Red Hat Security Advisory: OpenShift Container Platform 4.21.26 security and extras update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization
🎯 Affected products191
- Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:044c4fb6e54fdb0aa3eace4f413f9bb5f0fb68e557f93dc55ec7d01fcbd232a5_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:0ef5f9cdeff6ce30fbc9d610b7811416848ee2061c6158519fdfa53d1f955d3b_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:8117c7998234471319f27e0d1a3a7909bac57312e8e594cbeba5f1fb57a22230_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:baeeb2aaea1f5f64d234ee25422f6277d33f8a90f605bf63f907869b25be056d_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:2e15a54305f9c09ab4039ed17385a5dc3261cfd5f1825e1c77bba5e8f0ebc0f6_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:4bda6ea8c1eb8d40972b6ef29753bf6fe09ce77c18f64bc308f26432d5833431_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:4fdbaa6046e245be4f38ca51703e3d7729cd58a745aef8de89f007443c14cfa4_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:84eb680b2acca5d8aeb7529150eba996f6af652c1b1f9c2bf3ea3d604b33e96a_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:149e1c1a0ed89e74c1b699eccf985017ce38ccc2778b4f5d129512479c1ac1dd_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:4c90240a047c2d6e705b85799ab90757f2f6ea9371808a4b27949c73e813fee4_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:cd860ffe2ada196a9713a555f87550189a92f30990ee83ca59fed3f4c600aa49_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:d8b230c40250b13fa5ea41323c5e8a556547226831ce9289bbfad95b711fe741_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:2ef313d3351a4047c5056fbb7081703c54d4d433baad63b237e710520e61385b_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:65865c0f8e105f8b09aff054922ef4eda431fed9ba6f81f221477fc20af70540_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:70cfc34c8da8de714993ce1d4b958fe2b75c425e7d6ad0ac37d467ed2d6ab942_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:a516e615b57a01397c3a5c78df5ac29762f1d651d2e888a698cb488e34a1bd00_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:22ccd8e61bc9a9f6060a989b3e1b8d011be75a7ae9b04780730f29bdce45d471_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:94c056053f44ca7a0bd93f80c192cc7c0d442da0e5d051dba596e3de9f1ba51f_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:b88bf71530517339da78935d7c258a6136743fb7ac331df63158bdd8bc51684f_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:ce246c96ce0772cdd3212a2c92e317c69c5336f4ba7febe7fa8abbe185004c7f_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:226bfce4e5c02ce18e756b1b5da94a36a06e85c4c529d2ecbbdbdfaa4eb22501_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:242ac1ee8951daf72e28f6376f211aa3e407f4df57b09cfc5b906db238a240fe_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:4e76f32378eda69474a904f4aa591f8e75635a6b647fd5f34457e4838d1be118_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:7811653b7d763d694c68e60da140642f58cf0566667ddc17d645f1e7db458052_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:226dc924a9bfb26e2d8e8931d79fd9c6505725c2c7993a80abbec178e26eea96_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:25bdab21fc01b49d20c377554a2b1bd654b0b4bc6ef14f9ae456e6f92046a958_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:a036bcc5b69584de891a4e27bc9343af3c8650750be15c9afc5c0bd4ec7da300_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:b1910d27bbccf54c4c1bca8729c350d118ffae022f8b27f4c285979487f98eba_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:2638f7e6d272a198001b9826c1a36fb29729f948e6f6d8f06cd8f29deb1841ba_s390x as a component of Red Hat OpenShift Container Platform 4.21
- +161 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:44268
- externalhttps://access.redhat.com/security/cve/CVE-2026-13149
- externalhttps://access.redhat.com/security/cve/CVE-2026-13676
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_44268.json