RHSA-2026:44263HighCVSS 8.1

Red Hat Security Advisory: OpenShift Container Platform 4.20.31 bug fix and security update

Published
July 28, 2026
Last Modified
August 26, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-40895 — follow-redirects: follow-redirects: Information disclosure via cross-domain redirects CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42338 — ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-59873 — tar: node-tar: Denial of Service via crafted gzip bomb

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:0289e5f57c72925294188b1fd8fa294d628ca9311b449a2fe11233797f1827c2_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:25a01f64673ecc30a065bd8fb1089f84532dbfc7640d6b790295edefabff21d1_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:44793aa3bfc919edf1db763cb8d9e5d3325b94834f8fdf280f413f264cb0ec6b_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:fae9aeb6a17720ea70cf2ab8b7b0df2f7a1c287c9f5c2952fca8e6f3c4769649_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4ba3fe78119a91f73215107ca691bac5c729470aa3215fce894c7d7787d59ab7_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:a7d02e23a370f6e4919d83b631bb5456590a7243d9784a135caa3ed114133d1d_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d7c3f6abd95ce595aee3621a8864375eaa2a8fb506f0ce73d367cadcce0f0ba6_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:e0dabc57b2efaf0d768cb45d3a913ab77f27d780a2ebc29fe7023abe2013fa22_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:796ac956e49c5936d56769f4d6738fc19c13e1f21bcd58d86175d4e10c882eb8_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:8d386a5dd1a3636450e5a9c431e68212676467cd3d7596c5d49196f65ab14374_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:cb65152aeb1ec9728257e5eda9a13fe608d493be8a15075573d45a6bdc447bba_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:ec4368369c815f2960353bd355e6f55492dbf99e32ac6f2f0d8e75adf880bbde_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:873ea30823814cda887b5c50e2e109210b0bf05e0941eed558d185518227925e_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:a6c19a19dbfbcb082fb9a3d535925d1532778d5eac5e8dec946adf81bc685a90_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:e2ad01525354ca96e7519047cd7ebd0f35eb6e88f7cab24b1b2eb3d36724dc9f_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:ef3efcb6c914ee8e672db9ed41dd3c730a767d0f39421ec99ece5a6283300c14_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:1101bc75377b00d137e8d8e86c97eb7303a6e66b5c8508ee58eef8896206e69f_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:29c5b93519efcc61adfe4b3ffe825c5db165979004f6ab70d2065d674d62380b_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:c7391a68570913886873cb4342eb2083fd158b70f96aeca5ee82d97074544f4d_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:e715cb94b2285601a8a9e87ec32686c2acc639f3a2d5ff767d71f8906cac910b_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:3d80b2b5cf068ab234416fdec94cc9d347344f78f342e6a0ea91a3426664f64d_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:7b45f5c617c2a2721be9f7dcdf49a92d29b6bf74303019df22241732f8e56675_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:9dff824ebddd277cc565a013c4bf3093c9316cbce96224c918eca7f5dace7030_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:b0f562313699196872b9cfead91b0c03836c8091cec9fd79b31400e6218f351e_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:183637da434b32523d05b00b632ee78a712b63338445600f165348ce55e75dfb_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:1bbaf0a398889ea880d8bbb38c9a937d23affd0c350f9886dfeef68f748cfd7d_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:45d9a18b94e0c2fcf8081d014a0e9a0466623940202b2ff1a89187afeb086409_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ee925edc29b196e57a90433fb9d4db57650bbcb44d79b791bcafa9ecb1e5f449_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:35471207fe794ba9ab997054875917a056a8e9c414eb89b87087326b4258e214_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.20 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:c71adce4fdc09a3629f2867619aa255a1ee4b8e1e2a4c2183a2e4186055d32c9 (For s390x architecture) The image digest is sha256:fdc3c5b3428faae581d89fc63d580858f5dac05dc6f7a569d7e9a180f90c0577 (For ppc64le architecture) The image digest is sha256:f08f7a80bfecab89cef342c269b1e85df53821522b70933c7d621978668218eb (For aarch64 architecture) The image digest is sha256:d5ab19e45d2051a0158796083ab2978237ce382ac36a02b06ac92c63487cf5e1 All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (11)