Red Hat Security Advisory: OpenShift Container Platform 4.20.32 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-16242 — hypershift: Konnectivity proxy-server accepts agent connections without validating client certificates CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-49978 — dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:07cd95f8abb1e9a677ec5b307579fbb466f2d9b2bcefed4d41a86df457da905f_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:8bb80b133d81de77a8a2fd8a01efb472473e94da606589ff6a88017992ab008b_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:e8a456af96a409929ded97b49a0f3bc7001ba496472348a89bab29b57fb75c3a_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:fbb7370c0bf48d8d5efe2dd8d8687d24f4c2831e191c730147f5b9a16ffa17b4_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:241986ce4fa5333ef6231ddc8e83448d968bc9d732e5b39ea34da7f1c00c64c8_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:6ef4f5f1e63e5be279e89713d37df4d6a0799b5099b009127d5eb208c0783566_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:9715ecde3242e3da6c949fc9b69a098fd5c59bd79e118806c8927b9c70156d58_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:c41b95a352197647ea5c140af6a2cb4561df161238606f9781a5a1c02c409ef9_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:8cb6fd75b0b9437263aa4ed04033c9fec665cac5d044921205f8d877d1e1f243_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:a0a0c539f87bf1f2881e26e9fb8a151d9997d271f5931a7cd89d59210eff4bb8_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:a69a932cecb0b8246fd6faa94024d9e53ea0239eb50d4f6dd29259cbd2731d7b_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:a8a6eca92ff5305dfc5cb269ec6923af8ff85c8468d3c3093d6e338f8c031aa5_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:147f7e4c504355e3db58d6d478c5bc56c7dbdf47509e02e2d942af1c34e98dcb_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:548d1fca34bc6c14f9d008033569a507435294ce841febb42b74f5875d17e71e_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b5d01186390013284b109952a484e0ead3b7e35f38f086f49ae01d7f1e91e7d0_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:bfdc5fd9425cf5e211fb456466a83fa4c6f173778fcf126bd63bbf7f1d468983_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:1448d33dce46efdfbbaea83cfc3514ef3d02ca2726e0c78b7d1082459a1569b6_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:745f3e98fd82600edeb9d3eba6443886808ae775ac02bbc1002ee27c6ecd1f1e_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:e01dc1352770028fc23c0309cc4da2730bb689e1ff0226832e55c3b38874467b_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:faa03b1075dff87429329b239bd29d8dee28b5d13c2584c5c3c5689713a557e5_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:50f2a6a2a7bf089975c7b0c60b6ad4898a8e2e32d6da219626a8e68fc630187d_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:67210dc40ac21a3bd74fda66779bef48010e59ff381d87823df73a72da265cef_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:af7d47ba3b0bcf354f33b4249756f902d59c3c088363bad6de71e07192899959_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:c67e1e294fde7b39776a00fcd34914e80e4dcfdedbd0ca78ac3d9c66c1af5fe1_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:65adf590a33afb79b0c1df0bfb2c4c315c18e9caed8cacafc229b1e1d92f6142_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:b8142efc68fb403ff830a87ad3cb17deb9fda69bc765585c640bc6076c74710c_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:bc3657b3b5c232fd52d33a66becea0af52bf45992d7f673614649384f01c6c7c_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:dee2eb2753706989921e15fc186b717ecd39c9f9f51a7b7ceae689f5d8fecb9f_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:054e07f167544836b3cd06ab6849533b47373e4e5389d51be069aaeb7528ce35_s390x as a component of Red Hat OpenShift Container Platform 4.20
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.20 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:d03909e954e9a6d24900809750bd39f5f69d8a9e480eec97d481b9977c430d4d (For s390x architecture) The image digest is sha256:e6f55f9d85db6b096864b17c4a589b82b41a38e2b817651d61c7deaae09f9995 (For ppc64le architecture) The image digest is sha256:6523a0a01258f0d0862d14fd77333fa475abfd8559fdc3ff3225b9b64fc9c31d (For aarch64 architecture) The image digest is sha256:907f840289ef117890d19775bdde1ca03111a40e986824b12457a865929e91b9 All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Until an update that configures Konnectivity agent authentication is applied, restrict network access to the Konnectivity cluster (agent) endpoint so that only trusted worker networks can reach it. For NodePort or LoadBalancer publishing, limit ingress to port 8091 to worker node subnet ranges. For Route-based publishing, restrict access to the Konnectivity route to trusted networks where possible. These controls reduce the chance that an unauthenticated attacker can reach the agent listener; they do not replace proper agent client-certificate (or token) authentication. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:48676
- externalhttps://access.redhat.com/security/cve/CVE-2026-16242
- externalhttps://access.redhat.com/security/cve/CVE-2026-34986
- externalhttps://access.redhat.com/security/cve/CVE-2026-49978
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_48676.json