Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.22.2 security, enhancement & bug fix update
🔗 CVE IDs covered (14)
📋 Description
CVE-2026-6321 — fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies
CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling
CVE-2026-9358 — postcss-selector-parser: Postcss: Denial of Service via uncontrolled recursion in AST Serialization
CVE-2026-33671 — picomatch: Picomatch: Regular Expression Denial of Service via crafted extglob patterns
CVE-2026-33672 — picomatch: Picomatch: Data integrity compromised via method injection with crafted POSIX bracket expressions
CVE-2026-33750 — brace-expansion: brace-expansion: Denial of Service via zero step value in brace pattern
CVE-2026-40181 — react-router: React Router: Open redirect vulnerability via specially crafted URLs
CVE-2026-41305 — postcss: PostCSS: Cross-Site Scripting (XSS) via improper escaping of style closing tags
CVE-2026-41650 — fast-xml-parser: fast-xml-parser: XML injection via improper escaping of comment and CDATA sequences
CVE-2026-41907 — uuid: uuid: Out-of-bounds write vulnerability impacts data integrity and confidentiality
CVE-2026-42338 — ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input
CVE-2026-44665 — fast-xml-builder: fast-xml-builder: Attribute injection leading to information disclosure or content manipulation
CVE-2026-45149 — brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges
CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray
🎯 Affected products126
- Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/cephcsi-operator-bundle@sha256:10dd80b3ad82c20eef3c275ae4e60e096e70da1d1caf2617c343ee87796216c3_amd64 as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:56a5765cc1d9c9ab11b0f081121364ee9566fbde3bea7bad187f79c04c729edc_s390x as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:799f74c85ebb87d20e141ead6f19bc15ce864c309a2818ff9f2b5acecdee8a98_arm64 as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:abbf0db79f97e40cdfe7ae4c8467f1e43640a9e779beca4442a3c71d6a37001b_amd64 as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:ef44ea45eda846f6c7398ac57b99c741b85eb56d962c563e7de09df41bd8552e_ppc64le as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:7d2b3fe9f29d4fc3e9e7c2e162735f058bafb5b642807395909fd163348857ae_arm64 as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:7da102846abe7686bde028f157b2fe31cd41edffdf3fc4803b324018b99fba14_s390x as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:e22ce5d41f0fab1983cb49db6578b998cee47f4a205459c08f6527a416ddac1e_ppc64le as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/cephcsi-rhel9@sha256:f46cbaa4c84c3de5822b1fbd4556213492d519e772aee22828c17702a3262a5b_amd64 as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/devicefinder-rhel9@sha256:13784eee313fac8cac56adb3d79867f4408ce7c468fe7d5cd98446a70c317cd9_arm64 as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/devicefinder-rhel9@sha256:328f7425f7fddbc2a7b51630ce053eaeabc52263de8f377a3883a6081b9a5da3_amd64 as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/devicefinder-rhel9@sha256:6480efbb4b0a279607e74afb7f7e65d10945f90f39604fe95ca48c2956461d71_ppc64le as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/devicefinder-rhel9@sha256:c2b058df336f51278f92b6762a206321d11e1c7e422f17a1e8873b351d425648_s390x as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:1c0b8cade0b754caa0e67951ce99cfc3931f786a927859990823cc7d5f95ca95_arm64 as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:5fce33c96d070692b42f15cc2c054897111c0bcee89454ffc78cac62b63a8709_ppc64le as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:74669da6414303b7d7d9bb2244a0d7099d1889753824c2782d14f7f74558f55e_amd64 as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/mcg-core-rhel9@sha256:bd129a261420f28720c841646211b8157070e4fa274edfb7e1006b70549c56cf_s390x as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/mcg-operator-bundle@sha256:9aad24bb89dc84721b3419ae946f3ca2e23fcdd7df7ea8b1555edca159dc8332_amd64 as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:50598651c996040e69c20b419e282b2ae06247fdb18b449d661b9201e5a6d3a1_amd64 as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:a7debce2cdbddc36a826fd5d53585356fe02173358bf6beab24a4507a2cb2a43_ppc64le as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:c39b7ed21d8355f8968565ae30056160dd777eb266abc4ec43ee73b4d88716c0_s390x as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/mcg-rhel9-operator@sha256:d6638e2c155622e06b1ac4b01e9424f6f0fa3f5dc8ce5976d30cbe030262a4e6_arm64 as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:0f0dc03a1726bb4099b389b490d86924e7249deb8227a49954409ebd2f9827cc_arm64 as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:2c93bc488ea43b341ba2e24826d132f08e49a386de9e35a1861386f1ac928995_amd64 as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:4e14258e6b72824405cd47f759057c8a66881c87bf1422f834348f94b7bb8805_ppc64le as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/ocs-client-console-rhel9@sha256:67a36e0f74870a7cfdcbfa0488930848e7602fadba2b24972017acabbb068616_s390x as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/ocs-client-operator-bundle@sha256:60b2daf9af3a904a4613c81ca1af26bbbd860992eb40905e073c45b8f2812adb_amd64 as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:18354c03c7fae81e867f70fda4ed3292e4f5ee6795e5bbbd8dab8151b7fc62f3_ppc64le as a component of Red Hat Openshift Data Foundation 4.22
- registry.redhat.io/odf4/ocs-client-rhel9-operator@sha256:2434db04d4689c277b0d7736be991d148b023d6ae3878de28f5bfa52be579977_amd64 as a component of Red Hat Openshift Data Foundation 4.22
- +96 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.22/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf Workaround: Upgrade to PostCSS 8.5.6 or later. As a workaround, validate and sanitize CSS input before processing with PostCSS to prevent deeply nested or malicious structures from reaching the serializer. Workaround: To mitigate this issue, applications using Picomatch should avoid passing untrusted glob patterns for compilation or matching. Implementations can disable extglob support for untrusted patterns by setting `noextglob: true` in Picomatch configurations. Alternatively, reject or sanitize patterns containing nested extglobs or specific extglob quantifiers like `+()` and `*()`. Enforcing strict allowlists for accepted pattern syntax can also reduce exposure. If the application is a service, consider running the matching process in an isolated worker or separate process with time and resource limits, and apply application-level request throttling and input validation for any endpoint that accepts glob patterns. No service restart or reload is typically required for these application-level configuration changes, but verify the specific application's behavior. Workaround: To mitigate this issue, applications should sanitize or reject untrusted glob patterns, particularly those containing POSIX character classes like `[[:...:]]`. Avoid using POSIX bracket expressions if user input is involved. No service restart or reload is typically required for this operational control, but applications should be re-evaluated to ensure proper input handling. Workaround: Application developers using React Router in Red Hat products should implement robust URL validation before performing redirects to prevent misinterpretation of protocol-relative URLs. Additionally, applications configured with Declarative Mode (<BrowserRouter>) are not impacted by this vulnerability. Users should exercise caution when interacting with untrusted links. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2026:56928
- externalhttps://access.redhat.com/security/cve/CVE-2026-33671
- externalhttps://access.redhat.com/security/cve/CVE-2026-33672
- externalhttps://access.redhat.com/security/cve/CVE-2026-33750
- externalhttps://access.redhat.com/security/cve/CVE-2026-40181
- externalhttps://access.redhat.com/security/cve/CVE-2026-41305
- externalhttps://access.redhat.com/security/cve/CVE-2026-41650
- externalhttps://access.redhat.com/security/cve/CVE-2026-41907
- externalhttps://access.redhat.com/security/cve/CVE-2026-42338
- externalhttps://access.redhat.com/security/cve/CVE-2026-44665
- externalhttps://access.redhat.com/security/cve/CVE-2026-45149
- externalhttps://access.redhat.com/security/cve/CVE-2026-45736
- externalhttps://access.redhat.com/security/cve/CVE-2026-6321
- externalhttps://access.redhat.com/security/cve/CVE-2026-6322
- externalhttps://access.redhat.com/security/cve/CVE-2026-9358
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_56928.json