RHSA-2026:40768HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.22.6 bug fix and security update

Published
July 21, 2026
Last Modified
September 6, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-40895 — follow-redirects: follow-redirects: Information disclosure via cross-domain redirects CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:31844e94e93779038fc15de800a511b0de2ab7b37ccf21f6dd187e80f4501af8_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:b7d4b38194aa8e67bd06c64e89e0534b0f651a23dacaa2b8cd39cdefc0d9b518_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:d0c6d9e69fabe59addb5a369aeb34fafe725a2cd199ecaa94ba032aadc77d4e8_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:e226f0ccf48adcfc3e01f38c226eed2544f4614d3dc29897a73ebe6b71f52e2c_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:0fe8f62e6a7246f5f89972495c09a91dbcd81f710c290cbe38893c10ec8af956_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:b42603f98af94dc3cc758a0371bb51243e3d7142bc3f1da5c05884f4b34f3bee_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:c0c9daaf430bf6d6b2e6549266d6598be0c3dbb5510e11450c020f7bed21b874_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:c1e8f4ff9307585d5d9101ce4f579e50d10f0d23af2f290f7aa0e1bccc557f11_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:55f1b14c90f8189e8f36b67553a78a7dbaf209f39f4b6da69332cc48958521d9_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:9f5746c06ec5609f9c229823bef661698e3bfe4dccbe5fdee24d3d7ee2f163b7_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:af5f369cd2ad32d86cfaf55dba23fdbaa86fa193d8a34b9c3f5e85085c667413_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:b5eab80d2caf8036d4f1775017bfca2dd1123284f791a1a696e6c762739a9867_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:0ba8b4afff11dbfb4783621d26d89af2712ea8a46a8c8193478917c26a26a3cc_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:1958f4bebea7bf45f0d59f224d5a1bd0e997217ca2efb88aa9245ef91787bd0d_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:7b108dfa511b2e61c4c5b0e1df84e4b8a815111dacef0f73138ddaedbf755ed8_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:ba8f65ed1f309a09d028c3dd709bf3dd4568e2ae71c6162907d691f82617a28e_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:4d786dcfab39602c3f4379b6c211b61ba3cab4effb6e3b28b8f19c849f7bd33f_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d2cd9e8302f47c448e5f11fd043d2bd07b40c2b8486df4c5bc9ceb2465ce8bac_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d67e350b464a4e563ee8b49950ffff6cf842bfd4dc2cb0f64d61b8cf513944d7_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:ea91a9da09e90d65069633833d2ea94ed76076df2dd29554c3c36a2b4123c125_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:012efdcd94e9c5638aa6db2b52307b82bb01fe2971aac97977b5c2c79838a53a_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:4bff2a75caa46763a6b62b5117f308d271aa471f07dcafa12867bd98dbad3564_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:c7ff939c5a484a2f4a8d9d762e443179d1185a1c05e0228ca999e5a15ce8a24f_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:c9664d50a4588502e56d86bcf4ff81515a6b3420012cb5131221494350c4ed1a_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:24c883eb4f5ed6e5bc40935aac63c194c540e0b7b1b4234563ffc5b54fd0197b_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:8aa120238f132f787cd4ad36d69e17e3a0510c6e530726d4634f0f1cb4a3ce62_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:d913a89c4b38b7b8d77e6076117647d043074b84e95285f078d915968521a48d_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f00d0a5fa84f70f91391c0dd105c2389544821074534d6e86fb541b840431c46_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:298aa3d145b288d519971a324d36910b0ed9ab68bc701f76e4cb51697be0b676_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.22 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:4b439fabd9a53e37a7fa436e349837283d04513bc8209e643171d1b86d31b845 (For s390x architecture) The image digest is sha256:c5de4bf75d24ce7ad29ef1c340bcf162c5a7342cfe02792d4a957f5c78aed00e (For ppc64le architecture) The image digest is sha256:9c842e45cc643645313d721ba669dba4c66a97db63482dfee14e224de5e140d2 (For aarch64 architecture) The image digest is sha256:60f35f63c8d87642bae7d49ff9b8953d429aa6bba7e510dcde317ddf48f30edd All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (9)