RHSA-2026:54602HighCVSS 8.7

Red Hat Security Advisory: OpenShift Container Platform 4.21.29 bug fix and security update

Published
August 18, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2026-14362 — github.com/hashicorp/memberlist: HashiCorp memberlist: Denial of Service via push/pull state handling CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42965 — openshift/router: openshift/router: cloud metadata SSRF via FQDN-typed EndpointSlice bypasses destination validation CVE-2026-44918 — openstack-ironic: Prevent rehoming resources to nodes with different owner CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-50236 — openshift/console: Authenticated SSRF with full response reflection and path neutralization via Dev Console webhook helpers in OpenShift Console CVE-2026-50237 — openshift/console: Namespace tenant SSRF with egress bypass, catalog poisoning, and admin-mediated supply chain escalation via ProjectHelmChartRepository in OpenShift Console CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:2c945e580f25786216f4bd75bb14d038a4b3687a1a3953bed6326928e7b82eb0_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:3a0bebc508a488526ee0f6214e148a659ef19f0fbc267b2e08e0b4c7d32a51d1_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:78b47d427c745c702a76b7908045728318ec79ce43fcea4af8224c8bc4c8d83e_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:d146f35e20207c8e18e5e4a68703bd80bf22f7f375d9ce54f67f33566fd9038f_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:3977fe6f6060a1bfe34c3e3b0989414991c2f57b7a0a0aa51698606b79b13320_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:67fd7fa221ec65fe3ac453ab0cb6c61aeb88ef828a3328f9faafb0c1a5062e2b_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:68aa457c6aee7072cca5b5916d1388fdc44ae9201619cc03c9dc07762d60b584_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:6f60eaf9be1c2b599d75038a088560ad044b727326748fcdef1842929dafefa0_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:26365b22988e01e56d4f2103af45dcd5dac668659b12fbb2b62772ea6a604782_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:9502c6a4121a3659059ac4e01d271ff9f7d529102edafdb9da7fb7e854da98b2_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:9a7ed9139b47aa07ec4c520b7982799e1ca5b524469bce0797982375647d95a1_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:bfd06afbfb2942cc7d0dee9ea0a3bc26e008d5ddba3ad1e63410ba3eb7bc24f1_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:79a80db7882f45b00d7175948354f86b2a136c051b8d40539f6a45fdaef94bd4_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:968de0ea5db8342b0d01a249cf38bc94f57e4c43f02dea2d0b6a58a8cff00619_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:a01b9fed5086d9a66448ab36584f0ad797a14c9005f0156d42b28e905851f6db_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b5d61a56c91a00a782e31c27a4dcb398e8b612b0a1d3d027f5ff47d6425ef5b7_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:36a11d98de3c7c175296cf4b5fccf63a60d4bce5e51b013fda7a32e64cb71e86_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:832ec4d9dffcaa4778782bfd3d1d77d561675c79a24599b5cc42d5ecebb2e848_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:9edef4ca4ae75ab3d1cb7766689e83e3d21c900a2a52fef31d8e315115de507d_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:a3f7d81cd4b26c82ab7b97660888400223e399a8dd278e741cc287d48c671bd9_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:4cdeb370fbad9e7454942431d4078bf2cbb0a6f1e1eec69e92a68032a6a87baa_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:54577c472ef91d63ee149e771b2d53d9ea89a1c137f5695632077ca97c1b5860_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:61425f97aafbcfd708822732f1129677a79573c4d28a89298577dddf7a26e496_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:e0ce18c3909f0b52ca853f9767ba37a06e2d7d11391d8fb90373c64e7e28989f_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:062e70cb9f9384afdaf26871d17d19388388228f7cc72edcd07b16aa0c9bd4ab_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:6afa036d0e57fc00a12cdd787d3a42c8b672e799dfec7531be752e95845a562e_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:b5c15b364ec3276b612fcaafaf04b80b6e0f94c5a9321e5d14aa2e95d6848aca_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d3852deb7ab352a6ac5edab8aeed1117b2e8161b8f0284cdc006ea84ff9a8c42_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:081ce48834f5d9e4c2080f64fb3dd7c5092d5dbdfffa7d3405b0ca8550f6389f_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:2333bb05e29582d17c07955ae077e52911734028a59d3a9a698ef59d41fb8a5a (For s390x architecture) The image digest is sha256:0f62eb7ebcb3e461c2404c02407de394fce02b7403e62233f8e346dfb00a193a (For ppc64le architecture) The image digest is sha256:ff64d0946a41b1ec80c4b4f0f97e00bfce6887b93c3656ab0846e31d140969cc (For aarch64 architecture) The image digest is sha256:47bf9e3d8c63073bf7a759ddac3f987fae55335fb9b43ebe3c510997036e832e All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Upgrade github.com/hashicorp/memberlist to version 0.6.0 or later, which fixes the push/pull state handling issue. As a temporary mitigation, restrict network access to the gossip port (UDP/TCP, commonly 7946 or 9094) to trusted cluster members only, e.g. via network policy, firewall rules, or security groups, since the flaw requires network access to the gossip listener to trigger memory exhaustion. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Operators who are concerned they may have had this occur are encouraged to perform a basic audit of node configuration, for instance, ensuring the expected number of volume targets and volume connectors are present. Operators can also use the provided ironic-status upgrade check to identify misconfigured nodes. Workaround: Apply NetworkPolicy egress restrictions to the openshift-console namespace to limit the console pod's outbound connectivity to required endpoints only (Kubernetes API server, OAuth server, monitoring). Note that a blanket default-deny egress policy will break console functionality. Monitor console access logs for unusual POST requests to /api/dev-console/webhooks/ paths with non-standard hostName values pointing to internal addresses or containing query separators. Workaround: Review existing ProjectHelmChartRepository resources in tenant namespaces for unexpected URLs using: oc get projecthelmchartrepositories --all-namespaces -o jsonpath='{range .items[*]}{.metadata.namespace}/{.metadata.name}: {.spec.connectionConfig.url}{"\n"}{end}'. Apply NetworkPolicy egress restrictions to the openshift-console namespace (note: requires allow-listing required console egress targets). Administrators should verify chart provenance before installing Helm charts from namespace-scoped repositories. Disable or restrict ProjectHelmChartRepository creation via RBAC if namespace tenants do not require custom Helm repositories. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.

🔗 References (14)