RHSA-2026:40792HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.21.25 bug fix and security update

Published
July 21, 2026
Last Modified
September 15, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:1ac33b95e55c37c82836ec8446004358a2083ad0ea2cb07957c60ccdc1917057_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:4fbaf8ce0fff4b959b6a89931f2a4f37a3d1496c6c91048c866be849f6d423b2_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:9ba6294b6d51c9bb1f47f50dacab729576f300231380a57ab7fb840389686bd7_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:cf210ed9fc3ea0cd1c96d2a262f13f9152e0b6defc69e005f3a8b6313077dfaf_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:00b13d55956ba035d05baae5743e9a74d539009425a97a273ea301a2429fff15_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:5faad121e3da1d483a2b3c02c816f1c052edef7f0f0d2cc5fa9750caed3bfbd3_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:6e99d928c3db44de3006c291c9cd36f2f9a9f4e13f107f2108ff52f9673143b9_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:eaad6b451f2ca90fa9ddf52a0bb1916aa5a06221db19ff0ddd0ef115630401ed_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:12c4a785d890bac8a74bfe3ebadf1ef585b9a823032e3e4bc36056565ddd3161_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:2fc61287ba58cc0596d56eb2330a62d4951300f5f1a382b67e2eabe8f3e10e82_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:51bd4754438c5794b0cad26418c5a84dd0fe84ed396bf8202c2434885219c996_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:858ca9b977fe190ef0f88a2ec6bdcae07e64ddd22befa605bba25047d90fb205_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:32fabc27bf256b48adbdb749479a3e8c0eeb7d4c27c087673921156b83e20075_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:7e7982b9923c443ed51cab35ee94e9092d816d2984cb8f0c78414ea61d39f798_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:9dde352b3454de94eb09a920a2674cc44cf1e54a0de4d7864bcfd13562d6c56f_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:ece25afdd49857ba29af55d4e3a56e310c1b881665787395b2a65c7911d3d8d5_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:11408fab81ae1e190e6b6f55ee0b23f8753c45dd81e65c68f4712efe6a3b0eef_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:1162cfc1da3b460332537332b8b7a266fc80d5287b9b1eb96336b99a69be6527_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:9540614ce50db10b60129f12344f2b02367025b36fe85a2d5b27263c262725bb_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:c51684bc8ede1411d9f944b410764cc6774e87785b6c1bc1de20af27c281e5f0_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:211b57a14e610e576b7ca3ae97c800f2c5be3a1a73a5ac758617815436f473cc_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:28516d10caf4c8b7b18abb5cd40bdf0f0f308e14415582b07dff72d83a52fb10_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:3c3c5a8b218a29e78aa81cacbad7f8617706c82233368696fc30460626fa2d9d_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:fd97e2d304a32e4bdf2ce4ddf0f6c4e2aac9ebb1a3e4f925c99ae6436c6da936_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:215ed3ccf97cb901f1a0a1ec3eb4d24d97928f1d6e80153c679dfb840ee5da3a_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:74c5db6d51075a36847adb4525efcece6f18a425c8485faf96ce80611b9c931d_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d2b080d9aaf715e0166bb2fe2d8b1fd51e8625022d969567664d04a6af8b067d_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d8b11121f73c1e845baf5c76b9b248951fa22ba3ad76a276d9fb2062982d084c_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:05b68c938e4a81e50986c2a789f6204a5134c30fdcf9d63455b47f29c0a32a9a_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:116cabb556737a4a36e17f1761c718e70bccd66c10d722f9b0a678074061735b (For s390x architecture) The image digest is sha256:104953e69b5d7be2ce775701775d21843404f4b649d9825ab4794098003146d8 (For ppc64le architecture) The image digest is sha256:a1b23175ec864db1abc82ff8417f1abca9d60378e0f31066c1875b41755d83d8 (For aarch64 architecture) The image digest is sha256:d83a9065f6052d50bd4fd9979db76f3bed822bcf0b53954f07018e3fe443b409 All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (10)