RHSA-2026:44235HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.19.40 bug fix and security update

Published
July 29, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-40895 — follow-redirects: follow-redirects: Information disclosure via cross-domain redirects CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:718f96f43cf0387be6cd922628b636432e36a9c093564fd8288915587b62ce91_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:a745435c1384987491ca5672f9b679b15899ae630847936d5743a7ca195af238_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:e1263e39bc9a15ae198e15a241d82979a35a77f53e2e99b92d6e258068243ef1_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:f364711c910f987d2a15095c3c105c035f6003269bc96c98cdccfc44777d22b5_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4c323e1cf933f9a02af43e57425bf189cbd08fc30f0cc471778eee669a1e1c9c_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:9f2cd4e5b86e7cdeab40f1e8a2b9cc42bad880fe8e8218e0da9ff02bbc48aec9_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d4ab873900f98bb6b91b2c6e9fa9aacfb72b954653da8c6f509fb7953a0115f3_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:fec5b36d114f7d7694a7ecdf55e9f3bcb546dc697986f9a61d31f8b808932de4_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:0231f446a00653bc62ea571fb609907c9d770ff8d347975f30eee83201bb615c_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:0bc0c984a3ec28e799e253031244686424451be5fb6f7b893f8e3782517ebc25_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:2c1c099ab60bb1ecce7e144749f312285fe39b93495f1327a3727b7d3404e6ff_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:63b208bf1ce1f4412f3f7374d2eefce0f81276dc0eefb105f6fc506018709d49_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:20c24f93b6268478b1492e3ee2dd19bf2dc248c291f2e09eb3b6168459bb0366_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:6c4ed95e7dbc7c0074e74092e1b585aaaa99891fabbc8b0ea3ab640e4fd3f810_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:a617b1bcf1f42929fba1d4d297966e63c61541830480e3b47020078308c54e4b_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d76064d389bfbafb8598c90c4fc71f92da9a6a3a2b548600d7cd9f43fb160e08_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:5e27346a62c0da131bba24363b258733e67c063b105d3eee3d087851d5888e13_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:793855ee56c7a301e7b078b874909b80a3cf735f310635885383b1eaf478aab0_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:a3d59912ccc2821cb5d345a9178dfcdc54f562f91d54965fb588470217ac43c2_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:e3256e02f766f7bca0667a039ce8315ded60f68ed6a59b0a27bb446e79cf76fe_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:2297bbb70c505e763e502a2d23ea44efd6cc3116ea3c3bc71783b1ba3953ea4f_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:3e55bf855785550f97378d58cb6ef56cb8c6189c9e9d74327be980a56ee9142d_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:8d7661f5fae2467e47c52456ce961c512a02a5fff27ef5f41cfdbc533297ef6d_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:92898ce73d886ea6ecea05bb37e71330b484f805d1ba38edb29d6e8d637cfab3_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:51146b3b380dea298b5e89bf7d983f306a7e5336b8f6c0c24a88612672daac0a_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:61124e35fa6cba43a8b6e2d4828d784203e8249e2dee98fbc855926901c704a4_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:722dba70f7491eb78326bd02695ecc707a4304322c6ef4f338449dc97a941469_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:adb51c7e85d9c0c52ece596b9e3c3049a0f6875b7f908e7e9f0f3527ac995766_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:0bd5c2140fd955683c69d86256527eb96858abb8e0efbfb5ff840b72a18990b9_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:800712da0a4fa8353d0f94a06efa9e6a1479726b653b0d8ad1243f014d40f1bf (For s390x architecture) The image digest is sha256:4d0acc69187a33b0b10a3eeebbe7d60a7538e3c7a70e37054370f7b24b649349 (For ppc64le architecture) The image digest is sha256:310602fabcd047776ecc3c52f82b03a56f4fbe79c1b052a5a6163a271f350227 (For aarch64 architecture) The image digest is sha256:feeb5daa474f243df61a0e7043c8242bfdfbaa445ca5a22565bc8dcbe42aae93 All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect.

🔗 References (8)