Red Hat Security Advisory: OpenShift Container Platform 4.15.68 bug fix and security update
🔗 CVE IDs covered (14)
📋 Description
CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators CVE-2026-16242 — hypershift: Konnectivity proxy-server accepts agent connections without validating client certificates CVE-2026-26996 — minimatch: minimatch: Denial of Service via specially crafted glob patterns CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-49332 — openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on WSGI/PHP upstreams CVE-2026-50236 — openshift/console: Authenticated SSRF with full response reflection and path neutralization via Dev Console webhook helpers in OpenShift Console CVE-2026-50237 — openshift/console: Namespace tenant SSRF with egress bypass, catalog poisoning, and admin-mediated supply chain escalation via ProjectHelmChartRepository in OpenShift Console
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:0132b55fd9ecd2dde16091658cf54726d4103c8511bae677383fef4d0c64589e_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:0abeca3dc9c7b88a3a256528157418c09c5a464a7b428e48c9492c6bd7f4a11a_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:8be879c97ae60cbf48448470dd5e6ce88bd3cbd15681bc594c0a06615d0df059_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:ff63c64b218c3d0f8df86371a623078f30c6e73111fa0275157889519ca94a93_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:00f80ff2125ffd4a62ac7d0bd91b0704c63630e2ab45fb681cd999aaa2470c7c_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:284a47a752bb2deca059ff12bc7bb8686900189bc352c8670b58d76ed7972662_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:6c2519c34c724051006bcc63c8337fd96a4544eddbed23ebe85461b1036d899d_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f45ed73cf21b1aab7633cc4724f8e22f3183d1dd52d7abca4bba455c0f0b3818_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:00b461c15e998d4d4cf137f1a44f8180ec95b7fa327acd92d279125fc899487b_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:3054c76da41e45e417f6a58935cfeaf6fdda1f1965356172fdf846c89c3b87e5_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:4cbe0004e36a9bc47dd2cccf7e0f650451d8356ad8f9a890eb920014dc169638_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:df3b64686d5aed7e3c7b5e63f75b797a4ac4bd15f08306d103cc8efa28b2cb6b_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:480eb4611a418982e9b9667cee2ace4a67969484e37c72db0e65d0b46912b43e_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:cac338ca4b90c8c5f8e1418401ac629edc71f1bb7105904594e116fb4244b200_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:d1fc919ab6cd05e6e22a0d35299284821b771921c5b39e9d2cbf8904a7706adb_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kube-metrics-server-rhel8@sha256:e60b1ad9f16e4ea7fd421a81ba90eba76a73715569cc51e95852b409e688e961_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:72ec2253f4a79632ddc0b960eaff7b53e28589965506106ee8f3843ff2310979_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:bb6e74b71b263009b938a410ac0fb95df23b4eb675d7f156a02c31156ebebc5e_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:cc2eac178025eca18b87b65f90a4c5ee75c1148240135802345c92884f8dfd00_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:e9fa0747a97cfc4f6269d5e6a4b2c6e2c699622354e92003163ac5415feed001_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:1dd63cedfc15a91348b7b5ab8e70c723c81d8674587301325e3d028c3eee871b_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:aca5f2fc673116912b38b51c8b7454ec323a99a93c2b6b26e08de017179a419f_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:b6721f9c47ed2e53f1164aea41f6c65d7299f320822b6112ef7716bb61d05930_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/network-tools-rhel8@sha256:e9998d8efb96b8c83fd077f7416cc96741e0cb918c1524fc9583d1c26b7aba81_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:6353b9821ea2ed9e51d1b7e2143a875d863590f29cf54272cf94d0c8d32149fd_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:b0906e235debdf490d6af909795f88f6140c34b616ff29b9a7e3ef495241e12e_ppc64le as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:da51f2d588f7328c87a1764b1b5bf58e177f6e6439b8593eed01ba6b6ae0dfd9_s390x as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/oc-mirror-plugin-rhel9@sha256:f67a8e18a30df74a8cd3641bec10d777227aa87886bf8ace23aa71ff92d125d5_amd64 as a component of Red Hat OpenShift Container Platform 4.15
- registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:01f0c9f38be5ce2c0ae23bdb06be7817ae584c95dc941694db53b0dde081a91b_arm64 as a component of Red Hat OpenShift Container Platform 4.15
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.15 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:7603840b85b8ae287a0f72a7cc090d333e67912a40fe53ccb750019073e1aeb4 (For s390x architecture) The image digest is sha256:4bf090ba11d0c8e8e3ad1b1461f466830ecd9791d3ba3ec599a0de5832dab258 (For ppc64le architecture) The image digest is sha256:873ccbb5947eea94763714e8508498bb2cc35f3b9df88502f3bf842bf0e90b21 (For aarch64 architecture) The image digest is sha256:f38b5399db1920f294470fc006fc3794812a75168ef2b4abc84379ef17b61a8f All OpenShift Container Platform 4.15 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Until an update that configures Konnectivity agent authentication is applied, restrict network access to the Konnectivity cluster (agent) endpoint so that only trusted worker networks can reach it. For NodePort or LoadBalancer publishing, limit ingress to port 8091 to worker node subnet ranges. For Route-based publishing, restrict access to the Konnectivity route to trusted networks where possible. These controls reduce the chance that an unauthenticated attacker can reach the agent listener; they do not replace proper agent client-certificate (or token) authentication. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Upstream application hardening: validate X-Forwarded-User against the expected session identity. Reject requests where identity headers do not match the authenticated session. Workaround: Apply NetworkPolicy egress restrictions to the openshift-console namespace to limit the console pod's outbound connectivity to required endpoints only (Kubernetes API server, OAuth server, monitoring). Note that a blanket default-deny egress policy will break console functionality. Monitor console access logs for unusual POST requests to /api/dev-console/webhooks/ paths with non-standard hostName values pointing to internal addresses or containing query separators. Workaround: Review existing ProjectHelmChartRepository resources in tenant namespaces for unexpected URLs using: oc get projecthelmchartrepositories --all-namespaces -o jsonpath='{range .items[*]}{.metadata.namespace}/{.metadata.name}: {.spec.connectionConfig.url}{"\n"}{end}'. Apply NetworkPolicy egress restrictions to the openshift-console namespace (note: requires allow-listing required console egress targets). Administrators should verify chart provenance before installing Helm charts from namespace-scoped repositories. Disable or restrict ProjectHelmChartRepository creation via RBAC if namespace tenants do not require custom Helm repositories.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2026:56912
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2026-16242
- externalhttps://access.redhat.com/security/cve/CVE-2026-26996
- externalhttps://access.redhat.com/security/cve/CVE-2026-32280
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-4800
- externalhttps://access.redhat.com/security/cve/CVE-2026-49332
- externalhttps://access.redhat.com/security/cve/CVE-2026-50236
- externalhttps://access.redhat.com/security/cve/CVE-2026-50237
- externalhttps://access.redhat.com/security/cve/CVE-2026-9277
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_56912.json