RHSA-2026:57365HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.22.11 bug fix and security update

Published
August 25, 2026
Last Modified
August 26, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2026-14257 — brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-59877 — protobufjs: protobufjs: Denial of Service via crafted .proto schema CVE-2026-66138 — ironic-python-agent: OpenStack Ironic Python Agent: Arbitrary code execution via malicious configuration CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:0ff888d5ce1a530f0a59f8e167fce60649800c8ff37382bfce2272096025992d_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:1a233a3d7bc8ac4aae2591f7a9a425c556fa454b7d8ca550eeb5ba327f30f04f_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:31091a01aeff7d803b41662f2894f9d156e808fbc0e19873328a41d11b5f6a2c_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:b9522c287864c0c58ebd083154917266611378ea822193b5a028f033f2b86f62_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:58552f63e5291b3ee87624b7d298a15af9e407f33aee3701e7d5c25a89430b0a_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:bade9b94e9735a190192cf0a29aeaecf545dab65bae4e83336b594c19e0c6232_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d4702bfe97ef1c129a84eec3fa16d6621d89224f20f400c446dec05931c15ebe_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d779198a9d1c3a930949dac859eaeef7fff5be6ee93f4ef72e19467134b2f960_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:4cd361786f859c274dbf8c7860390861ea2ed76731922255134c127fddbf57bd_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:54362f1b92b65b07224fc37a827b832ec01ffbd2f7ce0964d55d74043456016e_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:6e918d68a3e4c53e78a710925e1143898cfad407b67c1df7d897be404a757ebf_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:86365b7bd59b032f24804521babb1779716de49eb3d5732547d7481d822f04d9_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:2a8417ed59446478ad3c99b88745efb18ca66d3b47103adfba82a713e040eeef_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:3e7730bbf9e860c0e9fa201bd62e507b07625e5df62e02acfa9be461207740dd_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:acece8ffcc7c2f9028bf190f820f90de4038fbcd9d138c8705379b1202796653_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:cde6aebb345b6294764e7106c7fc4dd341264e49a50fec4ca52c5ee1e1eeb33a_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:1b80bdfd027ae01dd55461d783ea7faa5e994996d2bf0b9f1d694576e50065fa_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:a47876b812c8382902ad06ea85c32ee19fb4d0edb62fc6a56482e6c3ae59ed72_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:a75b08f7927a579e6295d06de028080f7bdff57a6f3b6e4e5156b14c7b4ab5e6_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:ccd117fa19dedf4718783333335431e551b0a52a5f72d977084daeb60c43c15a_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0d0d758f381fea7f1fa72ece650098d84d663339af97a381aab6c7b0db724f9c_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:52ff3908ea8ac39cd5a5868a1ebbe27cda74c253e5a1e32dcb91e36f1b1271cc_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:e857c4c5e5113f9d962625fc101a57ec36e40f157239c13c0b040923183723b6_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:eaff74821b72969569a317dcd81b9e60f4c66e6ed4b2f05633470acdbbf9db31_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:6dff2a181bb1ce4dd798b0892d3edeee58961b0711a4562b015d893a648c64d9_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:8290b1c0d6a229fa2258c8edaf830aac3817f0b53a5919d0098670c267a18831_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ceb19f9d5b6b1dc8b681f6cd3d7f637ad4986c050b94397faadd322eae931a46_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:e39bad83710fdd4e3e245dae996115a41c17f4d7ace1a7d84361c5127c055e20_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:1e3dd79380f858505dcdb64b4d98068c2221b6ed179f8c8fc64a709fd320bacd_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.22 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:7130a86441e55382a1eecf141edefd4a83c6eb7b27c6cb67883027736b8242b3 (For s390x architecture) The image digest is sha256:d2fc4065149f9310168334a67e530e58d6a80f302877493e9fee91547accb27f (For ppc64le architecture) The image digest is sha256:a0eb0d2d1b0ae972b00535e3f8b25a825efccca03ac01f1682fbd7f7b790d63d (For aarch64 architecture) The image digest is sha256:9bf8fa70aacd7119c25e466d563b24b867de1c16648a975978cfb42de7aacc6a All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Applications that only encode or decode protobuf messages using trusted schemas are not directly affected. Until patched protobufjs packages (7.6.5 / 8.6.6) are available, do not parse .proto schema text from untrusted sources via parse, Root.load, or Root.loadSync. Where untrusted schema input cannot be avoided, isolate .proto parsing in a dedicated worker thread or subprocess and enforce an explicit timeout so a non-returning parse cannot block the main event loop. Optional process-manager controls (for example systemd restart-on-failure, or CPU/cgroup limits) may reduce host-level impact or aid recovery for supervised services, but they do not fix the parser bug and are not a substitute for input isolation or applying the update. Workaround: Remove the chronyd binary from the Ironic Python Agent (IPA) ramdisk image. The vulnerable code path is only reached when chronyd is detected as available. Without chronyd, IPA will either use ntpdate for time synchronization (which is not affected by this vulnerability, as it passes the NTP server address as a separate process argument without shell interpolation) or skip time synchronization entirely if neither tool is available. Additionally, restrict and segment the provisioning network to prevent rogue mDNS responders, and review OpenStack RBAC policies to limit which users can modify kernel_append_params on bare metal nodes. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function.

🔗 References (13)