RHSA-2026:51008HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.19.42 security and extras update

Published
August 12, 2026
Last Modified
August 12, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity

🎯 Affected products186

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:8593834636ce7a8ca8ba81cd0ab47e4131a0f3eeaebef4d4e16c67f5e553712d_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:8753c85ebece086d437e92c771facac97e4bfab3e90bfd5e8749479350891760_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:8a4d481b7d7f77006dc66c4b7d55d727c9ec3c58d3b0b7e751810eabbe6c54d4_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:f084b372cd780fc484c4d5184b848b7857509fcec32bb305f551d86c2021835d_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:554042953230d52c9cb6aa0c69ced24cb65c699d3d07540b32bc305f6e93e79e_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:b8dafd7742c1fe5f33910ca27325a93c98dc3cbaa93ac3ca599be296b2959d50_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:d0817cc3b2847c0ccdc9844c60816c527c75d3bd86285d3e0ed2d69abe4088d3_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:eb559409163c47e1b0027fb593e25b15a426cb92b41fc9d3fc7cfd0e9bab2dd4_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:3550ef9ffb22aafdbd4994d963c8e7e567170da781d6105ba2e8e4d1ebfb5a68_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:5572bdfc357859f1d8729b55d4ce2846f798f12f51722641eee604de33ddbd2c_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:6aa47ff7b5ff8923e4679bbb4bbc4b684cca14870127a526458a2b1fab7f32af_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:70a4ae47bdc5550a03cfaea0f0974a3d9d0d6b79410987f94b93add237001825_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:5fe444d904f20ab64a1de60f618ef8023451e5f368a8e98b62104f6bafbadc5b_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:a0a33da946c7774fcca56bb6b21e77e54c93436f76071429974a094319104b7f_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:c633eab153d41723efa0724d4bbcbc17c2c720ea4d0b0e839c2fee07e106273c_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:fac76273a787ab2a57b84d19685a4f23d879f01d1b84151441231ba7da2f4061_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:24f3a1e7f6696ab80aa8ae29f434af5bc8d5c3e39d6cc1b837a4315662ebbdd1_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:7a25e911051de8d5a923e35e872a45aeedfd97ddeb784b6685284efe89c57063_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:a29d2f2c9f01011974878cda49de6bbbdbebb0a5c3b1e86ce3c3f30b3b9f65ac_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:bdba4479ead924125f415b8f6be1edca603d3fbe3038c58f7694693b029817d2_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:2eb559b39a1d5700472428fbf875234dbb3a7bed1fd93e0532a476f18fbd9ad7_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:65e3426393a43170e4cd2d12452ac46ffa95fed5515bc145e27d0f6715bbd75e_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:898c33c234d5960b764271e5abcf9964a5a5bd8ff8f18f421093bba531abef61_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:b5bb6c385cbfb2f2f3e01fb056478de3a993e168198cb17a3b3c251efa164a73_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:0eb550a1313190ba02d2aa980f04ded2c31c71c6b1c4600aad193603581c7d45_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:2237ad87a1b034f02d95e43e95566755f94b90fcae558ee8896b6639416a130e_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:a1b07c3ee5ddccbc7692ae2c324365d13b478d6a8e96187b8a1f86d76007bbd6_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:b713dbbf5a7ba1be2ef6830ea8b288eb5808e26c0aea232b7d7dd468447678f8_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:689bbc5e404d1df9bde15bcb868c07ab257adb5bb90340d5123c29d47d1f0c00_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • +156 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available.

🔗 References (4)