RHSA-2026:60447HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.20.36 security and extras update

Published
September 1, 2026
Last Modified
September 14, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2026-14257 — brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-73643 — js-yaml: js-yaml: Denial of Service via exponential parsing in flow collections

🎯 Affected products178

  • Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:36fb8e5a9ad6a5a213de85780181f4a7016c43880c7df65fb88adfc53706a555_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:621f414ca592cd9148aae284cc7c577b2a82850c091809792890a2aada0a612b_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:6851aa6e66c8fccf328b5bb153cc6c71ed85ad6ced708d2d3f3bacf6c4121be9_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:84a8417d9477a03bd2abc1d496132e633028daeca8b6cf724197da12e6c12a9b_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:1c0a280c7c9fa443d544937718d9365afbbd7065da9da59454f12e329f7181b8_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:90af45fa59011cb7a438f3f3c904eceac31342d79012aed0ebdc856b01851e84_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:d394712e29499f8818be670d95f49813caa256c7aaa49d146c9a0cb3cd449fac_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:e3c13eb13c4586557f9df39654824e7a21471f5a44c15b8ab41f6ab793fdfa02_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:1297a3ca220c6b5866a517fc45f39605d6f3a0b331a232fda83a33db9c3d0174_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:3c7d80b9b6e44149d472fe9d26f08bb9de7250e72ddcba4594a97a486ab2d5fc_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:56c03171f40fa94c97d68b21f98c6a8443c91b7d5525fe2e3cb12640c7631171_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:e2ccd343cb3e45b0d2e4f8ba31c874adb0605043e6a38cbd8e4f997e56a32fcf_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:7fabbdc6f9d45b393b7dcafc2cdf15a84a45b501c4c658eb44db70c368186e7b_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:b783aa68d8d8a08c0902723def71d8567e5acb2fae5f6b5587e4c645364b2bd1_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:ebf922459998d268ee60c6e5e48d40f1ec6413242656e30829a07e4f9fec14a6_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:fd14776c3efe5e0757527c426855622de7f284273c9bdc1b152c567ac85e99f6_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:08f0cbb1d3abd5fbc4aca97b0bd8d8e8f32c665b4528b3d104976b6e9dd7ffe8_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:15618861e603bdf7ed51a6382e6a49f9fd4835f3df2ffbd4163b7eb3c2c07210_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:3ffb8ecfe4c86bc1b39b55c55ee062792ce54881375378fce61cc6cd1ed52587_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:ff053a08c405c164f257263276f427169232dc125e2a71e161f592004193ab9a_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:243725e2fe49a34563940e28b21a3a713fd2a25c7a387ca72dc5d5dfb991fe1e_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:41b4c51a89a47bedb7c90b42e862f605eeebc5a7ec8e448eb5d800664652c38e_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:8446fa50a857052d8d4d82258c50ade616799a047fa279f6515b96672cb2156d_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:94260e2db9a96efdd30a77d88d62c8688d4ce64d15af50461163d348eee42420_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:256a927a8ff47b0fcddde553b4eb53414c2bef2814bc2d67db41612b7cef74b3_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:6a65bcafeba516b33af1c13a5ab19b29e395d593c0ea0255bf2cfdd6b6788cd5_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:7140b69763968d5dbcd77372b5f5e4828cd3d989c6659176bc6c54b0193b7487_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:b246162305af474f921a8a2630d79a2de7dde97bd1b044c9ba3e6590cff95cb6_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:0b8bcd85734d73e94d676ec61f8075426902a3c381c6a6833a968e171e6c7089_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • +148 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: To mitigate this issue, restrict applications from processing untrusted YAML input with affected versions of the `js-yaml` library. Implement strict input validation to ensure that only trusted and well-formed YAML data is processed. If the application is exposed to external, untrusted sources, consider isolating the application or implementing additional resource limits to prevent complete service disruption.

🔗 References (7)