Red Hat Security Advisory: OpenShift Container Platform 4.16.67 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-46579 — openshift/router: openshift/router: mTLS client certificate spoofing via unstripped X-SSL-Client headers on HTTP frontend
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:0bbf2aff74c94141c54f45dbbd49367e4c7d5c221cb3b5c40f76395abe592354_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:250d8d18a2a093861c5915e82f9d275c3478f3dd8f48a255404213f114f9a6cd_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:81458be3b8256099a94aaa5e07150411b83ba5cd3ba52c5f93d3621177bfb844_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ca354728f3e92e4980417f47cbee034932b68bbf78237da23169c373d323ec45_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:2383f01f7bb41e30d85915c985e4a2ac14982af81f2ac6b71f2d47be7fb2ed49_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:70f73b3faee7cab9dd47d3f538ae22c241a6a544bcd9c49c22c0386dc02e4faa_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:c2d99270a6bf777d9e6f1be7653c35e86a86ff16b5737250e5c88fa41fcd9765_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:c634dc3cb4302896c2789213f3f18bacd132a3c14b00dc0bba50201c2b753d63_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:706da59d1e8b325cc6fdb27a1acd2d16d250abbdf58dc8c85dd79ecfe71a732b_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:88dd05d72221a18ec735d47b109df683ff9d4a3793cdd71243c58e19917fe263_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:db24c289a2b621751c3e08c331fe16b73fb7b900e6c063314c2806790d3d9257_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:ff6d24265b2ce82da1a4ca7bd2228b481a80eb9427f9fe77b4aaa8b9b3676324_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:03e513af7f17653e4a94f47c89d6b2fb2b00f8f3ed9b4ecfb2817a7215d8aac1_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:a3e98f1767279801d05af8c69abf54c547f0adc485dc2b27c311248f72e82277_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:e756d78412bfc3f2daab674ecb128d6db0cbb70280a52fcfd45218bfb0c415df_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f865676e34466b0b4020a8a2090c11589f63806f5331225f59e31370221f5d90_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:1142d5c2b8958e146c46dcafe82b879aafe05711167af2cf59d44c08df3ef970_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:41206fb6efeffa1e3e6f3745580e7730e34b1028130be848580e15a0df4387d8_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:a24c3d0b69d81ee43562f80e2d25ddd64dc3cb3c896f820a45cbdce6cdc50067_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f9a35c2420a3d14b382a2d4501f1090df63f71fb6f1248d7be0f0506c5b503fb_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:2753483fda879b0df4091b9a12a39dbaa18ff94d50372fe95e35595c26dcc36d_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:435493f9a721fd6a554ad8ae5d2d350481d7b112a3334644e5a1997360282685_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:6b7dfee4309409c58613bbbc7625a753c38923be4ed0a750c9dd99f0b54fa433_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:beee62cf1413fec7adcd8aa6c3407bd208de223c4fb41308f0b34a1998bd5afc_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:02c0ab348f593fa1f6d2c913d849ddc2074f5b63d0cc5fe9866121299e42a4eb_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:0902b08b1f6ceaf23ed045b502c5f2f8f456b4c635276871651e02256ce43861_s390x as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:2cb95f3b5272a68c5d507655e91ff27c3a41274aea5f820a696e33d4d44a7ad2_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:43a94f4156a289e6940606cfb5dc80bbb65ace3509b13e34a8f0e373b9d2625b_arm64 as a component of Red Hat OpenShift Container Platform 4.16
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:1a7f9035973203f0c803f6bdaacf5b2f1824149413cbc38987f11f448f4efaaa_amd64 as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:6a5d0afd0e373aa47fe1598eaf01f359840f893a8ed6e4aa19339fb3a17f5e19 (For s390x architecture) The image digest is sha256:92f19cab497175c0ce96cd8e4397050659749abb4acd6ba1aa922175b78e4935 (For ppc64le architecture) The image digest is sha256:6648df8a8521b39261157ebde71bbe33d93ad1a50a6defe8b2a36e57466aaeb6 (For aarch64 architecture) The image digest is sha256:e941c0b4962c8ce9a5fae339922bba6347e881450919822cf16a3d07ad6ea4f0 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:43331
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-46579
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_43331.json