Red Hat Security Advisory: OpenShift Container Platform 4.18.53 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-50236 — openshift/console: Authenticated SSRF with full response reflection and path neutralization via Dev Console webhook helpers in OpenShift Console CVE-2026-50237 — openshift/console: Namespace tenant SSRF with egress bypass, catalog poisoning, and admin-mediated supply chain escalation via ProjectHelmChartRepository in OpenShift Console
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:011b68911b9d5c6d88e03f768a0226d901a51700fec0b7d7979674b71965e39e_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:aba1df7a1d658b2f4c615e997924391a30fe6e7329ded11dfba5d4ec4eaa1380_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ac448d4d128373d1a6251414cf85b4119814f491490df9ae2ba2a9662f00a214_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:f9ad191e10552b959c8bd06d6f52ec2d82da41106a4e33bb57811ac5cc45181f_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:7517d092edcf30e43867448ff1b25230513b6c343a2d4c45970715c36e121af6_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:b1dfdf0f8cdf4bc035b6ba1119940a4dd4890c2565bada8a81a9fdf8158d2dac_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:e758857146c3fe8b6bb21119363f0e720b77afe33ed980facebd36321b90ef9d_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:eb900dfb78d80df42171696a6bbe07897c66e5d99a759b7473e7d4ade8219642_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:43b3d50037ac7bae7bfc2142e43e4b7f550bbf6316187ddfd791e02f43f361f5_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:64a4be185de9a7b69b5f044dd0c1a755f5c79f133ace3e3d931ca87647055b5f_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:6764ee724cf6a2e70b663fb5b3fb17d61b78440ff252333cf5f8f7b2a9ae61c6_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:f7b390124f0f43f8ed1d96f769a47f8ad6360e809ad770233d89f5c81f31c0eb_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:5219144441d2887dfcff57d7dd265918a18d77a536b715bb6f63b54a920386d7_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:7c4924e6eef286e3e8b1c0f02f867e8eed3700244c546169b4cab84145028d6a_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:883b39e0b89e0122048545ac4215585141470b86cfee02dce8dba1a41452b5ae_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:99374dcb8fb1ba18592483a5994bb1e01463bef763d0471440268b818ed89b9f_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:0ce4f9abd2c4613d174e6d02517bf24a650a91aaeb442d152b53690cc064a006_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:46a211d0f9b6aa1754bd805d049941cea5162a590676726788e46a7c2ad62801_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:7b06d2a3775a0d306fb493d02674f6f291e13174bffc2bf600feae41c0990cd0_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d694801ac276c544bca043039cb36bdf18022ffdcdd5ce3e32e9e396aee4d901_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:30c732f498c2f6fe2d3a2da7c6422069b575f42cb89fe9c41448cb16fbb4232e_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:37096776fbe9c9b1bedc24c31439e0bcfe3e710e099d42b2ca9d04ca040f4e84_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:43ce7de4374b3d49e73049ac2af74693405a4683f439e8cb80785d858e7c1061_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:9d11c53406fa41c363d801025f310868511ea1fe5ff1812cda069a62dbc4110d_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:2dccc8d320050d7a28a8dd5132d292ba45d3cada458bb81055612e4a469d7cf9_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:318f21dbb09fe81c989c350f842dc66dee70741a39e4386d347a9a525a15b894_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:7023d4a7369dadbeb64908916418fccbe8288b34242852790afef062fe957064_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:f333916adb1f680f64a9aafa8541d89c85b5be78a3bd72cf2102a64463bde077_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/insights-runtime-exporter-rhel9@sha256:251999543b7336e843c4e190a61c81d5e06d4f49dcb1d55e5aedcb7c02669c98_s390x as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:f9d84ee7a22c2f9d1e36e40e7b2a06af7e14b44f5c88450d5567291d1b638dce (For s390x architecture) The image digest is sha256:b8422d0b0e94c96ab3d09f05702fcf318c4c94331671e7b845b37a4865cdd67e (For ppc64le architecture) The image digest is sha256:2c15d0c5237dc1a8553fc7e83d18f83ae7ac40f12397ac8017592802103b6d8a (For aarch64 architecture) The image digest is sha256:a316b38314a10b623db09bc4fd88fc74ccd8072e5cbcf6f5e19083b7e59ee28d All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Apply NetworkPolicy egress restrictions to the openshift-console namespace to limit the console pod's outbound connectivity to required endpoints only (Kubernetes API server, OAuth server, monitoring). Note that a blanket default-deny egress policy will break console functionality. Monitor console access logs for unusual POST requests to /api/dev-console/webhooks/ paths with non-standard hostName values pointing to internal addresses or containing query separators. Workaround: Review existing ProjectHelmChartRepository resources in tenant namespaces for unexpected URLs using: oc get projecthelmchartrepositories --all-namespaces -o jsonpath='{range .items[*]}{.metadata.namespace}/{.metadata.name}: {.spec.connectionConfig.url}{"\n"}{end}'. Apply NetworkPolicy egress restrictions to the openshift-console namespace (note: requires allow-listing required console egress targets). Administrators should verify chart provenance before installing Helm charts from namespace-scoped repositories. Disable or restrict ProjectHelmChartRepository creation via RBAC if namespace tenants do not require custom Helm repositories.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:54545
- externalhttps://access.redhat.com/security/cve/CVE-2026-50236
- externalhttps://access.redhat.com/security/cve/CVE-2026-50237
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54545.json