RHSA-2026:44267HighCVSS 8.1

Red Hat Security Advisory: OpenShift Container Platform 4.21.26 bug fix and security update

Published
July 28, 2026
Last Modified
August 26, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-40895 — follow-redirects: follow-redirects: Information disclosure via cross-domain redirects CVE-2026-42338 — ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-59873 — tar: node-tar: Denial of Service via crafted gzip bomb

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:028add11aaf52bf2e5bc1c28cbda7b744bac9e58e3dbfb1e40b4063103e0c1fb_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:151b1b447b76cdabf372ad95bcb607f87267d8cb917ddf92f471e9d071399d3d_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:25d611a7b723a91022813be661a4db54a98b346aa6bfdeb5642d86cef0f74719_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:ff6a959c16a167bd0237e28ce902111ac2bfd5c8adf13c8d19b3251de34bc372_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:21ffe7c50dcfad9fb2504d114ea8f16db35bd70a6dea723d3e9ca4199f36ade3_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:acc77bdc72ad4e60cb7100cce1dd6e846fbdc7a428f53692bc779bb77ed082c0_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:e3547c70cd010b05d85ea5789d670d9bfffdc1688bbaa24695d766bda278636e_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:f1a8fabe94bd4c9e4af4e649fe9db37b09e5bbe394f7a143a63c54cdeaeb7b22_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:294c38f9494c75cee68ea667f81d53986c42a32fcc1eafa8a52e2de2434d78b7_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:45dfd6567d3df9120e022910e03965e497bfcf6a11dfa57108409c0215291efd_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:5d3aa9cc75c28b4bd95ad5101bcc1890fcb9b4d9a8e42f6fab1510e4e2c237bf_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:640543bc1e10728ef7873d76e677a3092b260b519eb586f334e76feeee7fc93a_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:2f8513844a5633d23de6f50b73e7347df0d427588be8796c66481383da835bc4_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:3d1b9d886a9ea7670802e029562cd29c6cdbde5ead5d213c6afdbc8391400151_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:bf1bda75a6809935859f718062c7787048642f397a9e5e8ac124b141aea1b681_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:e37e1f3d7a5f48539dd5f6036d755dfe969ccf3486ca29723fde7b04f1d310f0_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:54341f8f0d0ebf02e74423138f03bb79e328f505255db890f792f2a688758f71_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:89cee3f338905fd26b15a252994cf7f3c0874af732d173c6b54cfbf9fc5b5d46_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:e07dc378b38625d09dec21820e81710ae6e83bec8248ca6f05c4fb826d37ea17_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:f90c25164c5d2d0a073464cbc0f20f2f98692133361ccd72c40f7da79a10238f_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:573430077274c707e68957801274842ce6f5a4b6f15133b337edf85fdcec1cfa_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:8a40cb25f4cddd168462330e368b21c4c9188b78a84430546f3b910b02f2617d_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ef068f553ce446f7fa62cc992534ef80fb75b279df18b5dfd48918906356020a_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f3803e10bd301866d952c6dadabc452e533837aa52520ba1788ab02bec4b01f9_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:3c8b3f88ea4f5e25dbe5009977fd3d9dea0ce5aad49f01949aabc2cae59b47bc_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:421416a4c9e0c5c4466a042d637c520543014b45bfcfa9176ec22f2bcae51a2b_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:68b5b0bf0cbbc0f7272a211f136aaae4a8e9593d14b96fcab10abd182d12148c_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:a9818a7bf31d8c9505c66bd2ac99b35a03f1a1dc394b8d7e734698449e0d0587_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:3380e49aff7920dfb0980058ad4af84319ab5c4c8ac2078d20c069b791d3d15f_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:f2cd6a3878eade92951168bd9491cc4828f02e41e41c4d7fad8d7c7948156304 (For s390x architecture) The image digest is sha256:6b80f7504b16dd1f5e82914b27fde5fec70f5f982c7bef37ed158c5374e00b5c (For ppc64le architecture) The image digest is sha256:4661974ec3f832c78905aa8b26833bd7f094072cb50e23bffd533b7310d05b35 (For aarch64 architecture) The image digest is sha256:e92f91e7d484df0c13799bec4993e1a741c7b05a395fe61a2b711aa3d855a620 All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.

🔗 References (12)