RHSA-2026:40795HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.20.30 bug fix and security update

Published
July 21, 2026
Last Modified
September 15, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:7e8e8d19e8b57bedaef1c02d8e982af7ef726e4288ec479a3d0f3d2698e90460_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:9abd74112deb58b2c4ae5c24099b9a1bb055545dc892bce8c99b1a4411d5a178_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:ed89f2210ecc4bf6f94def6bc2cf32d6ca69a641ce77f56b2eae13efefe134a7_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:f615131fccb1d8503eb721142278dbe358e0a69d506e9a2815d7972a021d7756_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:0f30ab801d73d5723118c1f4f55a059acf04e4531eb84c47529d54bdcb2a7acb_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:219ac15fe29ff88448d3ad25061d6505a0b6c23bc20fd27a4bfb492cb0694cc7_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:8b09a21d9f8d5ea754b1cb16c2fcbc464198083b1da8514c83a0670f532e06e4_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:b10c9c8d22c40270b43dbd3e19aa63e889e8e38a402c9f9a46ecb363fe36a754_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:18c8c601ed761f7d8fa9b29e3cf5ac99c8022d4172afb06a5b4ecc647ee01e79_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:36f098ba763b252b1d6240f724a3e335073d9843d0333bfa8f0b88631b3ed243_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:3fb0d9874c8c1942ccbeefc101e7eea44c9396203156bfa029de21e70d48c49b_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:717966dfa784d70151a09f518446130d63369967d62013c8aeaf255b07bc8182_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:3715b3530f053fc10320948bafedb0fff6ba70d49f3667e00b622cb3a0cf64e7_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:8a8b3d0de6efb5aaeb11375f3b97fe13b3648d674a14adb395232f69a6149886_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:a00a0ff551ac34a83f83a81c8fb99d2f8eb7b5f7a6c61f92fb8432ec1b41202a_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:efd9a9a557c8f7f508019f5e59a4da105144a4609767c35f96a02824eca8f137_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0a25d2e012ebe76bd9fe881fcbc99554b5a560fccf38b08b91f4b0616de2eb1d_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:37ccb0bdc0cbbbbc7a0efdee6c577f4b1a85859d7d228b51792ba9f8d60bd1ea_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:d3dcca688f2294b6c25499a6af98ee747e0adb784a7ebc35a014c73c3dd2cc12_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:da113605e718393d8a9e4b3a618c49341384232900fc92baf7cd74abee644ddf_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:01300bda700bf096200a6f9e0e691427ea9f059eb4ddee1c8cf6e9d6faf2bd5e_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:8d717358c31be4806178db565eae342dee307564f7a40d1359272345be0608fe_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:c24e6c5960127a8e6bd878d85f1afe9e0836c598770a97714e8ff5ce6895aa7b_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:c6c0f155cf8f941dfe2e63165178e370b2064f4831f5ce1eb81c7feb85281406_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:072a6fdcf7eed60f060e676ae325a3f94bd221e39d13ce12f2076c1f314da312_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:3e21276e838c10ffc103bd39242836a5545c42a36f01828fdaf3f66a60b91292_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c086b1b44cba740430705687cedf7ce721aa6e581985b0d20dc526749c036132_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c9a1e4ca1a1e7accc9f722618973f7ee8efdd6328f42a508e0f3b3631ecc606f_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:24abf5fcb3edcee6caa615fafd17f099b2005f7245adf876398c2123fed83046_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.20 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:5f3b32c81ef796c747320852073558aa36f65679cfb8b1f1e7ae64de5b5919a7 (For s390x architecture) The image digest is sha256:45c24c3a45b6931bc931d732b5e508c57056b33beaffc17255c94caf90fbcf6b (For ppc64le architecture) The image digest is sha256:72498c7c929f798c6e63a9e2816c1ca0ad8ff0ab2e3934b3948b9c994ab1836c (For aarch64 architecture) The image digest is sha256:7237a9b71c2b66694dc7d976f97b4f65abbf26900358604ebda8207726b1eff3 All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (9)