RHSA-2026:3870HighCVSS 8.2

Red Hat Security Advisory: OpenShift Container Platform 4.12.86 bug fix and security update

Published
March 12, 2026
Last Modified
September 2, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-58068 — python-eventlet: Eventlet HTTP request smuggling CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload

🎯 Affected products191

  • Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:03b4902359e5dd1bc2524b213d42b3c1c2e3e0f63380a17142705ba0b8397529_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/driver-toolkit-rhel8@sha256:0adb3f01f921885b64b9ee98648b1252c0ee4f46c3f65ff53633924d72f5694a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:f5ae1ca7faa4f3bbb86f3c32ad12928c4905c85a3cfaebda3d80c603b3df995a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:a40488813e76053f7e3bc398a6655b6dcecc7d8e641b8c9a84c4fc7a8babeeb9_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:a8f987adb667cdfe893a8fb16c46d04f64ae704ebd6f939ad86e5fac4e87d1d0_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:9227ff3d828a294d7076bc5ccaf2b316bb1b60620e4a549c1b9778e692aef760_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:5a9f74b5c3dc5f2a040ae50fa85cad4269d3ef5dd93c57ce97ac1640526ef083_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:8b973769b317e1ca3ec4df7ac8bde2fd3898649a73bf16c6d436d5dbbcf7d1b5_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-agent-installer-csr-approver-rhel8@sha256:3f162460712daaf28214bba38129c4cec5894aa8f0dd4e133de33797801abb6a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel8@sha256:222d3e7cd6cde1dd90c007fdcd9ee1eb0d73e4d9a0972e01d68b1e23f6643d6a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-agent-installer-orchestrator-rhel8@sha256:94450b3c7a1318f9aeac92d28721ff3b9b0e032a9aa85726d8b02c54ea424f05_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:103394f2799040d165d26e83a4d011940a27a311221cf53388025da8cfe2bb3b_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:9f12e9a06be28ae59e58ea78263ad17e3c729418a77b09e232524e46fb98aa90_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:d80e9ac78a64607ea74ba4d5ecbe521c1f919c98ba7c42f3c2ec1c821576430d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-alibaba-machine-controllers-rhel8@sha256:7fd5087403be83fca087e1ec911beef62ed77461d65ad26f4680e50dbd719cb3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-apiserver-network-proxy-rhel8@sha256:2e7c9331c70fa6692e0f0ca398caf71060007b0243da63cfd549159874fd7dda_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:18bf1ed1f3b68d8676b3e1b33cd1922ca633e530a769030287c6094310890e44_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:b5967b8947d53c71c2d6d86a31c1d2b192688504c090b27cf92c330affdbb9b5_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:3da852fa79dfd7986e841fbfdaac11b058d722477229a8a3e446acc03d2855bd_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:2555cdbd7369c083baf6cdf13c51b567308b68492eaded300fec1a7ec2162520_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:3ca873b2249269813d75f2fc77ce7136dbc0bcb91ab5ea7fddb5289f87430ff3_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:5f0235ee6907bb4cbbea1f5a0f6799a2316f53dca50dfd47bcb06553779d90ee_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-azure-cloud-node-manager-rhel8@sha256:27791e130a789c4d7b82bc485b656f898efade15008428923d7bfff7412220ba_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-azure-cluster-api-controllers-rhel8@sha256:4215367141864d8246cd30210801d5eef359c01710205917d366b0969aa39aad_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:8e6843d665d705d385b691659de9ceddb5a5c632a2b8ddbb54ec53a8aae7b5e7_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8@sha256:57114c78085fb614e49877646ea3d32b8ca9a11f55758720cfbf5b237bda33b6_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:aad175767a53e40687563666fbfd4b0ade6740b0a9106dd9072338b4ef6a967e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-azure-file-csi-driver-rhel8@sha256:551ea5cd1d61aa167aeebe2a664c584e1e604ccf044f95d4ccbd7581a37a28a8_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • registry.redhat.io/openshift4/ose-baremetal-installer-rhel8@sha256:352e9b8374953a6d83b0bc7f47feeb949d36c4d19d5d4487e4e9e0935db060de_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • +161 more not shown

✅ Remediation

For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/release_notes You may download the oc tool and use it to inspect release image metadata for x86_64 architecture. The image digest may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha value for the release is as follows: (For x86_64 architecture) The image digest is sha256:07275faf221c556cca2a816cb48a87bdc25a44ff41f91bb88a232c15bc09165e All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html-single/updating_clusters/index#updating-cluster-within-minor. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.

🔗 References (6)