Red Hat Security Advisory: OpenShift Container Platform 4.22.7 security and extras update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
🎯 Affected products195
- Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:0201194d2e390155629d4fab31f6d90165e19ccdd5310cedd37d97910507532a_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:299a53f075f4f6c6fbdb710c02f05d56c1dcce9e05679681be7d1aff24f5a844_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:7fffeefafa8d1f7d545c89b59de436f5e6d533fa2b893d3708c5fce8f595e170_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:b92141038384c6bb452b6d4e1737c985c1d30262438865f3090a9eca550b7400_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:163cc26a1e70c5d9c81f110a84c6e544570e2d68ed0fa0794fe45d6a6cdad8cf_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:7befbf51c45be9849ef12bf35db616a496a16dc8c206c249f568d9cfe0357bb8_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:d98b325f816ee9a8b79eb67e53d433577b7d9637def144f0a43d08a20b358169_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:fc372aa32f2f7009d0812f40360daa57506e6bc9f1146f989842c1bc8ae9aa39_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:1d2bff05e4bed04b5c5f4ac75834b11e16313226fbb2df6d168a6f9eca96e1cb_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:216cf7e29212e1b120cb0e8fcd75cbe04fe4c708b1142e17cdcd6322a6f2c58a_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:42664ce5ab2f0d9dac5cd5ce32b31660b5d63ae23a1fe6cd3a00d38edd401d00_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:e48931caf72c37ff17dfb9871bdb5f6897380ebb6b5b1dba41ad8484c010b62d_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:242825ffe582aca687c126a4e5b92a553e15e5b67ae7fe7c133b485eadd46fbd_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:35ab69c40cf8d12545371c9562bdb2ee04f4a4d32275f110fcce80bb2844dc6a_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:d42d6cb868fb00600d6271cd835b8bc74f2725bd7856cf28e5b201d487e36959_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:d98f83716b319a50c49a0a6ec7604680e60863fb6efbd72aef266fb538af28d1_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:04a83ac6ac76b654d32af11fb88f15125615a0f2cffc22d49cfb52253f6241cd_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:413c874a326eca4769592330dcdc60fb777a6171625d782cd57feee2c2756e64_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:59631ace37256bcc614825d7cd11d0c6c438a2e79563d4e7f2494e418019f117_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:b2ea576739cd0e8bb557d3329012192487fd47073865e4d734cdca9fbd2c081d_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9@sha256:1db405a10a565b1e225d466d8d3fd954c3eccfb99eac7e1705a74256e6094088_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9@sha256:77b77d03b294209e355388672bc3a59824803235194354de3151cae41a574057_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9@sha256:870859316f6e9a4ef609966c29264de3ec295f002d94bab5d24d7df34cbe12c1_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/metallb-rhel9@sha256:eb7be2343aead01385980e17b5abded8613ba8cbb82f365763b1a5fe76b84e53_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:0251690607374aa68e793df00ac8e9c574866769b42ecbdc5665f5d4f8019e2a_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:afc69bae101ba15c4df0d4be197a103797e9035a6014d3f186cf735ac3c07934_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:c504997db613f08299ff86d94c5e45e84cd8657b2c09b48621b2747a9f101531_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:dad0ad54658546d93fc3f691cd3934dd4354e17435edad4297aa94ae40e4b0d4_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:3f0f49cb60d645dc63a27f7c64ecb90bd8a0de8fa2cb62983a1b21048f65e5a4_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- +165 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:44239
- externalhttps://access.redhat.com/security/cve/CVE-2026-13149
- externalhttps://access.redhat.com/security/cve/CVE-2026-13676
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_44239.json