RHSA-2026:57545HighCVSS 9.0

Red Hat Security Advisory: OpenShift Container Platform 4.20.35 bug fix and security update

Published
August 25, 2026
Last Modified
August 25, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-14257 — brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function CVE-2026-14362 — github.com/hashicorp/memberlist: HashiCorp memberlist: Denial of Service via push/pull state handling CVE-2026-27140 — cmd/go: golang: Go (golang) and cmd/go: Arbitrary Code Execution via malicious SWIG file names CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:2617888d6db8ec413fe0731f23e07c8b1dc00499aa2845a6971735b617ff3368_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:30165782ff4612ec2745a4fcd3041192e14a0519517ee05aa7bfac9f726b1fc3_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:42400efb018669e159f0624f2613c05fe8a7444aab020e67fad79a00010a741a_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:8e97b7c71ab40fb6e65dcc905ad95ecb5046b1dfef2d413880212074ef807327_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:507e8da4f68dd7a57e413c009993dc52f5b25f84a6b6acf91b131bd1e5fa406d_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:5d4c1e89946eb5afa5e9bd8d844277efbc3538986690f178d39d00c4fc9a0f44_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ce1a9d57e98d94853c17732df6b4892fb8dbc0a85be8a142bbbf0410c986a439_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:e4cf8f3db0dc63824ad977f770d9763fd16d4407ba9979aed28d52082092431e_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:00dfb1fbc5957502e967ae74990f9da137e55557d3fa9160f5b0edd3c2b764e3_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:50691aefb98e6d0d3eba6000b8b00b4b9742b6dcf465dc6027f0f2c6aae7874a_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:840cccf7b539c1d73e818f169d0104be3611e2ed8321e1ee165926aa585ab5ef_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:f28c798c76e64d886d27be0787639788985165f8ca20ab2ec78b2c6db089955c_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:33173ed284b9c20e515f2ecef98b7a605183922f86b45e9138f1fa62acc67de0_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:6364848d0e67adf9fd8f94ec17b952d69a1a6b9f5539ccb5d1906c444df3e3fc_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:9dc04f7e0cc65df3bba33e8411768836765f90a73849323f1d0513b249a60524_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:bbc46313fce4190b996c7be7c96aa4dbe17645ebd83089c882fa9b0c2921cc0b_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:2cede03d11f736874576c5186228121f8f091830a198a76ddb22ff8f8e58977c_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:53191fdf2076be9a394246309842fc3c052c4076efd6ceb6075555fd9be69dd5_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:86c8cfafb04b21e4d10610a483c3adc4ae5d990cddd9a8378c06a35746752498_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:92d69cb4f1003ca43cf8bd2d2debdc10baebe96012733ab7a3101909892ede5f_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:28f0006d62e878c278453d419c77dc7c9c62c0ab20d7d9485ba1d1c4f94c2b67_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:641c7ca52f45619685367bb4bdb08700a9fe200367658864fed6d43c4cf6240c_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:a6dd5a9db95565cbf22f10e55353720d5db5636ffba765685bd459aead6456fe_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:e927b5832aef48805866ec60103e27fc3f0e6f8e79a6507206f028774f73f18d_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:403f6211301b7e32b0fef98bfd4f7ca145f4d84a067fff11fce7c15fb7c31cb3_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:8c83645ca4a22bb6931d58760fdb5dd64bde4cc294772a408ca8090acf87bb32_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:a91453fa60944669552d850de72c90e225778e18538cd080ec7848bebb17a711_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ef2ff8771d7a3e40807b853e1ae830004b78fbe330d61b01645803c86b328249_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:47f3278751a3221e9fb986aa9b953c114fb90be12f93c2beae8e17a538ebcc60_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.20 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:ffb9ee7de8d13bce19d67ce5c6c13c56ad8e9e1906341fccc7c5d12e2fb6d97e (For s390x architecture) The image digest is sha256:cc186d91c9aa6912b0c9b37d4ad6a2a351c7d2a25057be1dd877d4fdfa749199 (For ppc64le architecture) The image digest is sha256:53c1d50692a293687cdb9807dcbbe7fac623d7bfbe43e05424a3ed4669dff1c2 (For aarch64 architecture) The image digest is sha256:e6afe3fe2624db9921344d41cd507f65156faf84e3bb6ee23a0cf0ec5990b68f All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage. Workaround: Upgrade github.com/hashicorp/memberlist to version 0.6.0 or later, which fixes the push/pull state handling issue. As a temporary mitigation, restrict network access to the gossip port (UDP/TCP, commonly 7946 or 9094) to trusted cluster members only, e.g. via network policy, firewall rules, or security groups, since the flaw requires network access to the gossip listener to trigger memory exhaustion. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.

🔗 References (10)