RHSA-2026:51014HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.18.52 security and extras update

Published
August 12, 2026
Last Modified
August 12, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:51b58e36e8e1f982a1a7f8119e14d811e66f32c2da01e9d37b8f473483335452_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:c1b16acf19b01df9fa7b1144b9c87982ebcf4852e7cf9ce3cd9edd927bf0da36_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:c46dc0774dc175ec9d4b66f33c1ae06aa54fc163fdfda9a598c2cda6a51d0cc0_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:d8df87ec77c46553df12678178d237fda15f2acded0746f54fd10166734de3e5_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:38453b35ca3b1948f852060aec034705dfbfd4321b9e43c40e7fd15bb6e704fb_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:64feb14130c303c60db94d39c93eeca9d08ac9b7de75e16a74dce539526bce17_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:a5880834f468df46681d05e9ee797e621a2fd0250ce8cbabb10aa0764aaab315_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:adb974f35bf1656a894c9ca1f4571d420c6301b31704355221446f0e05fd0087_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:065503560ed4671957b25220695859a26d1cba66a5c1b8ebeae1861b6a064b67_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:1cda42f279f32ac517cf551544c04ae61b2a44e00bb6de70e1d163928b6dbaee_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:4f1f32fd4ec498c7eaca1c0f28571e736a602028c0b24b4a9751514f4d70a5e2_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:f6ff6171acd153168e792ce26cfcf5929653f55bdf794b90bfd1bac94b15aa4b_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:03a25b13bc0ec23d836ea7ce4c2574b2fcd643eff50b45fae752320acee8d6fb_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:500b7724ed538de18f337262b072d6ec0a0ce5a59ff5ba471c7bb39710ef83e0_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:526da9a4b6df6d34a145b0dda648807d2287466df412bb39f816adaaa6bc8205_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:a6293fbb188552c92bd8ec9223aa03afe5bd5e919dc7bf19b4a025f81ffc7578_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:18c31cd59d612c1a183894fd619a122186e068463dc8a61864c2bb3948437493_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:5cc884885d1a2d46effdd0756e760a1e2e3ad4a8cce16cadfb1ace67ae9821db_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:808d9215ab5797ff725a18c469179d93c1aa2ed99265ce3b2333815e8eb50970_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:c577e4930c7cf7500ebce7e2848a5e754ec9ee1e510dffddb32df67a9d572425_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:0e7a2a843d6f186ff5a4855a93034e402a9990a648ecb05fea90de09951b73c3_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:27080d8f0ab2578a83263cac74e1c441905a0f65128fab476fae6001b48ff340_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:ab923c4eefee2ed0fa0a93e34f45e57329a31bc2a591d2ec9085c0d95beeddae_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:d2afc188bca8c336c84b53487ce3f43ab6bdeae74609f9061610cf2786ef8b02_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:87c32f57d3112db771417cefddf4bc5110faddbf70abe1e82ea4dc54c5a84a2b_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:9915f69b58792bb3f3d155f98801ca625f486b27e4977fdf2c3a290f9224a8db_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:a6b4cca2a606198eb5f3450004473ab9c64fc6773b9d97b4ec55447ea592dc87_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:f6deeaf72ef0eb893a473503c2d37f98fc0bb5d2b9037577d3dfbe9dde542140_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:090d3578865eea172c7829597d9a54ce20280ebc573554f95ed40122fe589cf2_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • +170 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available.

🔗 References (4)