RHSA-2026:36611HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.14.69 bug fix and security update

Published
July 16, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:22f8312d0326420b31e6648524398e885865d27506a61ea59b56823452761d27_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:40b229b4bc159a94b44155b04e2d30cdea1ad9ec120df62494ade9ebd57bc42e_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:a547c6437a2bdb2bf1108eaaa5d8e7c0867042abc9b7edaaeccfe649d4968006_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:ac8067b6e3d1bc11a992ca8db89ffa3cf39a4631e46dc111b8d93149d201cfbe_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:3e603c8282a0a1c3b4fb6ba49e1f649b7e065fec41168d65454963973d095af8_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:43e484c1eb8b7322b6458a9de4411890c12aabdd30df2359998e12166b247e5d_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:81c8c712ad91dd8fcf5cae7802efff8ab53ced3944122ac155e05e2e4c5c9aae_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:8e1813a151507a040d8060af99787672309b20c22fdeed0e85f375694e41b319_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:2b6eee44d9336bc6c49c6207f6a480bdcdea10fa65a32a1d9156ce8a5e2dbd19_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:9877907e1e7dfdd9e192b5fbbc9a873f32daf93625051ee53f1e430244c95f84_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:eb17f25b63400037f3b6c426fdefe32fac8682d9bce828a2c9b10ab9045ef6a5_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:fa8dccb173cb15508cdf3711c5fc5db61f1bbc4b1fb53feabb76d1649e88da3f_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:4ccf002ef7c1e619e151e9b52579e074c2a8b6d63f90f4f127a041c1a9704bb6_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:94acf610552f9a5eee8f96af1578d2a71013c4a6695745ab8f4a3a9191ed74c9_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:cc15555c3f59013e309201cdc525ea45b744ea7b3d10d558d05991331277a7c6_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:ec1c38c3d9b63af91b263f222b9c8cfb556f0f1484991b27f3f988b4a21dab30_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:0c7d5f95100614cbfee1cba053d565f77e96ea82c54deec2b556daa71bb30b7b_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:40215347d8f9a3c4aa040ea5f080944ca3d8946086edaa72999e1cd8095e0016_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:a9fc3e8925ba85f2f757121a2e0110a34ee037968ff672c2725a475e806b79a3_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:bfce6e6c0099bd19efd6c6ee4eb7c78dbf571ec5f9e1e85d07e2b5f0d140e0d4_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:5930e0d9e89f56f9c4da135a4232a79618d056e34f627aa9f55edebd5c0a1f4c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:66789b1c7d1dc0325adf5f1ff71235f37c7810db11fe22c989ebc83528019fb6_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:caa81cf35a1ab4616d48c5b720b863fe0db3a023b8921a74336f938b9926fd48_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:e908e17619dfadb4b4a3600b1f60272a30e9fdba5120f3af8bc9eb3bdb49ca1a_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:176f4be4121fece8432ec1006368d83783bfdad25b2bfaba5f095a49898a64c9_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:b210e66be6ecd518aa4a7a63c731b2306812c66f2e164670973f5a1e1a92d111_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:c0f430d1e364c236f8c911f57a9d66480fc82995d20c27ae9322468c6946f731_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:f2573b291f66f7ff559a9d8c65237cdb2e6f0a20c3d4e1de22f2a359cacec384_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:28bb42a69feeb703a2ed43a8521391d8ccd820b359f738a52e42e8ade809eb88_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:7e25cbd4bc54aad147c040958ab4cda5d403ff5f4e6b0625625c7bfef91c89c5 (For s390x architecture) The image digest is sha256:6d3480e51422e450d54dc26db86ec6fc5724411286a9b510fcf7503ea5d04883 (For ppc64le architecture) The image digest is sha256:535f5608dafe33eaf0c49cc51ab3a798d9d54593a6dd13a5a0b04846fe28c3f8 (For aarch64 architecture) The image digest is sha256:8202bb741e00ed74e1ec516c9fc549fb4dfdf76bdd4c7a67df15c3333ebe025e All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (11)