RHSA-2026:44264HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.20.31 security and extras update

Published
July 28, 2026
Last Modified
August 25, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity

🎯 Affected products178

  • Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:748dae2f4e0ee7e45de18c95366e4f2188ce5d7ce4e8b7b83e6c88be5226dc56_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:a10ff857e0e502d2c390e0ceecba234e0d39d5ad709218837b004dcd906381f4_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:b57071c66a8c8ad83188234f8cbecc8522456395f76dc9fe6893aa3b904e1aeb_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:d0d2792781eca363fef3f649a6c2dd5adc405242f42e2aad908bdb40d17b22e7_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:4b507a3b006f6706166558d959d34acf446f091fb4943df0f5b26fc11f306680_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:a8b12f6a555af55354f6c4b2b92c9c3a4133dc6399bf14dea874e144d971f270_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:dbe1cce04d9045c114c70124b9f5fa674aaa7f23084a1c7ec5fda59d30d3903f_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:f390cd6841314f061085e451ffb1e2c51e36398bad98f7824c480bf3c74da199_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:042aee665e1894ea549c9ab4881c8d4e86207a9cfe398d2ce8fd3e874fc4f175_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:c4bb08f984ca7e4c2918db6fee5fa66637ec9156c5a683b25f2bd6c63d72c9f8_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:c93cf3dbec4bf0ece500476e589dbfa58f1beef374dc79369e012f5708dda401_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:fcf7b54a6e23f489244cef8dc168cfd86b286d4c3aac64bda5f1d9bfc6ab0dd9_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:17f02291dfef8340fd9bd8aacdf813639fb92a4d6b106a117f0774a5c38d2106_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:89425d4ea39114569cc4c2e44c8909f5efb96d4ea4ef7f21946187b721155f04_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:982aaf788f45bab2254c705442e9b4e8a7ee3a907c2a2317ac342a42ea83d9a1_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:b3c8979ba1970e3e144bb0334103f921a869e408861f8116899a0ed755e10a26_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:3a96c1dd9c1edde3e83fe2e2b5c14ea27c3acf126c071de7b8ee7734c8980052_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:3fdc0aebc1dbbf2e5c89402ba1a31893834eabd583aa355b788960dcbd8fa36e_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:97f7efd9c97cb51e8c69d7e10be76b1e0f24a88ee35bf8facfe131ac34d262e9_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:dc5c97a8a33b40bcb6081575210b94de19d8aae55c6f20c3b1d999f2f79c61d7_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:0d474e39ecb21ddb9e2f024e6f05e315e7d90279128af501a1fe6865d7d91d70_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:18c27d815de233bb292f21c725907aeae7a24d13cca9a3f5c140444e09140aad_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:9e1ead10d351756bde0eb500b3b8f21ca348cf83879a7ec22638ff4d2ab6dc8e_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:a9b5aa5baa223776097ee6fdcb6c316ce978cb3de9d5310ad08e13b4dfcfc9b7_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:513dc8ca252a6bda983e51d76c23f04856816376c237bbbc8870c0db66f7f32e_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:86d355fc182608f237eac5921a4d4d044569045a2072591761de349f2804c0cb_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:967dfc02919cc3dfee5c51c500ee45be7a6c9db62aa128b13736952e6127e276_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:c4f173ba168dddce755aa858b6d781316bf9b44c7929fa4b86da5801fcc3a0a5_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:a2c40425a2e932f3d06af911b8004281370e0f817d9fd805c467c373c51d0eda_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • +148 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available.

🔗 References (4)