RHSA-2026:40828HighCVSS 7.4

Red Hat Security Advisory: OpenShift Container Platform 4.18.49 bug fix and security update

Published
July 22, 2026
Last Modified
August 18, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-46579 — openshift/router: openshift/router: mTLS client certificate spoofing via unstripped X-SSL-Client headers on HTTP frontend

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:320aac95279c4ce13500ae8fa990f6a6344b416b564b91d33a160264fa2f45a7_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:c483f5f17085db424f7506d66bc537cd50b5e78c573cd02eed9e8d02830df639_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d9f4b1eb8ac6b4131b52a0828ea820e40971a4353549c9a8df6247a260a435ef_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:df6c60635e7283d9fb488f2d71b0f0b8eb7262523436748b9118a45854d4493c_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:0f5390606edca75bb1380d94dda725858b04ddfc3c135db8758503366079c093_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:73147e8d44cac76cc1640c3598541889c03156a0300427514b407784c29a83a7_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:ae3459ca299c751c66ce7ec04c0ac8e558f3619e520e4e1728c84a49f80464de_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:ef8468402b836cb12bd114c1621601387013a2b73696fbbd11fdb9c4cc3b6ca5_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:838846236e70d91c176163095545d215cf74a343a7acaf7a4f857839b4359cc7_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:9cda62e9cb03cc2734b045c87a2ed26bbdeae91425631faedb96051d9dc4f43e_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d8ee607e772e7352d9349f10a56193ff20cc089297dda792fdb6fead08df8aa1_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:f1ffe871bde3698a30276f0a510b8aeab23e2f6fcb04650819755f52b9cd618f_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:150b7812688460f3c5b0928ef50d210edc4309b873c9e6945a5930a79676ff8a_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:2b76cbe1a816ef1d4ea4b1a38e513f6a8756ceb18d03cd61636cd6bd43ded0e4_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:73d3b61a3c442e78ee153f273ca29ba04d975dd82493b1b3a42e1499837b7fbc_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:914ef618f8c59a39df9b732294461d047e50fab7b0e937b45505c5e269376022_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:26d7394e93d28dffc0b2aa0fb727b53dd05691cf8d37e50bba13f219c9cd3330_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:6f0d2e752a7f865e251acbdc1f986251b003d07a9ca0a5cf0dc59434d6182ce6_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:b11d00873b47b21096e242cb990923694b446d8c07a44aadf48ee33c6309bd56_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:b826bf038cb763e9163f6356a79718d05118c9aa07f86ba455d186062587a9d9_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:0d9bf002ac90d02718f12bc388991969f6620d0ecef6d754dee0ee4dd2d401a0_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:263f1af55504658b98e840215225b692d616c27e019cb0f5fd4cfbc7aa676ce9_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:9002306e5fc1709b28b80ae7c6376668189decf1adfaa5a540ea86ee942fb270_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f369fe9149926c9da51d9b124c66c5faec6a49e19b0d9ceae9698510acccc778_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:278c8b50a15c129361faaf70693f52a6e3ed2bc4777dfbb4eed6b5d609db23c7_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:83b4f83f5f178ca13d81994d1bac091fb71aaaab7ea0a5c7197249e4c39ca82f_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:bb47c0aad1b8f7a94b259eb5925c64238ec87ca7d7e4f1725ea0383aa5a16558_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:c90208709975ceceb80a3698411694de95ece475b2e98b254e60733470b0f908_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/frr-rhel9@sha256:0a2a7c3d09ec7291080152984145d46a5d8c71b7512d11a7808d308e041ec9aa_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:33b613b2301d908441b6888d4080665504b3d19d386e88175a2c3a2553fec698 (For s390x architecture) The image digest is sha256:6042af1b49f701a96f06846ffd675331f1766ad2a802eee30e36642e05278d07 (For ppc64le architecture) The image digest is sha256:c45a0216fb83f3f145967ac66978331719ea34c88810c7a74c95403d3dadc360 (For aarch64 architecture) The image digest is sha256:7eaa9fcc8c91fe1b812b00202619aabb99a4aafcef0dfdd0923ea8bc5cf21799 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (5)