RHSA-2026:56789CriticalCVSS 9.4

Red Hat Security Advisory: OpenShift Container Platform 4.14.72 bug fix and security update

Published
August 26, 2026
Last Modified
September 11, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-16242 — hypershift: Konnectivity proxy-server accepts agent connections without validating client certificates CVE-2026-26996 — minimatch: minimatch: Denial of Service via specially crafted glob patterns CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name CVE-2026-50236 — openshift/console: Authenticated SSRF with full response reflection and path neutralization via Dev Console webhook helpers in OpenShift Console CVE-2026-50237 — openshift/console: Namespace tenant SSRF with egress bypass, catalog poisoning, and admin-mediated supply chain escalation via ProjectHelmChartRepository in OpenShift Console

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:057ac7e4eaf3fceaec3052838192867f45f25bb4acbcc1b795e35dc614fbd139_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:2df66ec1bdf5f31658cebb15892e5222bebe509a488aaa35e95348bcfa2a062b_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:a4864245e4c74f69b6bac9d13022867da97a1cb55b15775754837259a876c6f0_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:f37d0b2747b9039342505fec951b52385e63d829d8b2d8c60a6fd16fd566a87e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:0ebb1ddd09b9d21ad6253f405d83b09f2f9664b9705666f2596e37dfd6bbfe3d_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:25dc6b4eaf0303224a9c3605a217843df2e8ef275ae98b35c7a5e8fc0cc95553_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:a79c507877f12cef3e7591dffc14fd7e55b9cb684519151b16d6bdc07d0dd619_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:b151f2e3e43c0fbd8558c96040549a08b6927844127952c3d29f57066207cc93_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:5b21425c8ad55123b90d2b159abbbdaa549f2f58a1bceedf481ea3659f5a462d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:b5b14b0ba5fded988fb9bc1c42653f6b1a6dfac59fa834646254b65794209430_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:e9b4eecccb707f8acea4c596004a874c1bc557b7f75d1e602abe6c2c43f139f6_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:f6efbbf7d2ea150795f5741630d72e7b6b71c88b55c5470e266c3a1d291f9a44_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:1a073149dcb19a374c15d61153a90773b9d44ffb14b11b46967f114cd6a95b94_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:304e1c1967a19735fa6a4f87582ffd348f5a591b2e29595efa6fa654b79982e7_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:6dbfe2c6e180c7e8b5df9e58e9f15cde17dfd1cc8b7ae7fc72b2cdf856ffab81_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:71b01ae56a2187b019c1198a8d16ca5f8886908b108d423b4b082a01189c5c70_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:3fcb63b4aa9fa9bd66b4ee652603b725cc6a61a24a69083682fe937d960ad28c_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:585318096ffbfe34e6a4732f213c96134174ee434cd1ad07cab8ed1115e4c801_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:e08ef4a3236e9b55070345eadcde98820f6f6ab64740704f837dba024175264f_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:eb86e8ae47496585c62beca324df9f28472983d9bb3766c9b27285d1e6a6dacf_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:57ce09be43c5a3223194bb005342584062f4c7a225524e3d0b25fa6022aa328c_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:6cbc95fbc3531808cae5866d2cf5faa8fef4db2807f8ccb8e94cacda0316e1e0_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:fbddb6a3904edb8305261078bfc14412cc14f1427c1cc0414213f0b48463830f_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:ff6f74c1d834ba41b8af0f34ef6ba41f28ffe208adda098b8ff930d6490568bd_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:4da6ede87c816ca5dd7aedb32e9d61bb56808fe32437dd99059b6b1c38702964_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:65068616a683bceb0bd116cda5add24ae4117dbad69e9096299aca61f7739c3c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:95ff3627925bfbe97930398f28538cb6524153ef7141bace7616df2fa8e4b94b_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:99991a538d74c45e05999f0346a19db47dc4877ad73260157d3c0a5c13943750_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:3ab2ad29af1820cb8fac50d399bc0c689e03742d4d04db2144a7d122bbe91728_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:e6be81645e10fedbbd1ebeca18933b761c648e37de9b761929e4d3cb46c46322 (For s390x architecture) The image digest is sha256:18a0809716072ebbfa149cea7b523fb24a54f345549e15b0fb7052ccd8b2966c (For ppc64le architecture) The image digest is sha256:ac88feeaf4a90e38cca07b8eff7c88f6fbc4efe650ff901b8211735814603031 (For aarch64 architecture) The image digest is sha256:7b4b85d36da80453343920f3049faac6c654d881180f37a22e9cfc4c71a4c09b All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Until an update that configures Konnectivity agent authentication is applied, restrict network access to the Konnectivity cluster (agent) endpoint so that only trusted worker networks can reach it. For NodePort or LoadBalancer publishing, limit ingress to port 8091 to worker node subnet ranges. For Route-based publishing, restrict access to the Konnectivity route to trusted networks where possible. These controls reduce the chance that an unauthenticated attacker can reach the agent listener; they do not replace proper agent client-certificate (or token) authentication. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Apply NetworkPolicy egress restrictions to the openshift-console namespace to limit the console pod's outbound connectivity to required endpoints only (Kubernetes API server, OAuth server, monitoring). Note that a blanket default-deny egress policy will break console functionality. Monitor console access logs for unusual POST requests to /api/dev-console/webhooks/ paths with non-standard hostName values pointing to internal addresses or containing query separators. Workaround: Review existing ProjectHelmChartRepository resources in tenant namespaces for unexpected URLs using: oc get projecthelmchartrepositories --all-namespaces -o jsonpath='{range .items[*]}{.metadata.namespace}/{.metadata.name}: {.spec.connectionConfig.url}{"\n"}{end}'. Apply NetworkPolicy egress restrictions to the openshift-console namespace (note: requires allow-listing required console egress targets). Administrators should verify chart provenance before installing Helm charts from namespace-scoped repositories. Disable or restrict ProjectHelmChartRepository creation via RBAC if namespace tenants do not require custom Helm repositories.

🔗 References (16)