RHSA-2026:34794HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.22.4 bug fix and security update

Published
July 7, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-9595 — webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:3c208d6a34a4b0d2d55da38e75abc65e936f255c8e509119da76c58bfc822ff1_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:408fd88ff1f7ab6b00b4641eb3113191acf16db0f4db21b8c2060a9500b4d690_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:5fb8f4469f2fb8389a711c2639e3960025e6e71d4b3486446b48e34d4bcf54d1_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:a9d9331e8913efb668665d46cc7734bef6fff5f35254232a0140c0e4a0c9d5c3_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:972b17606424c57925f596d907412a2ba23cef704776aed2a15e4c7c178656b2_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:b89d07aeb815bf496a5b7b50135880f190f048ed1f2f7f0a69263ac206f33afd_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:c8bd0ad39dd6da983194a72d74a7cee2515f7fc1af52b75da9f289e4c21c0a72_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:dca38a8139b8c42daf39700b5ad3d1f37239021801d4f24018e33a6a90ceee91_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:4df8a765d22adde9b0eea5da16c8cc2d067f0f9956f8e342a090307968b3194d_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:59547c7fb9048299a7450389a0d8c99ade669ce929e960c9e0c2d2690b6cde55_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:797472f17af425c2b0107efb3e1d43d812318f67756a196b00e5f3b343c8cf06_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:ddf1e81967357460ce5af24e0d13ef6c1f89931ceb8e53963b08646f68d760ab_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:54cfa0274969848d8f650b842220b794de5c64be1fc56864568d04d20beecf28_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:7d5da34fde333e8d99fc42a77ccfd9511cbb140248f008b9a4276bd89c9a94cc_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:8c85f600b328496eb7599f432cfe2c838e35bf47a5931ad04d654f224ce2ccbf_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:c60fe8ef6bcad2d2f65c59195649fd98a228e71c955f7b138026a66d723c4559_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:16ab3b990bd2f1d051b6b31377f4bd188157c56fda25b109d676891b1a29812f_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:240975962bf4398b5bb2e4e9a7dd7e76e55be95fbefa59e46c6d9207d91a5f8a_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:3e5e1e33bb7e63a3c5aeeccb7eb90d296fa59ccd8d8f8c8dae16f921dee06bf7_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:9ab638226e1ec7bc33d3a562443a9f332110ae7c503d4258b7ee7c57161ae33a_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:4205d1d490a0afe62d8363060f64bde99f336db43833b9d60c0c2eea78945744_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:b4136ff4d7e48abdfa8bf8d089460d819828a705cb1a9fbf4ecb14e24776f5e7_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:be5c7ff6785115dffebc8cb322040c43ddfe72576f01c72b1f083766cfdd6ffc_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:cec43283baac43424b904e84fd3f48e3a1a94c51c5313b20a4028b4553ce4d50_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:168f6552ef2aa4a2ec11cf313e81a24894f06c5e8111f6fdd78ae0ccf05f415f_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:3c7c254fe44d7f4ff5beaa1b96e9675a3711d356fc4bc590d037a08ab20b93c6_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:5b87aca4bd11f13e7c18ecdbe08c9ebde024a0a052e1e0a7cb320e651444c110_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:977d4e13df65bf48a41a39523fcc5880262683f39807581fa535406e7611ccc3_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:15304928fe2d36f72f1506108015b1ddac03025fa0165c474572c935741216e0_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.22 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:a961faec0b28568cb4bf9850fee8079a2327a0c72ccf3b4258e3646e903f027b (For s390x architecture) The image digest is sha256:93337ba988276f08c61c57020d73b4bbee15556d261f01275c2484baf5854230 (For ppc64le architecture) The image digest is sha256:48d9d06a7ec98773fc8835f7a316bbc923232037d9f3eb572e6b00719ae5bce1 (For aarch64 architecture) The image digest is sha256:3a99cd80b75966456223f1090cf9e5afedb38212709f0c54ea0e122ae861c022 All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, users should avoid configuring `webpack-dev-server` with a broad proxy context (e.g., `/`) when WebSocket forwarding (`ws: true`) is enabled. Instead, define specific paths for the proxy context. Alternatively, disable WebSocket forwarding by omitting `ws: true` from the proxy entry if WebSocket functionality is not required for the proxy target. This configuration change may require restarting the `webpack-dev-server` instance to take effect. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect.

🔗 References (8)