Red Hat Security Advisory: OpenShift Container Platform 4.18.51 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators CVE-2026-16242 — hypershift: Konnectivity proxy-server accepts agent connections without validating client certificates CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-40895 — follow-redirects: follow-redirects: Information disclosure via cross-domain redirects CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint
🎯 Affected products41
- Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:0866eb3d44068199d2511abb8d1ca782dd61dd66b13a6d0b72dbc727c2331ded_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:14580d43056d87cf84a2ce5f2fc7fa5ad3dd47745e53f431bff1203db20a7b77_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:5ee44d986d12f117a4b78bdef0e015e9dea12e8d80a6d981c38934cf7587a36b_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:65ee346de74922a3d3a15d8fdda96809bfdc7fedb332fd3be6b2bf7f0471e622_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-cloud-credential-rhel9-operator@sha256:481789c068fba9b6bd657a2e193b33d6c4fb5c6cff0d0f63a7e55986e56d0eba_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-cloud-credential-rhel9-operator@sha256:7414e957f7abbccb77a45b4bddcfc22b3b6d72077cc995226bc8874d5ae299f0_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-cloud-credential-rhel9-operator@sha256:a9df2055d0d970ba40f5b2ed3cbf8a8418b60090fed5858a6cbce116e70917ae_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-cloud-credential-rhel9-operator@sha256:e2033ab2cd2e3f98576c6cfea20297829adf40d3f7f50b6eac1a1a66e3295f4c_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:19806d3ba170fa6a9aaaf83b1c25dde1d20e7a07061dc04e931b37ce81996e3a_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:4ae0174eec7cff35f2ae0926d28975ad4d2f303c4c3259fc5e2b9deea91699ad_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:5438bb301dc7d71c1fc945bcfb0e966e0a96d38fc0a6ddb0fd40da43aa4a7282_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:ef993089bcd3530c78589e14a11b8214bc98d444553156b59ea1fb2395550f6b_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-console-rhel9@sha256:417a162d360d2da6bb1aec58f44a3400482fcaa9c535929e62676c1834524ead_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-console-rhel9@sha256:44230e060120cd247e24f22e21b03423ac13b4f41f6eb081172f9be06f25c584_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-console-rhel9@sha256:68d192c8b0b1fe78c82e9640cb734ac14b2321a8c710f88ac06bb87892fb2313_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-console-rhel9@sha256:f18eef7c2dd973425a667f993bd8c3ed5b06acf098276d56d4840da210b11b2e_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-hypershift-rhel9@sha256:0d1c736eb20d065e6c48a12902c87396f8babdea65207a838301dad0937c7e2e_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-hypershift-rhel9@sha256:303de185a374a7d3a22eec6d10e1c8a178f68a33d0573b195fa8d9b40d67becc_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-hypershift-rhel9@sha256:84153090a97f4d2fd7c9136a40cf98d5bbc86acf9ae978d8ae17a731284d5aaf_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-hypershift-rhel9@sha256:cdea7b9a3878b0f1b087fc19587e91f6c35a1325e09efe411985f35c7af7a3d4_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:3df178f2cdc1b46a0fb728b1ce65689052c1728cfacadd4ad95383017a625202_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-ironic-machine-os-downloader-rhel9@sha256:6b500dcb1d4dd390820c45b6c53cf5edc822e49dacd525fb4530ce904c09d8f1_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-ironic-rhel9@sha256:683cd49dfc9a43c876db6cf94b9f7e417cee3f7bc0adbd320aa0cb924b817732_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-ironic-rhel9@sha256:9a59698fa26507d2dac42c9d5add511fcb224a25bbc2b8d6c24f443ee8c28410_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-machine-config-rhel9-operator@sha256:1833524376750ff3cf91d4e95eb6670180428c4d936520002a6cf27ecde777f1_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-machine-config-rhel9-operator@sha256:57686feccedbbb655b36d5231aa69f47b0d77ff9c04203bb78218feb0367585e_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-machine-config-rhel9-operator@sha256:749150b69ff000b5f45a5c169ef58c2c67541f1f5caba7539a2e8e133abb122c_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-machine-config-rhel9-operator@sha256:a3085627a26e2e6c6be38a3a6757523da4da6130a8517e6fc37076df6ee101f7_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-monitoring-plugin-rhel9@sha256:134def2853a731f3d51183c2efbd3d475cf64156dd3fec97cf84a2ff46f3297e_s390x as a component of Red Hat OpenShift Container Platform 4.18
- +11 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:0bf08effa1f11a7afd1c21574a1d25b4004b12511fe790c651162074e48e06fe (For s390x architecture) The image digest is sha256:40eaec63a2f8e89c28026a764898b25620654f17fe2ccfc1cdd010762e1d8246 (For ppc64le architecture) The image digest is sha256:09115b927b43a0327698fd02fc9d87f3999966bbd5f41bdeffccaabb84a2fac9 (For aarch64 architecture) The image digest is sha256:44a25bbf10e6796842df3ff64d13e27ff5a942850eef28c1d3e0fb2bedf2b366 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Until an update that configures Konnectivity agent authentication is applied, restrict network access to the Konnectivity cluster (agent) endpoint so that only trusted worker networks can reach it. For NodePort or LoadBalancer publishing, limit ingress to port 8091 to worker node subnet ranges. For Route-based publishing, restrict access to the Konnectivity route to trusted networks where possible. These controls reduce the chance that an unauthenticated attacker can reach the agent listener; they do not replace proper agent client-certificate (or token) authentication. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:48699
- externalhttps://access.redhat.com/security/cve/CVE-2026-16242
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-40895
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/cve/CVE-2026-4800
- externalhttps://access.redhat.com/security/cve/CVE-2026-9277
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_48699.json