RHSA-2026:34795HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.22.4 security and extras update

Published
July 7, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

🎯 Affected products195

  • Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:517456d2c3278e2840747228088bbf20cb59d577403f7b266813c0fca1c9d0b5_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:69a069ef7a28a096488a425eac01b94816d6dd858269cb50dbd45a53c707a295_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:7425173749a3951a300b297337ea05b6cdf2d90ec6be4976e62f49ed9c5dc534_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:9ad9b62bce5c18aebc3f3c0aad4398d7f1829da07a8ab135be5014b95b3cd43e_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:11cc7c887300594bfd7c7cb207dff043c0333435d05a7cc3f0bbb3940fddfa8c_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:319c61f43bd6cfc0524b57e71898328448cbd0d2a4312d9034876379b3dda628_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:458df07f305aa6fc2b5d9acb891d0ad925bcdb299e844b9a58d7c5c729282baf_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:fe1075f79909c38b4357f713ee7919c7f743ce730a4aa18b9520d8acd0562573_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:06940e1da39cd12b0992b17df078a26021ce375be7ee30ac5376669dc368d438_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:9413d1a73ec14542e26a73bccdd7915ce9aae7d518411ab5b9ad644f5a6936f9_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:b6728fd23f9daa9acd4a9e27f2afc93928a1f6f1e047939365da74d05b0571b0_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:e5de99f158b3c1c41d806f176dc481a7c785b3430deaf24485249107ed3c07e6_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:4c1373195a8ad83f4bab50797a6a104e7de70c25987dbfcd176a3d5cf19e4e9b_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:82bfc9cd088b2c071b573e74a8b06c834f84d4e6790be3dd18efe38b6bf76c6e_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:c5313fbda8837d44b85e00bdb815b239ac07f509fa3632d00689f3a2842bc734_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:f726b1c7be6041671eb5b81d61002eaadd8b2c182a968332403d4fbe4d7561e4_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:351fa7233f9d2813450f406fb5b319a198b96f02688a1d35c536aaa7eb4058c7_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:a79aa5134775ae5d8ea2b715dd845d928c43e32ee121feaefd7041dc9b5b6a10_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:b901f71f5b2caacc73846b8585e902e0e303e8ac7e8b3f1ce93f1c008e8ec67e_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:c9e720a224163fcaeaaa0b009be0311656ad681f2facae376659e50e8b8a4144_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:454b5439d46563feb9e5a0c5a10cae4dadf52e4cbf5d97366fd40235356083b4_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:49c8bd2a1f8d54412f8d0349d4cf41b1cf62bc9fc8156bd2c4b4e2fc13fdbe94_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:56c4cd102242917acee6f6233ecdda89541dcc16161da6089f3b5f1ca0cb1b80_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:e0be5702126ca8452662f5a287b2f34a55cbb4581649e0c46d1ec38bdf7a9771_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:1acbf8649ab118f645c8978550625080edd6f68166be851014fb7b06832f477c_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:934fb2c1d862dad0ff33fda4d49ab712dff27b599871195cf04ecb5452954460_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:c7229ef630ad13bdacb59570c9b0b0cad4b1bb21e9270b63788340b7bf05e2bc_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:eef60734928c2fee5b778de5dba9979c6452fbf5bca200aa2653bd9b80b6fd44_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:4d8e6b1d9c57ad13fb553078b4cea739e947e58f1cc5d667e9c91fe419c7ae40_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • +165 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (4)