RHSA-2026:53773HighCVSS 9.1

Red Hat Security Advisory: OpenShift Virtualization v4.19 Images

Published
August 11, 2026
Last Modified
August 11, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

🎯 Affected products10

  • Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/aaq-controller-rhel9@sha256:484643af88d45773372fab81ed3b46d1bc12b754ca2044b84dfbd21bbf16ab1f_amd64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/aaq-controller-rhel9@sha256:4a72cbf3828e5bae55b71753191c09216359a6ebcfbb7dddbdbb9e147d9817d6_arm64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/aaq-controller-rhel9@sha256:fcdfeb04a046d3c710ae74730121dd3ad34305bb4ec8d0cca64d960d8843084d_s390x as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/aaq-operator-rhel9@sha256:27115a677a2ec51a9deaf1bb2eb82e28d01a22adf9ecd848f2d8ac24428cd3eb_amd64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/aaq-operator-rhel9@sha256:b472c07b81fb19ded65c8b3e7ff55ce02a16277d3e1ffd09fb3c53acd358bf97_s390x as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/aaq-operator-rhel9@sha256:b8d9020e840fbf32c9c12e9fa38778d8bfdb5f9f8b849112758f0d2cf08df00f_arm64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/aaq-server-rhel9@sha256:a9bb34648ec6323171a58328e12532dc67ed341fe19620ccae63c208a8ff8f9b_arm64 as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/aaq-server-rhel9@sha256:c0f08cb14f325a0c771c854fce3b30cb8ce94a7e64cb0fb82fab0ea7eb50988f_s390x as a component of Red Hat Container Native Virtualization 4.19
  • registry.redhat.io/container-native-virtualization/aaq-server-rhel9@sha256:e07a0ec5489c0b9c7f13dc5b3edb572369d0761cda9f673c30cadd2bf4e1cac9_amd64 as a component of Red Hat Container Native Virtualization 4.19

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (4)