Red Hat Security Advisory: OpenShift Container Platform 4.12.96 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-49332 — openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on WSGI/PHP upstreams CVE-2026-50237 — openshift/console: Namespace tenant SSRF with egress bypass, catalog poisoning, and admin-mediated supply chain escalation via ProjectHelmChartRepository in OpenShift Console
🎯 Affected products191
- Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:2c67f7f59a6149a2be4af5a01cbb1377720783e4dfef492c1ee0d8f2e01522af_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/driver-toolkit-rhel8@sha256:a87b0c30f498bbddf613fe286f001ea9dc19d7ddc73ed9ceab011059b85cd667_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:fa9f1d2d69bd8800d431a7ff20605fd240a3c729850f83110d705a49fda87124_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:1d0e7a5aa3d4ed2e64615a8c5cd4ad3cbe7bead9d8fd4cfd1a11ba72b0f1cf55_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:8a996b69c0e5b0d854ca9199572d56859573bfafbfea6dce64f631e900c5b019_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:89221fba24e233cc5587a6146f45a819d583344f7f58b629935a91e837524e5d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:a9fccbece79553689c4f6c083d68dbfb3ccb25dfe3adbaba50f9e6897d83bb96_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:9d93885ff7043fdf3f3bd3b55537ae4953fb303dc79e91fba607c76abd82d82a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-agent-installer-csr-approver-rhel8@sha256:986c0d508f08fd8de9189acb84a218d3b830787f144c3c9bd2c757c200879416_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel8@sha256:77dd0d1843061621b2b4c350e93d256bd46d0e3553c81b3f29af8a1eedd3b020_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-agent-installer-orchestrator-rhel8@sha256:6cbb3fa7fe88994bfad10b473a34e2c21062ffef5b9c2fe81976fb462f424c29_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-alibaba-cloud-controller-manager-rhel8@sha256:1bff82f5ec41cb467689d70a021ee7ef7160fa649d61423e4f6d0a956f074a83_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-alibaba-cloud-csi-driver-container-rhel8@sha256:78e0d3678af258828908675270dce623096b81d6a27ed0c299c7dec255e24848_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-alibaba-disk-csi-driver-operator-container-rhel8@sha256:618dc6282ffe6f8010c2a4a3bbbdd9f00c42f82e1d8f1ca35a8e06cfb7ec2040_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-alibaba-machine-controllers-rhel8@sha256:18d3918516de5fed8c9c15b973a37611867524dc231c95180cf536e1ebaed3cd_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-apiserver-network-proxy-rhel8@sha256:f716071e34f66b61691a779235389380962eb91c002145ece0c0be28429f1ecd_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-aws-cloud-controller-manager-rhel8@sha256:7095657c1ddb7e2f6c60087d10f4d919cc67dd27169df3afb5bccdaaa35da689_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-aws-cluster-api-controllers-rhel8@sha256:622a2347143f69ce94d11a1e236542f5138a9a92ed719714df2c48a607dab6ab_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:0eb48b0c444b32feb7a90fb56fe29466476c6776d6c2b05c3acc3df1abf29cbf_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:ca1c536abb9ec041562d8a739909d99a16b92b37e76d801e2618f33f5fa0d718_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:8e7235c5a19297df5b6d74f7228de613d2cff342e046e98a73ef1d8d9fffd0c9_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-cloud-controller-manager-rhel8@sha256:4f5992befb410ef43c26b7eba37a72b675d70c869b17167f781341aaa2db2b22_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-cloud-node-manager-rhel8@sha256:9bbeb0bd1d6167182bf1351c574d33f430c458f89bf57ccf8b7799edde614ed8_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-cluster-api-controllers-rhel8@sha256:aaa4f3e70f9ba6c41ebe1eb5293c359f460667feb42ccc14a16967fc19ac9a5e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:e027fd9b5b2b2cc479871397768a27339b969e3cfda1fe6fb83419d70cd3a862_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-disk-csi-driver-rhel8@sha256:e01e5be55eb9d078d0db0524e72b231f9a4165ccd408ed067f92898290849d6f_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-file-csi-driver-operator-rhel8@sha256:a39deffd0abd4d6b3eeb62f56dd2a5d850084de46dd3bde0540e1abc4ec1ecfd_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-azure-file-csi-driver-rhel8@sha256:e6a7dc486823f8b3864c90c81f0b1c24012c3179ebbaa0ceb7faba74eb997432_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- registry.redhat.io/openshift4/ose-baremetal-installer-rhel8@sha256:ce0dfd0e207bb0986a70c67522f47be75d6765a0eadf2a2d0591e5fc39de3879_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- +161 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html/release_notes You may download the oc tool and use it to inspect release image metadata for x86_64 architecture. The image digest may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha value for the release is as follows: (For x86_64 architecture) The image digest is sha256:fc0a3dd609a60dd4ad10fe4badef3058d61a1a33436d33ec4b563d5aaf9f26cc All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.12/html-single/updating_clusters/index#updating-cluster-within-minor. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Upstream application hardening: validate X-Forwarded-User against the expected session identity. Reject requests where identity headers do not match the authenticated session. Workaround: Review existing ProjectHelmChartRepository resources in tenant namespaces for unexpected URLs using: oc get projecthelmchartrepositories --all-namespaces -o jsonpath='{range .items[*]}{.metadata.namespace}/{.metadata.name}: {.spec.connectionConfig.url}{"\n"}{end}'. Apply NetworkPolicy egress restrictions to the openshift-console namespace (note: requires allow-listing required console egress targets). Administrators should verify chart provenance before installing Helm charts from namespace-scoped repositories. Disable or restrict ProjectHelmChartRepository creation via RBAC if namespace tenants do not require custom Helm repositories.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:54206
- externalhttps://access.redhat.com/security/cve/CVE-2026-44486
- externalhttps://access.redhat.com/security/cve/CVE-2026-44487
- externalhttps://access.redhat.com/security/cve/CVE-2026-49332
- externalhttps://access.redhat.com/security/cve/CVE-2026-50237
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54206.json