RHSA-2026:37186HighCVSS 8.1

Red Hat Security Advisory: OpenShift Container Platform 4.21.24 bug fix and security update

Published
July 14, 2026
Last Modified
August 26, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-9595 — webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization CVE-2026-44293 — protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:64bbf029772a9a3450c687e49f47b8517fcf7d50fa41c16f83fc42a7a9d8c9ae_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:8e3c8c7bb14a94217d8f70f361ed5e2ba5a1573397583eef24476e2e9762736b_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:f58c51297c0c57a76e35caed815a18bfbefad5d47e7f0923ce9cacdd1abb4ff2_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:fc40a3246d3d7e738879a3b83d1fcd6225e291570565eb715aecb5bf2e95aa67_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:47d14be5b80382af6afe070d4742ada90f61672e19463135ae7b13d1483aad3d_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4aba6ebbe3231a1b100ae10361b535bf1b0dec2e08528825c3140dc8d9716c6b_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:8281943a8311bd6c038a720f1a0c75ec1a7da009d83213de33d1711cdcf0f687_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:9c1c3be2600444511c469ce2d586daa47bdb47710d09452c4367185b046cd381_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:67862980ba946dd6c13e243e2f62dddbd44c69140a76c0fde3539135aed59fc6_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:9bb821a970a8738a41b85f20f08060ad55f7cb86e382e33fd7528ccefd13f89c_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:b59eb85191bd5cd74e8703d44f714765e001426893b584da848956da385418fa_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:befe9e7e2916449a7de2bc94a16dfb9e4648a02e4629f27c14f0a0ace35a3b24_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:1933183994e9930959ea5121974ed0234290277bc70a7d047f3841a1b3729023_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:5d0234d583556716e5fe56b5c01b2233a7b710f4dfe631cf84f988c1537068e4_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:bd09b643c0185e15d68bc8580e9ecfc33c39c495a95bfbfcf4ec981ecd1df970_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:f1e4ef6da7d912946c7cc50615bda0b0bc17c6610c6ec83e083028ed1660360a_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:32c471f44e6befe1b94f57a0fe64b0c6d2e4d33ba866e9c6b2a701a883ee8001_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:7b1592d6603fb535c6db4293b58505acfdc70bf8dd64500b92264547d095813e_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:84065a8f755bcb4a1121664f5c76a78b6821b924f4842f803de486e06bc10952_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:eb4a864b16659775cbaf463c7f0e605ead41cf13ae658deb950cee8a13449e94_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:4d6b25d44c52e5c4281acea9bab0ed01c0aa66471ec78f4e277aceffd24f5446_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:62a3934c22cae0c1902aeb5d30de2a74f95fd03c66894e5f76079cc1f0a0f4d7_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:75ec0c45cd651717d256a5882c6646c9a1c9cd0c5f452543a7adce04673595e2_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:e557c2fec6d77c1efdcf9d647fc72b8c28c7f8c8e111b1ad0a8a9656fa7e2fef_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:71921d4f24144abaa7653d2c4f0ad4173c88c1cdd2e67f12185dc8642a11467d_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:8e67940a9e2515fce31e42185b1f8a7667804baa6edeafd13381d103f6f09261_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c0d56c9b088f63ee24dca491efbb6674445bee9230bdee77a770cddc57a56aeb_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d27102ae236d670e4683700302b5dd43bda2f6b01ff8ea51bad882a80893216e_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:61f8ca7171a003a41a29953162b629bb24baa39a440163cc00f7db8b16759bc7_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:9ed4f92ef5d48054797e08789b9a09ebeb9bfd9c6cb6ebba2876e4e81aa09c73 (For s390x architecture) The image digest is sha256:962b4ef5e92b07194c93e171ea848669455b6b1f406ea39920923f76baebf199 (For ppc64le architecture) The image digest is sha256:6e3c893541269ddc36f75c82e8f0a10d4c75d363319fa06fa8cf927f9ce0af74 (For aarch64 architecture) The image digest is sha256:c0f6e1264a7ee402a5403a9f024031ee9c5db95f996aa9997bf126e7608f682c All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, users should avoid configuring `webpack-dev-server` with a broad proxy context (e.g., `/`) when WebSocket forwarding (`ws: true`) is enabled. Instead, define specific paths for the proxy context. Alternatively, disable WebSocket forwarding by omitting `ws: true` from the proxy entry if WebSocket functionality is not required for the proxy target. This configuration change may require restarting the `webpack-dev-server` instance to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (8)