RHSA-2026:50758CriticalCVSS 9.4

Red Hat Security Advisory: OpenShift Container Platform 4.16.68 bug fix and security update

Published
August 12, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization CVE-2026-16242 — hypershift: Konnectivity proxy-server accepts agent connections without validating client certificates CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-49332 — openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on WSGI/PHP upstreams

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:196b00a9e8227b3facdf7cce04554bd03e72e41a31ede469a69c21c90266d433_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:309c4786102b678d2ab5270b7d80bf9c2cc5c7cef1f27350b5a89dac23a07ca1_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:78b40c709909df1ce9ffbd8add390bb248415d3cf173fae0ee31b188e4d6b9ab_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:f9319d6dfad74f74f4b50bb534d222c9eb593ab2385cebc8abac2298aeb3e674_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:5e5f3b47d44721eac435282313862e4b5df2f088429a958d97c49749208301f4_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:a15d2d0649288e1951b2ba83d20e969c323ffd5366cb58c5fa538360d3f367d1_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:cae47626cc69db9f7c0de0fd56020b78c2b7f4f9721f26646ab6877db0c5e696_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:e902fca4b7e1c550ad012c916b69a56f0767f70086aee45e2f403d43fb126bfd_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:1763fd23db6659378f121f0e87373c0610cb5f35ac944b761eead9e591125c36_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:48561b603b440715174c0e09a9a688269db1e43bf54b0353685c0d1f41d40f40_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:bf00f82b254c41b229d6014e37568738c9b36227e82f9b8194dd6f05b7004764_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:c2e60db2aacadf99acd32cda92525083ed20c368c5761043f2b46255d5ec1d39_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:1fb5011427343bbd5d85614bf5f90b349e1efc9b8603a6f4285d95851c8c5681_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:7f02d2c0794358457d38700806fe1ea1ccad9c9981b3f5e71b172802d8eec512_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:a86efbd31c5f9ea10170611bc546cf3313bfbdfd26f4237f5c24df366a383c22_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ab4155305d47fa5601129a696a647f2a6058fa686ab87b0a510aef007673394f_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:89ac029846dfab58f0824fe9e59ad38cb8ef60c91abdee9bbd1f40451d667ac9_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:a5cb369d63761b5197afea99db7960d7e09f11d52568af3a8a9492e697799180_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ad5e792492bdceea2f1348b0cfa4f2003a800f048d5ef1d5c2f099be1b448b95_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:cbae7d76b1f7aa3de5e98c5238823c006cd351225dd87375bad41edab86a67d1_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:55d339bec0cf49214c96313a34ce6296cc28a45ac492afbaf6c50521f4410576_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:856690cb1c81699cb6b438cc6685cc79a353c3755c4eadce2cbec15fc95a9160_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:974630f4156791a3f9a00a0f2d6c7b6ab9c06c990d49781edc018fa544bcb455_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:deda757b5e87e733e8fea7190bef11c035749c4e5c56c2ded93539cccdd465ef_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:15cb16e63f9dd5bedd9cab47d13e0a53ab3ec770b7f9a387c62b58d4cd2988bb_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:b4502e0dbe753a113b27aa8d40e9aeefba78c7f6738c09e50f53ff134d17de99_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:f7d1906567ccc5ed852fe7f80466b8914395c1715715efcbc883a427e927276f_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:fed55320caf04fea7dbc5c1e4c8a93968fc1309efbae82c6d4dee4821163a545_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:0c676f00b1551e31d34ef993cf19036f1673fe839c0c0da1a2d9328493e4970c_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:70219bcd3394cbce5e1704f668b4d92a21b26fa044dadc44f3a6726e861f9579 (For s390x architecture) The image digest is sha256:223f9060ad64c681e17e85527ea7bfa69c8e05ee879b5c0190ef339e0cc2babf (For ppc64le architecture) The image digest is sha256:b9609a0cd783bc3a2a214f049da8ebb8dea47c5378ec3cee2c0884114ed61e51 (For aarch64 architecture) The image digest is sha256:0ddd5462cfbde5476a104136998987c54ae7a936e5b769da2c2bbf688a20e153 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Until an update that configures Konnectivity agent authentication is applied, restrict network access to the Konnectivity cluster (agent) endpoint so that only trusted worker networks can reach it. For NodePort or LoadBalancer publishing, limit ingress to port 8091 to worker node subnet ranges. For Route-based publishing, restrict access to the Konnectivity route to trusted networks where possible. These controls reduce the chance that an unauthenticated attacker can reach the agent listener; they do not replace proper agent client-certificate (or token) authentication. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Upstream application hardening: validate X-Forwarded-User against the expected session identity. Reject requests where identity headers do not match the authenticated session.

🔗 References (8)