RHSA-2026:56854HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.16.69 bug fix and security update

Published
August 26, 2026
Last Modified
August 30, 2026

🔗 CVE IDs covered (12)

📋 Description

CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators CVE-2026-27140 — cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names CVE-2026-27143 — golang: cmd/compile: possible memory corruption after bound check elimination CVE-2026-27144 — golang: cmd/compile: no-op interface conversion bypasses overlap checking CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-50236 — openshift/console: Authenticated SSRF with full response reflection and path neutralization via Dev Console webhook helpers in OpenShift Console CVE-2026-50237 — openshift/console: Namespace tenant SSRF with egress bypass, catalog poisoning, and admin-mediated supply chain escalation via ProjectHelmChartRepository in OpenShift Console

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:7edc9d33177e8c410cfc7698cdf0d12340f5ad73052ddcd259a12884de26b555_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:bfe56979c22c4f06c3b7744a343413b306ada02b43cba76078f70e1cd26e3b78_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:c6f93592a241c1fb3fa1778bce6da78a146e9b08bb9f9bbd8d4ad74a605a8305_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ce1787325ad5122717b19a0ae7c65594ec1b7ed1e8998d651bd817b56234143a_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:02d5c6efb734b921008fd18f46f28a4f67c258d3d3a83922085c776dbf37101b_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:54092adc063a914c9151acbb929d9313477d5222554a1394fed5945034910fc2_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:8bf56c6d5fd1884b6417692d13d5e0f2313869150c63a407574136c9d55a2275_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:fb99c0498a842bad53c340cba03eed9839be69aac162f1db38141c977f020890_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:21ea32e6e5ecc524f88bb47afd38b36b9d12a4f0580532cd6b5687e3888716fc_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:67b031278b374f74da5c71cb1c49eb17d2d77e8ecf8a8f00ac137f64f9aa218a_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:9e21b493c74c056e9b9117f80005a27722008ee72ecad3ca40852a3cfc8e4e81_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:a4aefd366e26fb42416c54fdf7d9baba4f2d70a14a3b4cc1b480e974a3470597_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:0136a2c7eea25530bed1ccf2dff56662b277e7f5ce1d418ae5a3779cdb430e07_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:903a88bd367267720aed42dc1906b6fcab0ba7e3d8444dfc154b642a81b03dac_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:b71b3b53e9f051409306cfcc3f35d5f1cc911bc0b004e907a28429af243ccd1b_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:d8513564e81c2acce2fc3d083d9071d2b3def4161e18285d8ddbecc35b737dd6_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:81484878c2629f1ca8fc9e6f756eee91ada78b21b749036e211c8d6afddc528f_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:b4a5550016b6ef4e1068b3388fbe62f973b5674c496451601fd19ad026662522_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d2a6c7fe2bad061caa50ecbbe8e5be50e3ebc5a158965bf0e9589ef182210847_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d783137b411812e0409c8511d3dd85a490f362149462edd3ce78584fdedc12e9_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:873e6a1417fce3cb2cc07d0f818ff9c77ed9a0d53f11dc009c2059cd644be6d2_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:dc6cd264b157c00f4e56c7d73ca072b62662142968e44907926dc770a5491761_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:ddc5d20611712965c751a5673c74e943bb98313fd6c9129c579e248d75d5b565_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:e13a347c8787e98020e8e694c2f2f0e8ddcc5c1c98b0277fc7cb88ac7e8d02fb_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:08471e17ccef533438775b153c61bc6e3a24f120b08cbf8e34caa41c446c72bc_amd64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:23910c59145f516d053702146b5a7e3987fcfaead7b6227a2979f03538bcfc20_ppc64le as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:4b16411a22e4c887f478713acf7bfe2d67afc5a90e5076b0ca09122996de959a_s390x as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:5038d116d01d08c425d920a48806eb9a7895658276f3e6e8106c657c35b6d3db_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:4034a21303ff55d3f0ada813c88be5ba39bf16dab46dfb6ccb588a0378d48c6b_arm64 as a component of Red Hat OpenShift Container Platform 4.16
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:6153e72b10afb0a08ed75d928f51346b30407483477f14f3bcdbe9a0cac0286d (For s390x architecture) The image digest is sha256:f32a58e7992cb8c99b0c46b13d49f4b0f9b4223bbf0dcb512b91a08f8f6db492 (For ppc64le architecture) The image digest is sha256:c8ae2207b3f6cbfb07f5cab88808f2e629808ab382900f60c61852125c2d3d96 (For aarch64 architecture) The image digest is sha256:7ef17710757c0ec0cd1022216237a48dbf029bdf5b0949ac8b6dbb91942c2050 All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, strictly sanitize and enforce bounds checking on any untrusted user input that influences loop counters, iteration limits, or memory indices. If there is no integer overflow or underflow, the out-of-bounds access cannot occur. Workaround: To mitigate this issue, review code that performs memory copies or struct assignments. If data is being passed through an interface (such as 'any' or 'interface{}') just before a move operation, refactor the code to use concrete types or explicit pointers instead. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Apply NetworkPolicy egress restrictions to the openshift-console namespace to limit the console pod's outbound connectivity to required endpoints only (Kubernetes API server, OAuth server, monitoring). Note that a blanket default-deny egress policy will break console functionality. Monitor console access logs for unusual POST requests to /api/dev-console/webhooks/ paths with non-standard hostName values pointing to internal addresses or containing query separators. Workaround: Review existing ProjectHelmChartRepository resources in tenant namespaces for unexpected URLs using: oc get projecthelmchartrepositories --all-namespaces -o jsonpath='{range .items[*]}{.metadata.namespace}/{.metadata.name}: {.spec.connectionConfig.url}{"\n"}{end}'. Apply NetworkPolicy egress restrictions to the openshift-console namespace (note: requires allow-listing required console egress targets). Administrators should verify chart provenance before installing Helm charts from namespace-scoped repositories. Disable or restrict ProjectHelmChartRepository creation via RBAC if namespace tenants do not require custom Helm repositories.

🔗 References (15)