RHSA-2026:54188HighCVSS 8.7

Red Hat Security Advisory: OpenShift Container Platform 4.13.70 bug fix and security update

Published
August 20, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-49332 — openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on WSGI/PHP upstreams CVE-2026-50237 — openshift/console: Namespace tenant SSRF with egress bypass, catalog poisoning, and admin-mediated supply chain escalation via ProjectHelmChartRepository in OpenShift Console

🎯 Affected products192

  • Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:8be5eb16bce34288502c8239b04a87f3eb182d7c50712b55da4916d837cb51b2_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:36424623a6c359b5dca9e637ee0046ba9bed11fefdef338cdccf871001c6188f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:0dbf2dc0aaf3f59b71f7e7afa589a36d34056acbb29ff93ee83e123c00494f99_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:8ed6030639e88a1ecedc9d73e815ddd2eefb4e199110c6b14cd08abe0876c419_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:5e1f04a693e982a888d2989e8544486dde3e9c6b469dd813317211607c0128fb_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:278feffeaf18a79649ae573f97f2176d2b696d3a9c3ee32c7135973bd2e0605d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:08524e93561d803a69d7942731f2b02f193bea6dbb5503f93628f5ef36e8762c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:f69a711ba3e24952d5349377699d097faabea1fb88a27ac4ce74b42bc36e364c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-agent-installer-csr-approver-rhel8@sha256:11c2998d83106e7b6b1cbf3453521b7e00b4f8ec313a20b375676e213d2deec5_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel8@sha256:ba86a092a16eecbb9a2ab7ce75f166d8b519eb4b4fb6d81e8896781aef649a40_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-agent-installer-orchestrator-rhel8@sha256:6e57c8205781e2833abea06fa66cbe8bfa979b8e9bf3ef4a72d46d2e6a478f79_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:dfbf038de94d046b1fe0ba490a20a28deee36f090cd6743181dfda393d2a388d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:ec5730952f6374d6430beed94951a6302686eddef1670066bade0967d453990e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:b4bcf87c49fa8487e649fbcbf3bb9f75f5c140a7f3fee450dece4e971f611384_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-alibaba-machine-controllers-rhel8@sha256:73d111697ae8f3616fad6c6f509d097d2f69a86d1071fa5f6928aba61c5f0773_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-apiserver-network-proxy-rhel8@sha256:422f1a86e4ca35a447b7f7478e21c4badeab9d75fc14c7f9c8582179fcf763de_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:ea5230672a3093af6038257edbbcccfdc47161b29a5a34cc0d965cb8d4e4413a_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:59bb1b068d17aee123a3224ddddb39c74ba03f832d3f5b898967192c62959302_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:99a61fc3c12d962993f894073fc46bf8e842d265997f75596d1f1b784a843868_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:040451469655fb57de07a5b343b777d80cd351dda41385c720a540e703c634b1_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:83cd0cd0cd32d5bb786ed5268d61ad3745ef3e8477fe6db99c67453a73f5b423_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:bd6675b1e787c3471e51b5baaf4743ea95281184646ffc8faa298fc218c475d6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-azure-cloud-node-manager-rhel8@sha256:0a582ecb0411afef902e564b5c5db4a31019c06925c78941196f126e14c97d18_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-azure-cluster-api-controllers-rhel8@sha256:e8bfedf9daafff2705a6fbb565bd92982b5f535409b0eeb07bb60427f34dbc92_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:5a1ba6457340c06f34ed3af38fef999c43b7e410d2c62e305cd75209b18f4eec_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8@sha256:e3c0e3b83dff0cb03c98e36c3ac21dad0cab582c439d8616b9659418e2483d0d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:45a34da862593857d2ac0dcc02ca6bad65169b99a51220deaca11135d7edf62e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-azure-file-csi-driver-rhel8@sha256:e6de9da49ce7170a6398751cee05ea884d6894a204eaeab064fd10e1f2969969_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • registry.redhat.io/openshift4/ose-baremetal-installer-rhel8@sha256:ea97e2ca86bb681e562747e678f454003c82a125384ed8a8ec680f4fe9531821_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • +162 more not shown

✅ Remediation

For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html/release_notes You may download the oc tool and use it to inspect release image metadata for x86_64 architecture. The image digest may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha value for the release is as follows: (For x86_64 architecture) The image digest is sha256:033e3d7ba0937c0b3d2f88993bbe2e97c8b396f1782a7353c68ebe1282b2586c All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.13/html-single/updating_clusters/index#updating-cluster-within-minor. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Upstream application hardening: validate X-Forwarded-User against the expected session identity. Reject requests where identity headers do not match the authenticated session. Workaround: Review existing ProjectHelmChartRepository resources in tenant namespaces for unexpected URLs using: oc get projecthelmchartrepositories --all-namespaces -o jsonpath='{range .items[*]}{.metadata.namespace}/{.metadata.name}: {.spec.connectionConfig.url}{"\n"}{end}'. Apply NetworkPolicy egress restrictions to the openshift-console namespace (note: requires allow-listing required console egress targets). Administrators should verify chart provenance before installing Helm charts from namespace-scoped repositories. Disable or restrict ProjectHelmChartRepository creation via RBAC if namespace tenants do not require custom Helm repositories.

🔗 References (12)