RHSA-2026:57408HighCVSS 9.0

Red Hat Security Advisory: OpenShift Container Platform 4.19.44 bug fix and security update

Published
August 26, 2026
Last Modified
August 30, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2026-9595 — webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration CVE-2026-14362 — github.com/hashicorp/memberlist: HashiCorp memberlist: Denial of Service via push/pull state handling CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27140 — cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-42965 — openshift/router: openshift/router: cloud metadata SSRF via FQDN-typed EndpointSlice bypasses destination validation CVE-2026-44918 — openstack-ironic: Prevent rehoming resources to nodes with different owner CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:21a707a0c7a983452f072abe3e1efaed92b50bc65f47f0a674fb427953991257_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:7f074b61b1aab3ac64c5612c87d4299ee88e9883a2f220b8df2f7647bf578bd5_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:d59907dd1d364ede0975d7530376e64ff28502d2f07924fa4ad3c83a53d3a727_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:f40376a91d8f8a233eaa815da003b40d61f183233100f64f5f531884b9a83224_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:0a6dd9c920abddfd81f609775d888a55e5376b455e2739f01cb956da8df6e2fb_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:1a9230cdcf323ecbb17a237dde3ce6b13770d62b356e9d57c49ffe42eeafed82_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:3b9f59e9d1464c2a13877429f6ebb98b2e77f7f5094a713fef5655d3da6078ac_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:8ee1fed1b11f311fddfff89c70ac176e97f828d0d5b7bdcbe9ecd372c9615c74_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:44f21bb227510a5c04c7aeaf4c1b5362bbfd50e219ead3e518855f72d75177eb_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:4fa87f13075d66914a55cdbc74971f9fab43c97f0a901f4bd272e742ad058746_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:93dc02223c14e970b52eaa726324aafe5276970da2cfe5ed7fb46f2fa194a694_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:faeef1245d9ffc8555f6d9bd0df9175c6a1d0e168437f363fc33634bcc52a471_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:c7e28630643fce03fcdfba6d231ac399abd50e5bc9ee48d1879e325cb80b8480_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:caa9156c57e6357b65426154786ed16d46a9e3e613dc6514c6cd30de4491ff94_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d79024a46f695f25b2c83922d051d05db710ea22a5ba64d4055b734ec78a05e6_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:effbfde6d75f789718d58cb6c5686050ef11f0b1cbfc4107197b3678f9e00f7c_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:32f7dbed978384b313387126637d4a88b3570befae77429bb019b361bf855240_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:8c5cdbb06697edd616d877629df393b36067c873a9a7eca26c428ade57b50551_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:9ed98703f361ee744844774edba3a764f6423e4d85a10dcb3b5d4f3bf7cc0e09_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:bb45f8776d27dcbfcbbaa1fbe761114958e904c4c6f51a5cf966c9d9fde9aa76_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:10692536d56f5b2e9814a4b527c16a09d61de8c4794f641700d89d01ce788724_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:3957c073627d37b77539b3e8661e53c526f51ab5800b5433366f28fd502407a9_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:800f02a53de9e68f18d92d81a7cfc40fab95da7de2ddd1e4c04ddd6d16e76a51_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:c81e18e283884b681acda2c637930d86356781c0009ffa879eef4c2b27f9f5d0_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:44bb27c9f3b608d0752ba095806358e0f98be7ea6600a91c3ad0d5a39a0d0751_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:6df8ef19e2a97b4d469475cc43c00aa43703489490aecdbf7e7d13d601b19cb8_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f0da8e4347e6e9e0aa552324044189ab095d696cd6b50b009797d8838c86f58d_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f4c812ff24ab8ab409b2280c05cb16d180d5fa1138def6430bb4f3dbc36eb18f_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:2c5c3ecaf73d77ad6913e2ffb5e550c5baa78d4aaf1345d0ed3462010162aa97_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:6290a8adb6b7a43783120e845feaeaa19b9ddd685e3cbcb2724efc250978375b (For s390x architecture) The image digest is sha256:d3a37762aaaa6efbe58830ae4fa023b098f23ea601b2feba432fe3654d49cc12 (For ppc64le architecture) The image digest is sha256:22037e3d8727ed0ddb40381e4feb888c354444d6358f559615b2dd394a638907 (For aarch64 architecture) The image digest is sha256:4ce537bce3f790466b866ac23a233a885d1234e20b502a485ba511a0aa281dc9 All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, users should avoid configuring `webpack-dev-server` with a broad proxy context (e.g., `/`) when WebSocket forwarding (`ws: true`) is enabled. Instead, define specific paths for the proxy context. Alternatively, disable WebSocket forwarding by omitting `ws: true` from the proxy entry if WebSocket functionality is not required for the proxy target. This configuration change may require restarting the `webpack-dev-server` instance to take effect. Workaround: Upgrade github.com/hashicorp/memberlist to version 0.6.0 or later, which fixes the push/pull state handling issue. As a temporary mitigation, restrict network access to the gossip port (UDP/TCP, commonly 7946 or 9094) to trusted cluster members only, e.g. via network policy, firewall rules, or security groups, since the flaw requires network access to the gossip listener to trigger memory exhaustion. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Operators who are concerned they may have had this occur are encouraged to perform a basic audit of node configuration, for instance, ensuring the expected number of volume targets and volume connectors are present. Operators can also use the provided ironic-status upgrade check to identify misconfigured nodes.

🔗 References (12)