RHSA-2026:44233HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.18.50 bug fix and security update

Published
July 29, 2026
Last Modified
July 30, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:0419c7b399d6fbf8c4a2aaf21bc2182dad2ac8ace92a3f7ff8f62eb00a4f9e6b_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:1cbc6ccd44677b648beef153ac01f56f6ac8b10043334afb63af394d01693f95_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:6fc9b00307dbd5ef10d79ae349d1880efb10562db468465ad642629ab3cafa4e_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ea3ac4f5bf27c762f534f511ae50d916cc72c0946bab330bddc5b1e59761cf4a_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:1d7124312a528d6456483e4e577faa6b4b4435ecb1c8bc96cc39adbf69c367b1_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:4e91c162474cf8ad9e745739c76115a4044f0c69568a66fb6bddb8b7d8e771ec_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:9253f2ea4c18916a92ad872b23086d3a0ba19772801b7c3e0a02f0e2f1dd7239_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:f752c20ea2d2c85e338df26634725365c2f62895efce17cb72c1997331dcfd81_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:2174ead9cf3fa83f7275e95b7b4ac4c760978b772cbc167d5610d871c97fad89_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:68c77a48905ff4b240411017c699254db100fa8fa5d0d29010025a0c356cdabf_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d3cfcce8a64d78c71e2a5fa34859b013ebabd957a00bcfdece7db1f5f02ab3de_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d5784db11551bb54400c2f9078919a27080fbee930fb8724130c2f7248836eee_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:030967ff51ab18743110196a4ad89be72e8a47d9e3b64274b828a0ba2b9c8c14_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:6f0d7625c9e2ed75b927418137368c9d4933e3cc87d7640d462dc9ace887fb0f_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:9014e45aa55a6277ef653175ace5d4aaa316bfe961e03f6d55c175fcf707277f_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:d06acd22525a8d48d43031e2d718ecb06c1d2a3b309dfb347ffc29178c02aa19_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:2474219a16a60d9f09a8c896205694a1df7c4bdf13e7be173beb89ac75f592c6_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:414b52c52af854ab660054e16fa9848603a2e31baeeead1488d6e36fc69f1dad_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:551ff3f039242ee11fcb88e5ffbf85d174e3ffb908bc34a244bf65ee0c20d198_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:5d804e075193b24b0efc9e3684241827da2da14db4625c0efa7d2ca6595762de_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:a3aa8b1768347cffdfe06eb6cb4c7ef11727fa1a87d3253582865b4ef05364a8_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ac83cdedde8acd9007a38a60bb1579eebabdac14ef5af07371447bdef73619c6_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:e8451ca709c711d3bf542f19ac3dd9afcad71b67a257ece04e87769ab1469faf_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ee0767213360bfcbe6625a382a74c9f31ff0c4129f3e4d0d5657cab225306d21_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:58365549f15c0af94d31247051adc0a25ea705fdb4c2a921065a5fa43319c4e4_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:72115bdc83d2ed93bcedda60ab558f426a3596cf1f4f692604dd42d1d989dfb6_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:8d758cd63d739ab85dcff513f052bac5194244a8d6f1e70f02341d8ce8450679_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:af90de440d330522a6d3bf7480930540857bfa0f8bb34d7e45cef5588f3d2771_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/frr-rhel9@sha256:1efbffd5d333c80a28651d740fe36316cd5ae01e44ba56418ffa714f1d842403_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:06c81645f1c2c36c637297d2b2bfc9f0441ae4b78e88e8f2e9f67879a4ceddeb (For s390x architecture) The image digest is sha256:fae2a08a585617518ca1b3a5d37eb43e1b77215390223a6658bf766472b09e29 (For ppc64le architecture) The image digest is sha256:6c3bfbee4e48e56b6f0cad979e81445af095e99ebb6da0fa7d0009be26724969 (For aarch64 architecture) The image digest is sha256:95179a9a06cd4be07272fdef8276105d5d6edaa88f5ac6c28a8674e2bd2e993e All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (4)