Red Hat Security Advisory: OpenShift Container Platform 4.13.69 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-46579 — openshift/router: openshift/router: mTLS client certificate spoofing via unstripped X-SSL-Client headers on HTTP frontend
🎯 Affected products192
- Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:585de77f1575d7bb1fb9cf193af50164455ea8da0bd715125605dd8e0d32a69e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:de51be7f25ffc86de2b34d649da0181707adcccf78c8d6df2a398f1e815d6f8d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:6210806313fb7c58ddc95f71b0cb4b215b122a789b11da3881e8b2f3170e2968_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:a7aff4247497a048e1f8e19d4d1fe6f19d40176f5a1c924afe074a8ef939625d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:1db361ae442b027c715c52aec5ba2f60563966f0e1e257b6d7a146e2f9f480fd_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:45ad23d3d81204bc0b4fb7ef3b6a1cc20bf3ad9da9db6dc8491beedc85a83048_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:f9cd57c2fa8f60ede8ddbb95439518c9f10f6f87268d198dd0058072144cdba8_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:d1d46dee0e780f2af370b75316954767cf3b425d6666b1bc532dc680ac3ce6d7_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-agent-installer-csr-approver-rhel8@sha256:06bc7edcf461edca1de360347448547195e962e933de20f60c4fa210cbac3a0f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel8@sha256:b34923f988f97b863d014a9f08c31f81bc28ebf8d3b71a716c4ee081494e3a0e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-agent-installer-orchestrator-rhel8@sha256:71fd65e4824084f0f04be5bdad4b855ddeba14ac86a09dff42a4087f23b31c6d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:57a15d7de519791f7eeeb55ebd12234e858e1c897a2719c618badcb68a6702c1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:b53de2a09cf29cb118300dc24df4881070207a327f5fffd871cd6eca3f0b1cb7_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:c5f6736fc5713ebb0f46ed6be06641a501855a28edf0ddf878a9b40abe545325_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-alibaba-machine-controllers-rhel8@sha256:82d8194c7dbbc64fa0bb48d9ad28fb92f416f59a6d62d9b3f8e85c8cd1a3a7d0_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-apiserver-network-proxy-rhel8@sha256:b361332ed0b89c5a6157b2c144a8b3e9864fe16dba81a6f80ac17da0cd49fe9a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:1ff808ce5554a32a4af35098a0ec82f2013ea28b3c764c33cf301ac68e8b2c0f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:25dfc7fd2ebb6dbf30ef6fba790812608f208c650258e60ac3e93eb5414e86b1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:c0a943015f5ad800bccea2ee69711c24cbeea67626fdf80a3c83e8ec092f0676_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:e7b377f06b14905ef08096f9d489c0484360b2f16b56ed0a213e9b3ce5ffe199_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:7016147fd939a9e4b6ea53a7a8d9531811c1de53c5ca390ef3973d0baa161c10_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:4d03ac9d6918ce1da8686f462f4e1f46ed2c62ebde638b7dc2b9f935555483c7_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-cloud-node-manager-rhel8@sha256:6c7376dac70e6651e0a1d71168d924b130ab9b4c445d90e5afa46824373abbb9_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-cluster-api-controllers-rhel8@sha256:25ac623d8717e1c9f38cb7114c53f55d8d7df8a5b1b480a56d0b73ffe0c2d7e5_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:cdaffbe2b3b509c49753bfeeecdc161ea35bc3179378a995420ae8b2bd14a52f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8@sha256:cf8dd2dc353fadea7191a0a5e5444512f5f93c27d2c9631fb14bc45f792c1333_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:d3a33b1176cc48c75d18d29bce3c150944d81d844bbc965d68d6166dd490e0f1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-azure-file-csi-driver-rhel8@sha256:58856ed879649730c9bf10ab5ebfa2a6b281f6b91554cc8466acb76f7ea678cc_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- registry.redhat.io/openshift4/ose-baremetal-installer-rhel8@sha256:2fc6681e1428d4884b3016bde5139ccea8a1f82a74cb7bb5e4c9cc8341a9c063_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- +162 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes You may download the oc tool and use it to inspect release image metadata for x86_64 architecture. The image digest may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha value for the release is as follows: (For x86_64 architecture) The image digest is sha256:6ff433fc5d4e0a3e7a0496e41af47da5c9349afeaad949e6d3bb49764618e1b9 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html-single/updating_clusters/index#updating-cluster-within-minor. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:40022
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/cve/CVE-2026-46579
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_40022.json