RHSA-2026:57487HighCVSS 8.2

Red Hat Security Advisory: OpenShift Container Platform 4.18.54 bug fix and security update

Published
August 26, 2026
Last Modified
August 29, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-44292 — protobufjs: protobufjs: Data integrity impact due to prototype pollution CVE-2026-44293 — protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:36e208f56ad53d74275cc7ef97ae3f462b9c26f0d0c8622a3ff32b18f77220ce_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:3e3b523892d6b18ca61f25fecf99ccbb137c9a98cc2dbdcb8afb27fc9de11774_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:addfc794cfbbecdc40dfa63185e09e9e6e1885dd6adc49a7768fafc08152041e_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:e4ef29c6ff24e477ee8327b0da37d9c56e8041295d2382e074d430a88574d069_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:4982b8f827f86cee9c7ba84ffbf2c1849feb5f5aab8d87e5a30c09355979239d_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:8a8a8adcc3546359f2a31169c7a2f9591e0ac14ff58351cb385a8b9e28825d99_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:a5225869ff127b5137346bde5b5892047287aa6f03e91b984955bc6b4c0e9b59_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:dd1847fdb4b1d4c58b83546533e42c06d435e93a3a05af4bdb26ab9f0fa964ef_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:26c4442ca2f30ff9f87561348479cfea3c6602d5af93ab60f977ab487dfa274c_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:37fc2b8a5bce15eec3b754df26fb251972b450466249b53adee5d910a3fc49e1_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:53abb08f29b88690e86414297d847125b8de5788609fb18f6768f406312defc4_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:ae1e533d23aefe954dd0e12857f70209cd6bbe12618dfc62c2c67097fec36a67_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:4a1a24913c9eb78cb71ea3584b6cfb105901aaa5d7b9ccf16470abaf7eaab93d_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:de3c4e5000ff2ceb48791c8b7e4c0938fa87306919c21cf4b3dc2ce3172328c5_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:e9343bc55822d0106a703ebf4787e4331bd30c5cc53bc6698b67ac7a35563c1e_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:f1bd76491529e76fb1e1fe06fd3f02c4ecfd2d833eb126b3ab5bb139aaf6065b_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:067441a7b6d347e58c43599de21e3c3c54c98fb2b08bb9b78686c15190972ec7_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:83929c41e6cf536262fa09f60df5a558c504c077f796519d23d5bc6f7698f9f3_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:a933c352c2b94db328187fdcc2dbfa03c64cbc5f5bb5853338d486e969b19694_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:b7623ee9603cff3abc570e040de2d2550b22e3913d6d6b121feb6a17b20d6cd1_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:20bda653c1f47d2289541ee742f219d7612b27f9561f3620d3711099860bec55_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:2d06ae3071eb81b794c8a0102141463604ea46c5c2de0bb4869ff01d90805755_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:365c3129d4db9d9d1b065714b3f011724957438b7971fe3303b15559c9a45086_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:93ceaf9f5eedaa73a82105d630b0544a8e5d3d7da5e0a3fb7b7b67874ebbb894_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:2820cc58fac054e92ed91b60f8aab65ee388e1d0cf29c9f7184c645e6c23fae2_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:2debb8ba146d16379142e846f4ea9ccd8ba84775e8defb3d0aa34228b7bd6d2f_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:afc8bd40e2d668b6cfb1afad080f290fe91eec6892c9cc9eaa2cb06d231c1537_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:dabcaa0fe6e1c2804d69c14fcba54e334d9864184e6e599c99ccc020d8052512_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/frr-rhel9@sha256:00dc538a83ba23dcd402013c0c80c10cb8dae812bc4c7acfefbc5551eaf0dcfe_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:4d4e6147f15c286b33afbd6838ed94683b5f93711a90efe046c58d453318663c (For s390x architecture) The image digest is sha256:66a3f21ee82c3651eae07ef0cd7dc81859a06b9c48b0e727489a6945a1fca830 (For ppc64le architecture) The image digest is sha256:e6f5a4487f2a5a040ed850a80b6014af330ac162beaada80b2b21a9bd79353ed (For aarch64 architecture) The image digest is sha256:bac5e091e587bba94d10d0e64d6c664748f2106f020d219b08247065850b4f80 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To mitigate this issue, applications should avoid directly passing attacker-controlled plain objects to protobufjs message constructors. If processing untrusted JSON input, it is crucial to validate or sanitize object keys and explicitly reject any `__proto__` properties before constructing protobuf messages. This operational control prevents the manipulation of message instance prototypes.

🔗 References (11)