RHSA-2026:40984HighCVSS 9.1

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.20.15 security, enhancement & bug fix update

Published
July 16, 2026
Last Modified
August 30, 2026

🔗 CVE IDs covered (22)

📋 Description

CVE-2025-12816 — node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-15284 — qs: qs: Denial of Service via improper input validation in array parsing CVE-2025-66031 — node-forge: node-forge ASN.1 Unbounded Recursion CVE-2025-68157 — webpack: webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects CVE-2025-68458 — webpack: webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior CVE-2025-69873 — ajv: ReDoS via $data reference CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects CVE-2026-25128 — fast-xml-parser: fast-xml-parser has RangeError DoS Numeric Entities Bug CVE-2026-25896 — fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling CVE-2026-26278 — fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion CVE-2026-26996 — minimatch: minimatch: Denial of Service via specially crafted glob patterns CVE-2026-27904 — minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions CVE-2026-27942 — fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33036 — fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33815 — github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability CVE-2026-33816 — github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-48779 — ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments

🎯 Affected products103

  • Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/cephcsi-operator-bundle@sha256:522d40e50ef3d69227addc4eb2d21110da67a71ab38a392a6a73de196e291ea5_amd64 as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:330cae7d058b96317b8491b53d5dae3fb6375a47b5744b30c9df116b029aa664_amd64 as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:668dfe581c71024f3df2be60109cdb325190d7cd4d861e5fc3dfb6bd01dad986_ppc64le as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:811fb7e18f3ad662751bd217764ccbd3f551ad64eee318d6c56391f94d5fecf6_arm64 as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:d2ef0fbc8fdbc8053b55cd9945985e30cdba8f3d1db56d67b0b2fa0b1af12d27_s390x as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:7d0ee8cf249dafabae40686c0a388721d9e57d704402a86551d247c8d8879f77_arm64 as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:940cd4bc97f6ef3620baa0ebca7beee947c34be9355beabd68a32df3bb951087_ppc64le as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:d1d9ee046d756cb57e3a56589ee4682b2c14a1419ee8f3a7a6c287244caf8b2c_s390x as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:ffd512657b2587866bdd42012599027977206f8a1a11ea1119c1349e646d2ddf_amd64 as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:166209cf6aba8304d21e726b01e8daa23ba9c55d101965af7361028502202d12_amd64 as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:6e43cd07cd09a8ffbc0d93d231d700f13fdef16214d37c7a08e61ebb0705f894_s390x as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:b61fbea3a0cd949c2cfe81ede0ef258cc5b9e40be586c5b9c8683661e3fd4cbf_ppc64le as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:ca371cc6a86d0f550ed81f50617dec89a96d6f937df6e3aef5b901065577f05e_arm64 as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/mcg-operator-bundle@sha256:e4a75de357d5dbea6ec922e69d6655c6ce4bc7ed8d5109c867004b6b7d80b326_amd64 as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:0c1b66f5de4228ed4126a9539f0396d2cc66969ef681f627028216014dfaad62_s390x as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:37088cfa9eb040c313aeda47ebf25cdd6da56e8a590a9138ca733058c0cd4f89_arm64 as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:5e69d78a4bd6d1a2dbef5a67dfb37a12a63b20d4eee8f0996053d69c6ed32783_amd64 as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:cf2ddab5cce4e1745af69d57cfe7a30ed7d679535fdaec820c3e7e42ee6b4f21_ppc64le as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:29f2259cdd8f0c1816c00132494f18b8bb35242e7a66be8939423d3736fb2eea_arm64 as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:5745226a94969b986e5506d7ad87c3fe1c1f19b6bdb9e2793d1481c0110abac7_s390x as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:8db8b9f10bca358b10656a71aa6daab9b393e298da7bba612248ce44f5e01058_ppc64le as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:e068dee56a84a243982c14067354234d7440283c2c77284ddc1cc47ac0e4d4dd_amd64 as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/ocs-client-operator-bundle@sha256:55f4e42887bb170300981c39073628c0fed7e396fcb149a7b57fe6e7254cea02_amd64 as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:2950615bac6bd9cf88f38e60d014edfb2e619aeff84b10e6f5756cdf74848deb_amd64 as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:628546741792632dd843a88eec8ef184166a4a11ca5b852fdc5211ea4c5ddcf0_arm64 as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:754f8f8710fdaa7d4235ae202ad84f351b554d8f208056b5f13248f330ea56e5_s390x as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:ad85aa77d1ef3243872eab3830ddd48d6d734b3db3a9eec84ba8488148e3e71d_ppc64le as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:55bf353d6b4c47fe8fb265cfdb7b5305901d1c5165e9ce19d1b90b0168802fac_s390x as a component of Red Hat Openshift Data Foundation 4.2
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:5d566c013690784aff986517cbe99c91724e9323b67f47144aa9ccf90750cc84_ppc64le as a component of Red Hat Openshift Data Foundation 4.2
  • +73 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.20/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, disable the $data feature if your application does not require it. If $data must be used, implement strict validation of the input fields that are referenced by the pattern keyword to ensure they contain only expected and safe characters. Workaround: To mitigate this vulnerability, configure applications using the `fast-xml-parser` XML builder to set the `preserveOrder` option to `false`. Alternatively, ensure that all XML input data is thoroughly validated before being passed to the builder to prevent the processing of malicious or malformed content. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (26)