RHSA-2026:34766HighCVSS 8.6

Red Hat Security Advisory: OpenShift Container Platform 4.19.37 bug fix and security update

Published
July 8, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:3b3d170cead92ad45ee3136ef90925a1f10e2b1ccebf5c5a66c9bf905f45aab3_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:644684f44a42a1dc4983c25ae2d391cb531992b9da57bddb6ec85b0e3612d46e_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:6e5abe6b4f03b763cc101044088600d8a036c242c1c25e4edb8d0f46f9f3dd99_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:e173974cb9faf0581bad577ce3cb5a45a084a857e5460afb01d3520a8da81aff_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:02745eb2133178d5adb8d815fef331f3b232aa5ab900ff385a80111c3165e395_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:273049b6459f797a0c12c093fb5aad00ea7aa0128f177f68cbbbdecf8cc714c8_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:5dcfa75d40f102ba5f48dfb86ea4921a11256e1f33762765a5f04bbbea672f73_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:f2ff087aebbb79433f7d3f69e0c3adfb35d540f74e88664ed8ba2a36478c6aaf_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:71f5c318572f799e40b8833b0774a8e2f575a4be7f1b5693527d65c40d1c277e_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:7604645ca825a9ba483a7ba904e19044b8ac421d2033ed7eaed58545be92f3d9_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:82dfbc5a1c8fb8dc045c56788f8a070a3065a3b52da8fdfd3297fc64db3b487a_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:f372b370e47254b20791d59c903e68d5274b79c8f612623a99325c15d3a1c76b_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:4e2ebcbb5c77e3cc3caa09db0228d224f6cf3433cae4073f376975e86281eb99_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:a43c7eccee8b08ba63e7601d7f0caa767ef024a0b82fef3f94dc0383280dd2b9_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:c06f030a667a16ab5d4e32b35b5f86de9544c0dfa45911f8a264dd54ac061f5b_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:f181eb31bf0d13d89544b4cb4821f716313bcb410e5fd619b35053ccd5fa09be_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:25dfa362f7add2f91a598e66fedfedbbc3ad023bbf6cf9ad8b54968a59fda0d4_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:89792b505076f3b66b2a10f586a1eb7a6e295be8be9fcc712f46391dd8f501ac_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:8f8b4e8d1d6b9cd83b1d4f4c97747bc1284b110ab09ab772a76a9747c13d00ad_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:d887db058c32a61190ca542db1eb5fab699570da7cce6b5d2c3191641145e033_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:2d75599216f0682f6c29fd5312ed131f4dc1eb1ce111eb6b35233dfa8700d573_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:96903a57c1fa43fcd03077d71fdb251bd76bcc89a40d38ad64a527df914f8140_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:b08f374f97e5d93eabcc0951231ff294df95457d5cf20b2143111b1980392b73_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:b9cba5a375dec863ceaac0bfe3d0f74e377ba4f1a78056e2011bd16b11259afe_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:0c5726b67a4fe463ec72f87963c2832370f7853dde31561932e295eea196050f_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:307304079a5ce0c31bc493a53d20f42dd6e7b89289d60517fb520848e38e73fd_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:36aaf4fdb5cca1e2a11686a860fce6ee84ea04322ffcc8a149e272977daca8ba_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ef977eb3a8e9cd01a5afe11cf2c732aa51ca8f13942495de9d1c27fe7337bfad_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:257f3b4240a4f82547ec674f2070b7742f584d97cfb7cf648f2e6394bcabab68_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:79dbf4584baf7b1dc523add340b02a22edd635c6c275a4f9124574a334b7310f (For s390x architecture) The image digest is sha256:187d99cc0aa359369ed2ab906f1bd80074a23789813adb0b077a13ae3d6e4ef3 (For ppc64le architecture) The image digest is sha256:0ff726e23ec140f6af03a2aaaeaa7ec10c98b115cc0cd7355f7442551bc038f2 (For aarch64 architecture) The image digest is sha256:a7b6e859ba988dc3e3c1679bd4710a1f2b0c3c62ccafdd6a66867fe264ad5bd5 All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (8)