RHSA-2026:34100HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.17.55 security and extras update

Published
July 9, 2026
Last Modified
August 30, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-15284 — qs: qs: Denial of Service via improper input validation in array parsing CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:13aee442582ce386b0e68b4680d8df3f02ff43d80b521e87631522e3f827a013_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:5ce3a4f1aa8c4c9e35725eda911cc4c71d3774a69025ea1cea3dd86149bc97b2_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:631de7310be89b502d1871ac204149b14a00f7aa94ed02a6be9f312ddf80ccea_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:cb12ec82248125f9547f05927a035b23271fb8ef4601e7823f634edc6d1f834d_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:0da909efa3eadaab9525aaac87bc362ee63041daeb99568505c6e0c0a939dbd6_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:6762668dca22d9473a6f1c60307bf738f4ca88841034ca526b62e0023b752350_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:930b4869dd1be54d42ce5ccbeaacb265b77ac12f846018711cb4ce3e88826478_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:9c76e213d4c93d04b6e6ce4c233baf3e674bebc33de101218bd2a87be2c6a966_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:60abba0864ffe5acd4c5e9bf9e078a6c20ebcbb81291efd9b1c31b96a6e765bd_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:df96b262a721e8a940e4553b59943106f76a3a49eebea8a1797f2f52beda2060_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:e8d59e43b7dca836c7ae382cc82e93072bd2987cf8688268061fdb67b72aeac3_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:eb87673ad6fcc13b27b9a4b174259efe1832b65812f25e6f5b0493c8536be238_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:4decf02bd1c0efe53dfda90095ed366d665ee7ea4944039685baea7dfcbc4338_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:7367d8c2d4cf15db2b4951002ca302633eb0ce5b573af384dbb173b56aa6a010_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:d4aefcbc51be1d54c76ef0c45553cff63faaf717993e41790b505080b3e445da_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:dd36b87e226ac60a39f00b6612ad872463cd803e563b0a0bdc4ed4b62cc003bc_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:1af264bdffd6a4a2a81bfe15d46f128ff37622e5fcc316f8460e96573c1c4560_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:5dff181345feec6b6ef2573e3acae81153bf30e5acca02aa4ad632361878ef3a_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:8edbca867008344539db15d42d82761a0160a9dd294d6e48a07d7ca21c512ea8_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:9aa84a7c5f6dc9a42703ea869f56a9aad8258098ba65af015bf11a5094c5fb75_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:076eaa4ae141b661b3797f8b6aba82e5e57034a864a56dce1bb1af54bd68f9c2_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:6737c305554d290214b53b67f2f9655338302f21b11caa6351af3fe934e09d7d_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:bea5b401f00cd95038b2feff00442f19be654fc7e04741e12df79d11afd16aae_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:e1f9349a956708c5925b59dcb702c8da9de6786c40c5d007782944fbd60b08ae_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:16c6bd2a7614a02ea8d728d26ddead6ad9c1405a9581005f9d0dbcf81f0f996b_amd64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:58abf373a1b9071c9dad4f0eb5f9d921324b521e08b209d4d13e5264ebd74b54_s390x as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:80c980cb85de8afe3e7b79bf3df93c7666a0e6657d053a77da2bf220b6a358d5_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:8e0854080d2bf5666dd9b988fd4d266ced521abdbdc02535cae29be7ba68a539_arm64 as a component of Red Hat OpenShift Container Platform 4.17
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:418ba1faa960209e23efa2c8b6e2f92916afbae73e843cfd54a00ead9e93ca12_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
  • +170 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (10)