, 2026
Last Modified
August 30, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2025-61728 — golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

🎯 Affected products92

  • Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/cephcsi-operator-bundle@sha256:d352e6540cd5ca2ff7eaf63ec47ba7c002ea4a8c45a1f42415e4fbb2110276e0_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:00d4622c0e21f50569ea61d2deaf5b9c2cd8d859fab70c979241df06227a844b_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:25f33b805d92b80851b73a8fcc13f2205ef0b0ba417cd61f6306c39c4f805e9d_s390x as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:98927f83a6402a800af93c5ea028f3ca58b005abe674266b726d9d305e89f2d2_arm64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:9e085e36b9a18184ab1dd3af35488ff91bcec58281bd3482e76913221f488077_ppc64le as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:ccd830c680500ea444670c1625af4f389e663bd08e990acebf0a66fd72f21a64_ppc64le as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:d1a24469e633c7a953508b9b219ae96eefea3b92f0ab8bc8fded8b2b71e4c893_s390x as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:d39c457574dff2f6f34a4b93e6076d0b30f441420532b9f6ef4ac63557388436_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:10e4b0b1e5c8104a84ef65716dd04836a12c509f1e2bb75382998b4dc2f0742c_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:3cdcddbfb15f678409e770654ad17af03531e161c3e0eb56074b2a83cdee8068_s390x as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:6a97a25a60d77f764e67635e0512d0330b8bd814df805033c34a412e19c3b2f3_ppc64le as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/mcg-operator-bundle@sha256:57836fe7327e7d62d4ced14995a57db892ce5cfc50c463f1e0ecc4f7f295826f_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:1f2b2710f02f4e67ea9b86f6a8756311b1e623f2a52fa7c39fd2c8fd8de86895_arm64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:369179e1978b016b4075850bc097c2bde4b244412fb6d98ff1701840dea23539_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:ae7c45d0087e6d85e134aabc75d21fd2ec18797dfb1b8a3386706f35a97dfe0c_s390x as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:c7afbf3509237274bad9f209e841d58266b0df09a0f29d2e9798974c6182d8a9_ppc64le as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:08f92dc9db6f68e8e2ac88fa81689d5e3254350c54a5b382a97a24300dc6b316_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:0a0b8b1fb1f12a69ec5dbdf87c50912574b4c9d5c050687fd9e45d413e955992_arm64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:b6570ce1a059b538b6e68a65efafb2909f9f39e4fc0d166131747f9578ef6819_ppc64le as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:caf21f4c49c318e7e1333384e0d0df7b8ea2caa71ea6225fec04b0f2ae62481b_s390x as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-operator-bundle@sha256:781b7ac85ff24b65c1416b64b8abe2c165a1626350b9f05e135b5d66992ac742_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:26e7a63c75f38d55dd7b7682e97f17f195abb6519e8a09ebe430f6299851c6c1_s390x as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:a25dea6da75400b7cf04602e2d25a9ac619b2263094f1e3de378310dd39e34c7_ppc64le as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:fc2f5ad84aae7206ba516ecac91bc5437b8796d98e2aca8b6c61a4a7455581fa_arm64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:fc74ee3c16a984367dc75fe269fcffb1e3e264bf05e9fbc09b565e46d35bd84d_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:53e652888f7168c71b29c32e6c982c761aa512b1e2732fb5c5abfe3c9014a131_arm64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:58fa783504840df7ee010fda1200aa6314002795dd3f6c2c0547c11617d13765_s390x as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:5b4bd8cc4c3b7aec84a14c30f7828cc04f24b076b1e8aaeccd07dffc8dc893a3_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:f63c2de7163e4783603c83a547d0fb3574c56b2a60a488354f37360057612c90_ppc64le as a component of Red Hat Openshift Data Foundation 4.19
  • +62 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.19/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf Workaround: To mitigate this vulnerability, implement a timeout in your archive/zip processing logic to abort the operation if it exceeds a few seconds, preventing the application from consuming an excessive amount of resources. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (7)