RHSA-2026:43253HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.14.70 bug fix and security update

Published
July 30, 2026
Last Modified
August 28, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-46579 — openshift/router: openshift/router: mTLS client certificate spoofing via unstripped X-SSL-Client headers on HTTP frontend

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:0981077f9fe845a8fbd6808669c207a656d39a6d01e6ddcfb59a9cdd35da14c4_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:569230751eedb4cc4d025e45fd0ea77c68badb730e5375c4839bbd699befed08_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:61eb82def9ad41dc1e18f7c605b45e34a437cd0bb4ab24af811db8adb52b0f7c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:7ab205b931664864a8128a35ed16833320b7f3e550bc567e92235d31c46f512b_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:5aa3720db44379fb76453091e7c34e885412b408558c07351b334ca0d0cd2b5f_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:cba22cd52390ed0810aa2b24088966ffbf400781cfad27ee39e2cf6060fdfcc3_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d08c3622483bc5212fadc19bf433939d9f1ff86e716ef783a430e9619d1bd159_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:df7a9c1c0b0988fd5d18ec9aeb5237b2e6ed9a1f1db41995c2313b0239e4b34e_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:07729cce618be69f0f7cc6767ab21c4c48d7f37b4a2c6bc39845635954d94eba_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:3c4b07a41b7fedbee95e087ebda5943848e66c17bc407a140b5f951bf6394948_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:6dfc08ee74b0c80c01d3ae21af0287641ba5ed1d3c2f500f915ef09dc052e4ff_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:fd04b233dc1200872b3b7c075d1db9729a96231e80400b87ebcda0f7e3723b86_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:2a662ac09e4ecd5bec1fa173fd6fe297a9dbdfea49f76d916d8bf8de392b5691_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:bb5caf242a5ffb7e73cec398ac1a933d321a0b9c4f4e85db8695d28f56d19903_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:d24e50a0fb7d4e791e755d0ea7ccbc7cc32ee99c0a14a7acc3787a3598486283_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:ef366e50f11ab6fe5dafeeb80d1b7b335ed177323cbb8d16afdc287affbc8fb8_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:055eff51e58dbe742283122c1f8927f6bf413524efc8c832d987cf089bc5456c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:1b276d954e7e0481c29c168eb2ce5ded55121ef7ae29e19af8b63fbc9913e832_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:b78a117c14a0018bae192d9ccc5637c796c49ee87dd6699d3cdb71acce0f2631_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:dc3f06e14b611dfadbc08280e489ed441f52afb2b5075d997f4a983bc2c217ac_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:8adff848dd10bf4c4ca873b50d63705e1dec6e5fa6ded983d0a48807356af8f3_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:a2fba4ae90a46e1333788aeb04124fb9e030ec1cbf55add9acf27c794fa4b29f_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:b29336a02fb09549f9ffcdab459e37579a8f52d477b114a4c31cf51c41695231_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:f90d2abaee58aa38c72669aa9620a1d73856072646e39d1d8bc383fd10b59159_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:48ad6d16b3e440b82e03bd2790a1091d090d7bcb3b9709f6f9b1cdaf57fb4a10_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:6075d7939b2681ec7f7aeac3a4999aefb28ea262bcd3157c36ff6513daf39ba0_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:71da148e56f94310ce38499c7dd4259d8ddb4c24cdf47cb9f11cb10bd5245a97_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:da265b921d6dda92af6c3a14dd29eac9abf5271236bf509c93668afde31d6d5f_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:5e1fd27a93ce783d972ee1aa9452f3f6485033591b8cf683e2449bcc4629ccfd_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:1295cbaf9e211bbfcca95501eb454f2cdb90d31ff3c724cc96dbb1b55788d4bc (For s390x architecture) The image digest is sha256:5fc9b0efdcad856ce6d83ec89ce252347fbbfaf8a8f8f6a9352418ab2ffcf4a1 (For ppc64le architecture) The image digest is sha256:8474aa39e1c5842c8a9209f42b877ffe06df7f4977cab7f2a881ec57aa6abd31 (For aarch64 architecture) The image digest is sha256:4ac3fcf2d340595a8182aec92cf3e7b5c8d7d28932afa8b547c987046dda07be All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended.

🔗 References (6)