RHSA-2026:41944HighCVSS 9.1

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.19.20 security, enhancement & bug fix update

Published
July 20, 2026
Last Modified
September 11, 2026

🔗 CVE IDs covered (19)

📋 Description

CVE-2025-12816 — node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-15284 — qs: qs: Denial of Service via improper input validation in array parsing CVE-2025-66031 — node-forge: node-forge ASN.1 Unbounded Recursion CVE-2025-68157 — webpack: webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects CVE-2025-68458 — webpack: webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior CVE-2025-69873 — ajv: ReDoS via $data reference CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-25128 — fast-xml-parser: fast-xml-parser has RangeError DoS Numeric Entities Bug CVE-2026-25896 — fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling CVE-2026-26278 — fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion CVE-2026-26996 — minimatch: minimatch: Denial of Service via specially crafted glob patterns CVE-2026-27904 — minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions CVE-2026-27942 — fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-33036 — fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-48779 — ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments

🎯 Affected products92

  • Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/cephcsi-operator-bundle@sha256:abcce35db8c70c8abf62ca0597cb146e89bf5b612657ef91570a2cc852439fb5_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:0452d41383814479aac36c6ec8795b3090980515df082a12ee159ee0c8499d43_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:1b171c07727e481188f94c64274de908f4c3830a0fd147ebb1f5fc0cc1c1db8e_ppc64le as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:a3efc8ba6ae18b5dfe9b7bafadaf1b17458c1d27803e3d7ac8b44013f72324be_arm64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:f37fca7a5b057f5f1f76bb806897c9f5ec53e59c680f60ce53192485f7dfe299_s390x as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:1a5031d59dee5a81dc17c504934f6f66559e509d124c181f90cc17625af6acfa_ppc64le as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:56398670eee80b5043e77106b9ee769a584872de5baffd7159d6cffd13d24b4f_s390x as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/cephcsi-rhel9@sha256:62dd37ed631205c855b9438396987008c5db68cbaa6d61eee4cdf2c5ddc2856b_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:1d500daeede9db67f65122ca2b9ba9275fd9308c02f5157a42d054ee91ae63b4_s390x as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:4d868a7f6a72d014d195c7e884fe7fbc5901277c6e9d44201fb0cbe6b3901fef_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/mcg-core-rhel9@sha256:9ece51fa5ecca9ca932c01b356dea548461b0215a0d9505b2ed27f33341afe91_ppc64le as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/mcg-operator-bundle@sha256:8799e3b3750d0ac29c1e90890906d2b8c054d98158abc24820083d37ed4b6e67_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:3bcee80f0b87bcec3675f6b7071a7664497bfa40030f5f136dd2fd43950d5a14_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:49f8bf233b7b34253100e17f2c6a9f45840c80580300b346062237e10f567229_arm64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:5a736355093b69a46c84ce278649172e86b2850102484468368293809a2a9f0d_s390x as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/mcg-rhel9-operator@sha256:69aa396ebfa0df5415ae4af6bc7d5f8f42130a31f5df1b5add3712a12cd9f070_ppc64le as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:2b22fe58e02abb82570514aeab6b27cb46e1322cfa71f90162cac8924d40521c_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:661d80cfdb84ccb131dbfc8737aa25678154366e7cba4f4d5cf5fbe798e412a4_s390x as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:7685f06c00e5e56fff3d20c385858b6d718511da7a69e2b2429a85e7c859fc0a_arm64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:9af545ce1fb2a8147adbe3527177dc5bf0d25a9a5561a95cf6a55e07fae0df28_ppc64le as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-operator-bundle@sha256:4aebc13f5cd723576220952bcc11b3ac4e975f40693ebb130d085aaed1183d60_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:0d5c7466f9cbbb78608c772edb33c6a6ce5faa0d2a22883720de4a8707ae1f43_s390x as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:723d090cf363d0426721287b911a222b790a80d99a2d4ea5516bd74fa58d6a42_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:b7691d3c8da4a4d437b5dd6833da28365f7fbfdea38acd75455653d566f61038_ppc64le as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:f522f342007686ff281d6cb0ab224915a385c6970fdbe2601eb3642890ebef32_arm64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:33687dcd95f5586f4f60d1fd91c817c54ded0b1a31dfa6abb28390c1388587c7_arm64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:4a4b87985482dc88804daeb5a32f3ff6c43b3769118e323a49be2c9c0af59ca3_ppc64le as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:837e1ccb1727486dd70268b34b86c894371101a24c5284b2a6f7d392d851e6f2_amd64 as a component of Red Hat Openshift Data Foundation 4.19
  • registry.redhat.io/odf4/ocs-metrics-exporter-rhel9@sha256:963032931c6df46888db0d16ddac52d41f346c5ddc3c0639c1e730ef286c9361_s390x as a component of Red Hat Openshift Data Foundation 4.19
  • +62 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.19/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, disable the $data feature if your application does not require it. If $data must be used, implement strict validation of the input fields that are referenced by the pattern keyword to ensure they contain only expected and safe characters. Workaround: To mitigate this vulnerability, configure applications using the `fast-xml-parser` XML builder to set the `preserveOrder` option to `false`. Alternatively, ensure that all XML input data is thoroughly validated before being passed to the builder to prevent the processing of malicious or malformed content. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (23)