RHSA-2026:41941HighCVSS 9.1

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18.25 security, enhancement & bug fix update

Published
July 20, 2026
Last Modified
September 11, 2026

🔗 CVE IDs covered (22)

📋 Description

CVE-2025-12816 — node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-15284 — qs: qs: Denial of Service via improper input validation in array parsing CVE-2025-47907 — database/sql: Postgres Scan Race Condition CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-66031 — node-forge: node-forge ASN.1 Unbounded Recursion CVE-2025-68157 — webpack: webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects CVE-2025-68458 — webpack: webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior CVE-2025-69873 — ajv: ReDoS via $data reference CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-25896 — fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling CVE-2026-26278 — fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion CVE-2026-26996 — minimatch: minimatch: Denial of Service via specially crafted glob patterns CVE-2026-27904 — minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions CVE-2026-27942 — fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33036 — fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-48779 — ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments

🎯 Affected products82

  • Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/cephcsi-operator-bundle@sha256:c291acc39b5c5bb3a2c3e9ab83a539ac2553d4b021892119b54e28f86f4094c6_amd64 as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:420112898072e37fb7698a706176cd71288f104f7740848378b33bc36d377c96_amd64 as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:47b312b3d0bb3b8e63a099f534bf51880b2ba739f7a674fee6607efb21e2865d_arm64 as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:c2289874552bccfbb09fc0053f59d5a95478b517ff89816c100bf38b173729a5_s390x as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:c51fb28e26b47b96cdf736b30ca7a27dff4fc4c579b7d8638e52958f04be45a3_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:468c2b233a2d4e44b3016139b52a06d28101a63d8b70c1cc3ea413a082bcaf58_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:6d3eceda5b92beb26d20e83bd814ee25e83896c9ba1e5cc6b53cd97c860181ad_amd64 as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:da2dbfde9be76d257df89e168285ed7a03173dc03ea4bc0ee3d13e46d63d0661_s390x as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:26b1d264c455a9796ed3c52fba80bad8154a58d88244025397ce2964072e5cd5_s390x as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:5878042e8d556331805517a25263457772ca13efeef2da330ededc9a47159861_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:b60dfc33f2fea78b4f18e0cdc5315f2fe1d35e5efd649b79019ab74be2416291_amd64 as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/mcg-operator-bundle@sha256:0b6ab8a023058f28c757d590bdea193c0d951535b6dc15be39eb68c6ff9db607_amd64 as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:607d09cdfdeb17b190a0fe0497335a95d6ef7896af4f89bb8125d8e9904b0cae_amd64 as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:a36e460e0f1fc24fffeb1dd335d48d9621a48f09c5135f38525554466525575b_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:dc2b8a25fd60d1d132ddccf396bcc0b538f63f9e2f8ec26d71a814e36621b884_s390x as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:eb8a159f967019ed03d30946745b2e493354e565472af45fd6d20aef58c337b0_arm64 as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:45a98fcbc383f76e919c0bed83205b66fac0cc864bff2f6b68efd2ad96efaeba_amd64 as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:d50cd5cf17ec3f53d23bbfedebf63bf5d63479ac754cfdd485977f1076ec40ca_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:f599c8dfc75e520ce40f699d991607061785b5f8f8a59fadbd7152688c1240d0_s390x as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/ocs-client-operator-bundle@sha256:b510e61d39cbda520b59e8bf9c9c778fe10f606389e92889c8f88bea2aebd5de_amd64 as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:51791037c682689ac6e3fdd880fe3792e50792fa5a940135e3e93209f4761799_amd64 as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:69d64fcb0609dca23ca051a1e67a3c3af02560336709bc0a7197fb84a7523246_s390x as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:71706aa11d805792e72b431b33a6dce4dadba63073f396c0f27ec0601834e1c4_arm64 as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:d8e259446d3a6782bef0e3d03fcf5d2e8904017a30ed559d3e5825a5465a2cb2_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:0b45328822aba0f4214cab4dba2bae2b1488fd5827a606aeed642a1be0448dae_s390x as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:1c04bab4645f9d2e896443f138b06a8c3aedcfd0880db10dda6ad3afa7ef4e0c_amd64 as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:54fed3e921c7d3dcc59165adbc58efc95602d22b5f6f934b1021b62945ccd4f7_ppc64le as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/ocs-operator-bundle@sha256:2b8bf257c02a63d571dae5c4bd913b57f22344cf393ec6ec39a816dd81949406_amd64 as a component of Red Hat Openshift Data Foundation 4.18
  • registry.redhat.io/odf4/ocs-rhel9-operator@sha256:0e4836594ee56f9f76acaded91f46a888d467c55b60927b8b4880efff443023d_amd64 as a component of Red Hat Openshift Data Foundation 4.18
  • +52 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.18/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this issue, disable the $data feature if your application does not require it. If $data must be used, implement strict validation of the input fields that are referenced by the pattern keyword to ensure they contain only expected and safe characters. Workaround: To mitigate this vulnerability, configure applications using the `fast-xml-parser` XML builder to set the `preserveOrder` option to `false`. Alternatively, ensure that all XML input data is thoroughly validated before being passed to the builder to prevent the processing of malicious or malformed content. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (26)