Red Hat Security Advisory: OpenShift Container Platform 4.17.57 bug fix and security update
🔗 CVE IDs covered (13)
📋 Description
CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-49332 — openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on WSGI/PHP upstreams CVE-2026-50236 — openshift/console: Authenticated SSRF with full response reflection and path neutralization via Dev Console webhook helpers in OpenShift Console CVE-2026-50237 — openshift/console: Namespace tenant SSRF with egress bypass, catalog poisoning, and admin-mediated supply chain escalation via ProjectHelmChartRepository in OpenShift Console
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:14b1037cc4bbf1e02478a4a6c4b168065e618f88f0ba38bbb5a84a5261a55308_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4ff792dd99dccd3ca116bc51f15d3dd16009c90b4f218e4ee7e29bca831ca754_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:b952c3cd4448afac00f1e688146e5702a6ce29b916cb1d83d377bac3021790b5_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:f44009eeec4be613e3ad60f336eddbdb9347cf27728b6dab0303307e5a453f51_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:0a58478c2663223862d24a6fbe78990e1edafb33c1d2d9b6f7456d4597ee82cc_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:1e4fe266d81f3d74c9ea58c6f7dab734438d51a6c9100890c6da51dbd4762d56_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:2089bfe55d521fc7bfd4304a4471a8712f36b008aaf978ac37e908bcbbfefc1e_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:a13f22d125be707763622c34a798d69af2d83de0829957fba1a31e0adfd20d8f_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:24c9369ae2cb1068cf46c566dc818c76c7666a6dca720ee7e1f5e58df12a98a7_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:6ba6dae4472088c5bca2205dbee865a87a8cadf61651f76fd311c5fcb5093cea_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:6ecc57cf6357835013247695a8991943aec0859b6810716d195f784708ea0814_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:9da6eb61e52bf5f4b09a88ee490a0ffb5a42c2f5fc2bc496c42fc0ae9777aff6_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:199c9ee38b630e9428a1509b33a2fb5ef2c2a9ab05367972147c09834c4c758f_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:3e1180b6fc39f1a85dcf49e8ff823c2da3b550f3350c78f1fb924ceb1a9be5de_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:7ad95b73098db7800f123165c98a6ce4cf665a32e6e825b8766dec71d0d7b5b2_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:d274d676b2cecd3b401d07cbdd890c4c00454e0ba4b0eb396d923b95c2026e6b_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:5ef8f380b6cb0c5f712e11b6ca62ca31cfb71b73c3eb01f8474dce623b649bbd_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:8ae9cd2bccecc2469e6cf6f7721ce50b2b3de986cfcc9f9bd7af1c91d4667d9a_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:93999ab17602f2a7b846454f7f5d78b0c731280dbf31043ed2e8e1d965633bc1_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c47ae4f1a5543e308973c7ff055944d7dc4bed3061dd2d602ba5fb82f7297cfa_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:70faa87dcc78c5423e4d33b1703eeacab5df8a24be809c20aaf5ebdcd0b060d3_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:7f51bbe039cfaaad5e49a8e43dfaa48d2d19aa2da0612ffb428dd0fe240bd548_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:9a5b9287f54207588057f79536f3483da63615667cd8ff52f4bca38037952e94_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:abb558da97e1dd7feaa23f49c40dafcc313a95ba12bdfd19a9a9d28d11908ca4_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/frr-rhel9@sha256:206f21b9851e537e6e68adc667866c60879b4da88344f13d714c6a0a4b90de2d_s390x as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/frr-rhel9@sha256:47435fe0ee5cdb24887ee8bd9930ba19c898ef3357082ed4599d2f6bd49ca474_amd64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/frr-rhel9@sha256:8f822655f42deaa9de8daf92fa790e58df7ecf30a4d9e5844a6255a110465b19_ppc64le as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/frr-rhel9@sha256:fe558cd5ccae4f9ea3e2f7d98a6d320adaef4d5c50edf2f04027d6929fd0d650_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:7adf363b41eb4d2667efa1642f2ec6043fcee6455989b2a516aa5461c5b58176_arm64 as a component of Red Hat OpenShift Container Platform 4.17
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.17 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:20063c3ad963efe23d545d4644231fc2e2eec33d066c8a8423f2dde973a062af (For s390x architecture) The image digest is sha256:9e9310243adae34d972878a46124be066f2fcec8d34c3270688455258205ba2b (For ppc64le architecture) The image digest is sha256:1095d7dadf9a6033f6b0453b30f6003ad6802d9bb6d971f2d260fe5a979a95d0 (For aarch64 architecture) The image digest is sha256:a736fbd7b865536dbf94501291e51f5180172f314a488625420880f820e5dc39 All OpenShift Container Platform 4.17 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: Upstream application hardening: validate X-Forwarded-User against the expected session identity. Reject requests where identity headers do not match the authenticated session. Workaround: Apply NetworkPolicy egress restrictions to the openshift-console namespace to limit the console pod's outbound connectivity to required endpoints only (Kubernetes API server, OAuth server, monitoring). Note that a blanket default-deny egress policy will break console functionality. Monitor console access logs for unusual POST requests to /api/dev-console/webhooks/ paths with non-standard hostName values pointing to internal addresses or containing query separators. Workaround: Review existing ProjectHelmChartRepository resources in tenant namespaces for unexpected URLs using: oc get projecthelmchartrepositories --all-namespaces -o jsonpath='{range .items[*]}{.metadata.namespace}/{.metadata.name}: {.spec.connectionConfig.url}{"\n"}{end}'. Apply NetworkPolicy egress restrictions to the openshift-console namespace (note: requires allow-listing required console egress targets). Administrators should verify chart provenance before installing Helm charts from namespace-scoped repositories. Disable or restrict ProjectHelmChartRepository creation via RBAC if namespace tenants do not require custom Helm repositories.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2026:60023
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-34986
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-4800
- externalhttps://access.redhat.com/security/cve/CVE-2026-49332
- externalhttps://access.redhat.com/security/cve/CVE-2026-50236
- externalhttps://access.redhat.com/security/cve/CVE-2026-50237
- externalhttps://access.redhat.com/security/cve/CVE-2026-9277
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_60023.json