RHSA-2026:54555HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.19.43 bug fix and security update

Published
August 19, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-44293 — protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-50236 — openshift/console: Authenticated SSRF with full response reflection and path neutralization via Dev Console webhook helpers in OpenShift Console CVE-2026-50237 — openshift/console: Namespace tenant SSRF with egress bypass, catalog poisoning, and admin-mediated supply chain escalation via ProjectHelmChartRepository in OpenShift Console

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:49ba5ee0e8eb80e60d528badc85ab4ee4f69ecfaa0bf82c335e83d3e24f2f7f3_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:7105555b37824b3d2da108495568f9de3a5cf769d86bef7a8d5d4113f56fba45_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:93d76c81950c137c6b20550aa3886b72a81be6068ae5a60ff2e55b6a07498bea_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:f9d8cdbac78a715838c9f870c6eff8a52045588546b269fb6aa6e3f15931bdb6_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:02d6a93448b85fae7226ca2b9f2681ae946d7460bbda876dbdf5af0b1e920a73_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:0dcce7cc0908ac3f5691c6d66f2c54cda829f116f436cd10a84ad0866da114db_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:2ccf1f1de0bffd6788224fecef5bdb46142ce79886c0a7ee8436be30d9805c22_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:440d705d7f56a2004d9af2860ff3cf4d4d222b7033448677683a58e89b8a9daf_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:27bad80e98f72aa8ea6eb265c82fb5759888d64638796f2302283764d5ae7c2d_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:34db43bec18b731fb259345c7dafa70a3cef4e5ce5c9d4c6c762491a8ba803a7_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:57f008d1764185742bb3b4151defed0b7bbbc5b24934ad93de192af3a66307a5_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:aedbdb22b465e7e9aaa4fd1fe46b675539d25c691810cfb312250681a82fdd6f_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:6a83cacbfd01d7332362b42141dfaf2d99b82000cdf9497228b0ddacffc90dac_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b14bb7beb2a84444fd1463dda3c3ed692f81bfa3c5e3633c95ec26fa18109446_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:e9bcbff734d866a868e7e16564b77eadbc1196a0bc1d57eb53a33327ad2855a9_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:f332dab197ae4bd83b1d1669bee8cade6203fd5f97a0822f0d4a9cc60a7f7684_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:1cc1ead4ee877aafb69e18f402af03d765cb7ccde42099812c828fef78aa10ae_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:75734928a394c8ca2b94f3161e474ac3e192ba791dd4d9bd7679732e4ee6a6f8_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:83b84d657ff2bca4cc7b10d2adf69ed585acedbf4c2221df6c66b386e97d964e_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:d053feb7a77781d7009603c27ec08e5e61c72dc4940a3c44308c806cc12787b7_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:029417607a1596da46c229a83d6c096fd5d8fa5be8d8163041870a3335432425_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:8172975b09a56211c859501e41ee3f3ce18b480a5cdbb1e0db6b63b557290ceb_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:90f3e0165d2f9c34898d2cc097f7aed0a0a23919d8bf1e1f2bca39a621d6df18_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f8a4c63472b04373deb0bd58d96cc66df52d86ac6c6d81304914e7df042d3a4b_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:4559ebe28f574bf7b582747ec7ed060d2dd308266e2b271bf1e8a7bbf83883e2_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:47165e9013be2b968bdb30d53399f33d136cb00bbfd7167eab90fb67d6ee0538_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:5632e0ccc4e7f9941c037823d0327569567ecb2953315d261b0f4d9aa862ae81_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:7c679cd0e2b6b78ed0d030adc763aa296237f73a987bb50557d44e841aa39531_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:027c4d325f0e32ececeb0d815ecceb4ce35626dd7bc3b882e72b8d7f727ed785_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:9dc530839ca5adfa742d89d7c0a5893d8d5351592972ded701b6b22499606a0f (For s390x architecture) The image digest is sha256:2a396444e4566a44dd1099867af6ea75e6fd1ba17d6467a0389b366e6a3ea0f1 (For ppc64le architecture) The image digest is sha256:b3a07d260a429838dab94b37abd960338c33949c8a61d8e86ba092bd27217b47 (For aarch64 architecture) The image digest is sha256:49b0fa463c6cef6f8eb70d9986a200b2d1ee2e651211644ab09afd20498f9820 All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Apply NetworkPolicy egress restrictions to the openshift-console namespace to limit the console pod's outbound connectivity to required endpoints only (Kubernetes API server, OAuth server, monitoring). Note that a blanket default-deny egress policy will break console functionality. Monitor console access logs for unusual POST requests to /api/dev-console/webhooks/ paths with non-standard hostName values pointing to internal addresses or containing query separators. Workaround: Review existing ProjectHelmChartRepository resources in tenant namespaces for unexpected URLs using: oc get projecthelmchartrepositories --all-namespaces -o jsonpath='{range .items[*]}{.metadata.namespace}/{.metadata.name}: {.spec.connectionConfig.url}{"\n"}{end}'. Apply NetworkPolicy egress restrictions to the openshift-console namespace (note: requires allow-listing required console egress targets). Administrators should verify chart provenance before installing Helm charts from namespace-scoped repositories. Disable or restrict ProjectHelmChartRepository creation via RBAC if namespace tenants do not require custom Helm repositories.

🔗 References (11)