RHSA-2026:28964HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.15.66 bug fix and security update

Published
July 1, 2026
Last Modified
August 30, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-1784 — ose-cluster-ingress-operator: Remote Code Execution Through HAProxy Configuration Injection CVE-2026-27143 — golang: cmd/compile: possible memory corruption after bound check elimination CVE-2026-27144 — golang: cmd/compile: no-op interface conversion bypasses overlap checking CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:2784332d2d8b27b6e14adb13936d85a4fc01e124a410d6195f7b30c82ebc76ec_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:38c85285fbf13147039a1ae391620dda28f2250dcdc25e2b35d8e7bc3c844159_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:410cb4e15564122deb254c6371a0342e734f965b41e851fe3ad59c5fbee5ae07_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:65955b2f0f337e79a207f359c98ef268274d255bdaa7db31befb0d3f0d94ce81_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:1a0075d2225df78fe45c20fb5c68440a92492985a2a84c668b34b2b6d90a8677_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:3459355fd83b9985d72ea2c88184f8382b47bbcdd364ab767a77e3d9b71ab83a_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:8a63d9b570808e37a3e018fbbd473d0c7560994c38d647071dad0b903c9b6790_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:b05e56c26897e89a23cdfa1df43534dbcb6f788ccf6851f7cc9f9c8249691948_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:8040894458989b54bbf36d4c80bef243cabe31e9eef0f04187f90fdb2e9e8f54_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:9640c2923a2ab7c9befd25e918f9718ab0d76562831d82f9bc585838590b43e4_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:ba8c0c4932ce00d6aacee258e024ce1eb2f59d0ac790f9c49da8978c44abb3ae_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:be736a1cfc16193090728260855f204a90e69af4bd0c278fc32cd0d5e54d0fc8_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:10c79b56807841edd3f027649cb35e48679660237c8f24337ed17470ab73ae1f_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:57ea94591769cf13bbf63de8951ddcb192f49320098f227d38bb69419dc5c1ed_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:9ac2046f4f2038595d3b0ac866c91fed2a8dfa56f088a190d7029294486a706c_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:fe78b0754b3adcf93161536fc8dc59680aa83b2b36e16cc5ae64b06b6b728e6d_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:065234869e2306aec7385903a285197f75699e21bd8419109bfd1af609d1be47_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:358981f3463707747767af16becda2cbe395b7b51ea30d6e8cbd9885ebc6a4e8_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:3aaa17f14242cc1ac5031eafd05844df15b62850a4bd40e17e418dffa0c7b09b_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:7ff00cf5e6f8aa3645dd78bf89c711782f409c8f2a1569842d6b2c12eef7b685_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:010fe98874830ae4a995c006299b2fa4cab60ce4c10affab04def0168e750fcd_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:3d92a7edf9c3e6e9d80716b60289c57c4bbe57b37239f601f7a8d51cbbb3cd8c_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:9d633fae1e9508b832b83f5f6fa834e7a7e1a2ca8fe8f343cea2cbc0aa698c0d_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:b552a5cc4f2f36169f2d53646df180827883d8c977eec1b0bd96fd1406e98777_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:0f4dcd4e3004d967a4bf3e0f734c4929a90da01c42e9f6a1a9005f8585dc612d_arm64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:5b00957caf9d410e6d21915663c607eecec196f286030bc6ee3c4cccf6cf603c_s390x as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:7c25d1ff3691eaec42842b0505375e8cd8c05f232a17ade4aa24d6de1ba81766_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:c9f212ed8bb8d16388f29b6d406253a053997d35c34b6efa1a39e3ec52e225ed_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:382f7c7eecaaf240f08750f865af4e92fe77bc4e85a403ef69034d44bf735d9f_amd64 as a component of Red Hat OpenShift Container Platform 4.15
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:50bd8d046a5ca99358672ac269c5e03e3eb30aa22016145901e6f473a8130e5f (For s390x architecture) The image digest is sha256:6384ba860bfa104731afbf658ca0684a0b8eb497a7232a21a9e1cfbf0f185d15 (For ppc64le architecture) The image digest is sha256:dcef1d1529608b70846f9db3bed18a42d440a25167fa6e06f2153fa89cc87fe0 (For aarch64 architecture) The image digest is sha256:f3ce6e0bf21887b3f44827ed84d9393b01d71a272327f8df8b63e73354dea687 All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this vulnerability, strictly sanitize and enforce bounds checking on any untrusted user input that influences loop counters, iteration limits, or memory indices. If there is no integer overflow or underflow, the out-of-bounds access cannot occur. Workaround: To mitigate this issue, review code that performs memory copies or struct assignments. If data is being passed through an interface (such as 'any' or 'interface{}') just before a move operation, refactor the code to use concrete types or explicit pointers instead. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (16)