RHSA-2026:48670CriticalCVSS 9.4

Red Hat Security Advisory: OpenShift Container Platform 4.21.27 bug fix and security update

Published
August 4, 2026
Last Modified
August 19, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2026-16242 — hypershift: Konnectivity proxy-server accepts agent connections without validating client certificates CVE-2026-42033 — axios: Axios: HTTP Transport Hijacking via Prototype Pollution CVE-2026-42039 — axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data CVE-2026-42043 — axios: Axios: NO_PROXY bypass via crafted URL CVE-2026-49978 — dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:2194af59a30ba6f4a78d96f4a0a7c5270f9686cbea34d9a1e1f440ea1afb113f_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:663796b897c5031c5c48ae554bec0318e8ad1be8abee72495a4baa0761252ced_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:8bb5659f3d5e6fdfde4be9c85cbfb5fda2d22644e1a27e83b5239c98172ec51d_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:9eb58a438e0fdadddaacb99646f00688a28727d497692dd6b99f378ae45946d1_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:3ba6f8a2080c7a47177da8b5831b4d3ab4fe115681cb0b0cc630a9b946782439_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:498f15c616d1e3abbefaefaa9e5a7b116ef88c0c3a00fe75e25723dba79f53f5_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:b56c0a19764a912510bfba04046362da0b96ecdcf2af359d7cebbfe791365627_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d5926f233078fc76fea787bf990ace937829922b8cf7594f4a4df7ae86385260_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:49a4dd1416acc8eadea011eef26b07d7da4e90ecee958965b2883eba6cd47f37_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:7c19fce5621afd340d6184db29faf272c12b49877ff305b9ee266a675405c164_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:7f6994770040666f8c66a4888a8aa7cef6e4734c96cca18b4be453425da536e5_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:8052e05c93bdd138cf19fa290a9d7edb37e0081e54e25f399de66c7e544c1b1e_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:2e08e2b10c42f3209b53c28f69ca13a80a813caf855e5ddfb5341755a3f56419_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:3541824c5f0398cf4fcc26f80cd38c6a4ffd7a1d2150f1b4c485269ed03f68a6_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d040c501c0a1ceda1ab60c58f2fbf4eb99b83a9539982f81abfd82d97b0ea2d4_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:e39f4577595b4351b7ee2ed2bbca352ad59306c02088be444af37536065632dc_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:07d83c7fe00d7dc917b4beed20d1ceab67d73a398b98bc5050de620281773246_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0b67449fa1ba56fcf7768c776bccb6647929ddd1646e0a91e2a85aeefc83f376_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:3f6b98dbbd4436d93d4924f6f5c732e7ee194496b0a150efef79a9322c8e34c9_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:9577495b0e81e1126049f3cf02e21f33601015b0a7be16a2e9c13338efd3d8f4_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:03d11b8316f03befdd2cc9b7ecca1ac339ff0a6056c8c59660959af04753840d_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:36343f8d12f235af463e58785c4087d13385eb3b7969c4ec76d2c170ef5da44a_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:4f1b87b3a4b296d5f61e7ef9a9692f37d3a6aed3f2d2aef8d26aa83571e2d98e_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:7c9e3b6703d1f1186011b90ad4840d4acafde845b7ce05bd3f184991e45ac887_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:253a91b2de8c22c926c5431e89c04f033b00cff10771a41c895ca55045bcabb0_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:5f5a30793f44e712a51eaf61692a02ae19bfca868dae372ba5182b41acea63b4_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:7cf94d5c91c2bc5143e8678d3b9581fdb874d0980ae30fce8c0e262bf36c2c57_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:af2c4223483c747cc449c1ba6f6b47b68a5a787117af2c1c3af53001ccd1df87_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:51a291ff367fe6bf76108efbc27c2c6d03632dfe248441c2a63a55529e73de5a_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:aaeee8b27a23a8a8923ca2f37dfeabac3c716b4fbecb249f91d0b377323c87b1 (For s390x architecture) The image digest is sha256:9ba1339f035fc9331e5165e37bce45525c7e30b4e1fa20492468a001e108970f (For ppc64le architecture) The image digest is sha256:0488e8a0d59828d11f3447174dcbe68b81a76d1d1e30dcd0640222b0759fd57d (For aarch64 architecture) The image digest is sha256:7e9da63ad9c292e8f3d586e9c07d59f895ca80e3d42df83ebd5397e52f075fca All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Until an update that configures Konnectivity agent authentication is applied, restrict network access to the Konnectivity cluster (agent) endpoint so that only trusted worker networks can reach it. For NodePort or LoadBalancer publishing, limit ingress to port 8091 to worker node subnet ranges. For Route-based publishing, restrict access to the Konnectivity route to trusted networks where possible. These controls reduce the chance that an unauthenticated attacker can reach the agent listener; they do not replace proper agent client-certificate (or token) authentication.

🔗 References (8)