Red Hat Security Advisory: OpenShift Container Platform 4.22.9 bug fix and security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2026-9595 — webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-43003 — ironic-python-agent: OpenStack ironic-python-agent: Arbitrary code execution via malicious image CVE-2026-44918 — openstack-ironic: Prevent rehoming resources to nodes with different owner CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-48801 — linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability CVE-2026-49332 — openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on WSGI/PHP upstreams
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:6c676d797d0a129953436be94d08fc6a1b9b6ed3f9f23e241663ca9e316cbc76_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:80992183e47abc965680a09d6773c6fd6ee106b6f9ebac545c23ddf97ef524b8_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:96a5f156681ca057fc6d26851abd7ac8c96314481652386001fb016a0cd9a6ab_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:f187e0b28a3ee868b66635b26fc51ff7d82e1d54897f50020032f1ac1d5b39c3_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:2cc5cf25f17925609c35a2ad2fa060f7a96c75d5ecbf7b74c1bc0814b5c72775_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:2f1e0b4b05f46b7d6f9ab39807ea4f6d48bc127b82b2c347e03c23de88af159b_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:7ad951dc78682502ea7710ab5a4370ae5f9db17f04ded6a6cc1770dd587562b8_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:a01b714cee330495c1e7a09c2890e1cb6746d1707b4c55288cb1e63ab77a2821_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:5a3dec36518be6dee4f2cdccc0f7a9fdb2426774f0dc76851748f4acb95cda20_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:a6ad69af6343effb5b5c7277853653d686e01c3667d94933800da9bc26b8cc48_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:cda7b537c6d304735feb70e5fefee7e10fa33c0f3c42035e6ce477a7707dd382_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:e314a920219cb4c4837c35c7416278a32ec23be5158487b0bff5658d6b67751d_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:7e2bf106b831edba30c7cb047732f86d37b5237cb43a17f2a87bbb0c09bbd175_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:b0cadef9d1f855140633a6db2c0d1db7b7531f550fb931c0dd8741b4572248c5_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:dd61891a9340ebbb9eb30f7371d094bfc4d885b10256578b30e99bc7b3857685_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:e740f2f50ddf11ddccfcfb2ec9485b56c3d06d9b81af10ad8d8ef125cf67ad67_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:2c7b0f4a79f2b2df1365a7b4335cb162ba98a405f17b1fa8ddf541bfa84ffd5c_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:6aa0ee4bc44574f1c8e4bd479ffc3606645eb911e0222e344c7ce68e530cba90_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:6ebbf2cd1c5b2035932c88a770a62116a985b0275df4b89ba07555f12211edc8_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:87f1be5f15dbb0583a620db3287effa928164a41f95522d2a00f1baa5ced1a81_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:915067ea0207e86a1dba71fce35a7f5809a15065852a644f7862efbe2395e2b4_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:b6f0a6de8dc3765725ff9785b9401a79f101d72775f4191196b4582bd4ccd19a_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:d1a16921fc63ffdf2e125578bb68d9a1b025c2812c1fe0d22cbbe550c562da2c_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:f75db69d531feccdc49ff1d2a8299a4bb292c6c54b4222a2ae9888d06abd4fe0_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:324b14994c1434d901e58225a18d7e4ffa09fb5f1b4a72e601bf10d4cd08bddf_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:cae2e068131febec3709dc8bf7ad93e5dc4e9577068da81f500399ccd9fae23a_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:e008ed77716604cd877a4c8a4ade6937599c6c15ca28985c75222fe2c3ceeb4d_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f3855f3a8629f12278a27d8f1b3e22afc1829155de9b22a37da8fca255a3af50_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:4aba8db903483d64fab57c7a5469d1db7464c6402303039c1b1edb133bbb111b_s390x as a component of Red Hat OpenShift Container Platform 4.22
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.22 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:fe1fae8677554f0091de1df21d612d33163b23479880a9c7c88e9fe066348266 (For s390x architecture) The image digest is sha256:b6cd23220a4dbedc3fb945d4e167453a5438e1f590b21619bc6ff5632f9019df (For ppc64le architecture) The image digest is sha256:3d9b966d4c72653546c76d87f0e28a2f322a2df2f37df3eb290dbfba000de56a (For aarch64 architecture) The image digest is sha256:08809dc377db79b34fea3d44c2373c1c8348742296a8b6b77cf5a44897fdb781 All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, users should avoid configuring `webpack-dev-server` with a broad proxy context (e.g., `/`) when WebSocket forwarding (`ws: true`) is enabled. Instead, define specific paths for the proxy context. Alternatively, disable WebSocket forwarding by omitting `ws: true` from the proxy entry if WebSocket functionality is not required for the proxy target. This configuration change may require restarting the `webpack-dev-server` instance to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Operators who are concerned they may have had this occur are encouraged to perform a basic audit of node configuration, for instance, ensuring the expected number of volume targets and volume connectors are present. Operators can also use the provided ironic-status upgrade check to identify misconfigured nodes. Workaround: Upstream application hardening: validate X-Forwarded-User against the expected session identity. Reject requests where identity headers do not match the authenticated session.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:51038
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-43003
- externalhttps://access.redhat.com/security/cve/CVE-2026-44918
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-48801
- externalhttps://access.redhat.com/security/cve/CVE-2026-49332
- externalhttps://access.redhat.com/security/cve/CVE-2026-9595
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_51038.json