RHSA-2026:51022HighCVSS 8.5

Red Hat Security Advisory: OpenShift Container Platform 4.20.33 bug fix and security update

Published
August 11, 2026
Last Modified
August 19, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-49332 — openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on WSGI/PHP upstreams

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:0b5a955881d2010fe9e996b5ff2a1b4e3e6e5a5b4181c27da40e8298ba0836e6_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:29953ef8c948b25699ac333a9e225287620ed73263f9ae81ad6173ed1deb44e6_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:96ef4cb21f0563fe2358d4b90f197543da9b09004cc08c67ece4855db1871277_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:b2bb5243b9b9ff094d013fbae06b4ddcb3ed9994c41982a3d51610a6ba7969d8_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:012652f5e3f7f28508dffcc074aca6a439d053d532a95fa756de306d36cd2ffa_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:53920d2b17570615a1e7293a0fab013755542e4d25a3e74d2d2b88a0b8ce4ef6_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:7bad6f4cd7a32b27252844d566ac98d90a478279284e4c1c1a88ee51c4e292d4_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:f318e2fe776d68adfec92e25b505ab6f37a3f033265c951046207918494f29cf_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:2645d41d2f50b1b7378adb0b156f8607908d2263693683f4dfbc7828ea6e4316_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:590f4579c527451f087d7651b5109964dbd36eb60794b6fd39544e3c881227b9_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:9c3a6ebc1a1f6fc745bc2658a1f54ba732868036420765919f4a45fff74057fa_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:a2eba6c2b3e8edd58885ae70ed6c33048290ddfb97723761d1bf827b82cbf2a6_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:0e0717382636927251dff1da1d47ab8bab37680b211cafa63f884cbaa9985df1_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:4280a032ea05911bd907281289123784392d626e7fce031d86673be15550d820_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:a7fb79b7b782e43464319a0e16b130835bdac912782fc08399ed6b3e33a34718_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:fdc46fdd54117e194025309221d41400c37cab8c8332c831f328cf3cb1da06ef_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:3fccb5cc051b671cb5ab932b5a6cb464302424c0171fad576a8e7699242eed3c_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:418f8f439f392a0810dc190038d93774730e51fd57b93fe73086f545f9bba2ad_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:4929b67505241dffeae8ef30937498f58ef2d6ec49aa033cc6bffbcd6636a6ee_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:79bbdb3468e47064551095c26406b155133ac7ee391af55e8c62a78c5e185c08_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:3f6d370c4ea972ad11a2609876d77cd1d9096fa6553b21d0556a85927ddb1fef_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:62bfe7ea323ea5e00a40442d2d2281eeed19a9de3d844fcc3e579e62dd3553b5_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:70955fe3f4fdb140db27e36912374761e7cd5a65cc23c96989d2037550819125_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:fb5ce003b2d23d03c2b584254ce5d12eab472387d55712932090166efa9514f0_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:142d7456cc0c98f33bfc64758ee4f303dc47a0308b0201a6fbf39e599f703b2d_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:37785c2f24383cfb01700ce4f874983e9d569247cc575f02cd68e5162421c114_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:567479d6c6246c769968206aeaa53789b9375ede4862b810333a9db6730f4f37_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:991dea8ffd7da176a6b18f94cfce0a6f300bb5f0d45a55022ee883784f6bc03c_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:4fe27ac6542b9d2cce9a59c5f19d05f33aaa87e676d5ea37740ea29a4636b8a9_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.20 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:237dafe3f2d26e355372001ae957748211bd4bae8249b48fe2624159cfdc8265 (For s390x architecture) The image digest is sha256:dfa5d518ba54d04bfd049286d039c66a1b8e3fad452cec914310c468c5aa9d40 (For ppc64le architecture) The image digest is sha256:cb467e5eb2c7597dd7fae4f575ef975d9bf112acaa321288bee0e9f991fd20c6 (For aarch64 architecture) The image digest is sha256:e85ca15632d59a6802cf89afb80a1aab7126d69271b94ab02a2d36eef72659f0 All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended. Workaround: Upstream application hardening: validate X-Forwarded-User against the expected session identity. Reject requests where identity headers do not match the authenticated session.

🔗 References (5)