Red Hat Security Advisory: OpenShift Container Platform 4.19.42 bug fix and security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-49332 — openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on WSGI/PHP upstreams CVE-2026-49978 — dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:737a126f7d4a611086acfe07d67bad263ba273c03532742d14037add8e7733b0_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:8a53bc79e4649d2b05126126775b07a2bb2f645bcf7b9ab825bb394f2a61ec90_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:cb18d72fa5f800cdebd3ca0b7df1851021f20c629660218ebd80aa5a5acc75da_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:cc0b7e82e38114d0e9fd40389d1125fd4e56fb0a2cd5debbe8a8059b1aef2480_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:2cfb57df5f8f318ce6ae997e7301d9528083baeb4721293f0c9fc282d5638dc8_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:52e1c5f2502c84bb6ca6292611260d8db54399ccf80e19b29c2e8403b7471792_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:56fc8fd77301ed8164e49512cbccc17e0c59305050ac39cde2341bd6bc2b1082_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:a7e0e25278af29d3caa531185d652eacc025bc67df9d828cfa659eb8362201c4_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:5e92c8b2e8aad045f9ba539e8fce36c273b0221e207d8392b00a44fe386eef39_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:6f03b8895395569cc518b3bc458d8fec1f815c457ba2ef248781db3bfccc13d7_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:978d5cbe961e05d9162cc5d64089d33a99133837a5ec11cb2fac21a781c3dd34_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:d5ca7004b457a3d2b53fecd1fbd677e8256cc54b7fd801931a04dc4d56150817_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:52d7fdfdbccc0c49b8180da6629a2b6c8035e8f91094a77703769bd1eae1df34_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:78f10b8fe9ef8dc9aec02600a14525bc3d33de190a744af6a84d6da3b68622ba_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:98d2967f67498f836485c7a1fa25fc938c6618b5b6367123b6f05e0b3593af56_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:beac77754c8f1186e6fa899d1bb2aa44bacfff2f44f37269052fc883fb499a01_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0d1bf566c12be7f3527599ea25f9e8030ba40a0c91f4102a78bdd5d6f136bb9b_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:32e04cde0980f26bcb60432a09498d30d13193dfeaeb1e6c23d2232b88e5df62_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:69375dd54c410c320822a009a0e4dbb4ede5e17887a6a1963b125a7a582e63db_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:75a10444501db8b272b474a6aab26ae0699a0a0edd253cf9a205e1496205f9df_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:8569899c4e4a9b8b30ca7d873ba21cce1c8ae1e0637f9738e635b0032c555f3b_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:d879261376b4d6364fbdf5dc1b3e7c1cdeeee58632fcbe2ee5a046771d0fbfe5_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:e3c944a73fba48777a8c0f63acaa5ace0517388b49e231547a5d78ccc4b8fca3_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f2ea87659432694e0dbdd5d6d63f4f1012c314599429b1320d2aa670c2b7e635_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:31ab4ee282a0e98c061be7f05a7b0af3d4c33ae23ea934a6ce6d067ba162defd_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:9ddf10163fc8811992a5294248491cad2112f3d4ed63569cfd75338edb2c5ffe_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:a5b99d850c5ecdac808edd61b01656f4fe18c5d97d4d2e963db15478d9d7f0c7_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d9a5493f7ccb96d53a39644f6c44a45c4e9e4944b329c851b24e324725d9b18b_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:2432a8770e60856a33ca77e9892764da1f7f613e5cf12da44b85077d0ed6051d_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:b49da1132d65409000515366b70f5bacac7d2f546f58cf9347edf994e9bf2577 (For s390x architecture) The image digest is sha256:d6c03879850fe79f6d2f55b066b7fe3763718de6bda25691955ee7b31320fa2b (For ppc64le architecture) The image digest is sha256:851ce5cce8c01ed5ac21ca7dd0e846c74c4debff6b5176752f69ce825a8f9054 (For aarch64 architecture) The image digest is sha256:dee7f349470d3c6357596a28700938114913b515534aceb85bab33615c26726c All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended. Workaround: Upstream application hardening: validate X-Forwarded-User against the expected session identity. Reject requests where identity headers do not match the authenticated session.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:51007
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/cve/CVE-2026-49332
- externalhttps://access.redhat.com/security/cve/CVE-2026-49978
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_51007.json