Red Hat Security Advisory: Red Hat OpenShift API for Data Protection
🔗 CVE IDs covered (3)
📋 Description
CVE-2025-66418 — urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion CVE-2025-66471 — urllib3: urllib3 Streaming API improperly handles highly compressed data CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
🎯 Affected products42
- OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:094258ed808f8815225e8473fcf71f85701cde60d3b2081264bbd055239fb54b_s390x as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:44868c71d21211d67c39480deefbd948509be584eef34aa87c76ef3f2ed86481_arm64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:59048e201ffb74e7f1f134b80b661379715d8e00ed4326475b691e50eabd22c8_ppc64le as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:b9c6a326e2cc6b45e5fb491c3e2b284d7f519f7decdeeacc724cd30f73a80fd3_amd64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:109587c1ef0a80adb21b00a69b3ed5b87de5b025b22d0c89ca3b36b3a956f538_arm64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:588eb439d6ca4e95f2d66e5511f369d00ef9994b9b72c0f048ae0a80e4494984_ppc64le as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:8824dd1093397de37d201f3bf22bde613014ea1a534188a405d2bde1ab4f1aac_amd64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:971850db6edd5189eb3268f74fa8240c9c2c61d168b9652d861a9e36d5f7183b_s390x as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-operator-bundle@sha256:39b71e72cc81926700c13062af301667e8d04ffa8f8b033c57d02c7b5d2ea281_amd64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:4226fa8fa7e6db8073217852c948d18cac9aa75d772c647fb57e38791f96653a_s390x as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:832abe32df58187849c202474d7144dfc6f120ecb50a3bb432fef9eb875bdec0_ppc64le as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:8b2314048002ee2bf544aef4e0de213e43f1240f77903fbf1320e92dd2a03583_amd64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:922e02f07ecc178295934c46705c0ce6a1f377e7df3085ad76ebac04be6363b3_arm64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:88afb6b847a016ee51afc44166f15519569d6b788ece8fd4cc1c6fb7ed37b20f_amd64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:b6a1df91a557e66a352384251b062f20c35907a6f95235e011a5eedf88ef8458_ppc64le as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:c716d6ffafd061dd6f5fdaac156f02482fd2246292f24a0a72ff7fed4a50a522_arm64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:ef9a25f2f34bfb96e94f29665ea8f8a203aab402c4bdd79e1b8a065655b37b84_s390x as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-csi-rhel9@sha256:06295855b40e15fb75b38b9e4a756a970751c576e4b8002f5842cc107cecefb4_amd64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-csi-rhel9@sha256:2ad3bbbc990723eae695be7c6b76fc4ea239dd554f8e836f4e19bfe7a022c8f2_arm64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-csi-rhel9@sha256:5a401aebb70eb3585b95d67db06bac7cc7a929ffdf97675230f16ba97e62d65c_ppc64le as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-csi-rhel9@sha256:8aea473db53d25d3f3a71f509e5700e3b818d811d5b9e8a16317e2bbedc96785_s390x as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:16c1e6d558e7bc95b3fe0a3ec404ba2a84c70b964d64f2da7c695a81f31b5c99_amd64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:18ccbc9f2c17fc4a6df7b09e85eb1e2646b59eaaa2d22a827ab7b5c2c50f68fb_ppc64le as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:5c564c465b6624e89408258be80b4fae866d790209e69fe6b9fa2193737ef85c_s390x as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:7dac1afe85b52f615664ef29e970f54084cec25f3e5f701b1e1f19bd6d5ac9e1_arm64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:21f551d34d7349d8a3bc823f17204d9a52ebd93cd9a4dd95a998b80d8947fc0b_ppc64le as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:3840398ac8c3a502c07c6b06bc0fb164c8a20247573283c1c254d01a31296efe_arm64 as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:97bfdd89e24733dbac4f4493e1ba40160263ef9deec22730658dea2a1eb315bf_s390x as a component of OpenShift API for Data Protection 1.3
- registry.redhat.io/oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:c7d4339e1273e615d603d55551dce10ab62573220709570344f2b453a32f1a3c_amd64 as a component of OpenShift API for Data Protection 1.3
- +12 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:3444
- externalhttps://access.redhat.com/security/cve/CVE-2025-66418
- externalhttps://access.redhat.com/security/cve/CVE-2025-66471
- externalhttps://access.redhat.com/security/cve/CVE-2026-21441
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/backup_and_restore/oadp-application-backup-and-restore
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3444.json