RHSA-2026:60454HighCVSS 8.5

Red Hat Security Advisory: OpenShift Container Platform 4.19.45 bug fix and security update

Published
September 2, 2026
Last Modified
September 7, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-43003 — ironic-python-agent: OpenStack ironic-python-agent: Arbitrary code execution via malicious image CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:0591f58240e2db284a76154d894e4db63ef132b82d034db49acfc70b44444a29_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:118296a0bf7a4a7785606731b54d5f83ca7fd53023526fd391a0b0bb65afd60b_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:2a07f8c4e4173f8a1c1d35045506f9427b859385759f6ac093ca60b528eaa56a_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:c840d18c462f04e224d2734391f7f0e249024bb6bce842f32f8f8ca4d50b53e7_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:584459c71569be0a25552d3ace6437910e046e24de9080edb133a3e768f9ad9f_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ca68573a6141e0e5f17d6418fc2793ebd9e7a2d2e445e70c13989f127faad1b5_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d196d92cd5e1fec6d741fa39189c15ffd29b6ae732fa3a84ed1c34ae0b99d13b_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ebb48262f7ed72ae1741cc1a670af631106f60f4a8697ca5a31869af512f271f_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:13544c9d6610450ff58af426f04c0081be075e480d6ef903386cb8d20fe07a16_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:8bac02390fc5a490f5d3b3fdf30886f45d1f664e0db5c1639e11b51835078252_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:dabfdf5d401acdaff7dd8a3d28facfa978f452a423e6d82512bd01690eb4aacb_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:eada04c856e3cdbd4e5055b5e6fe8cadbf4031098815018116a8e9528c32f0f7_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:7b094ee6cbfb579b328cacf2461d16248d7ab3d116ebcce6252511054c8c878c_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:7f97ad694e450c33e078b62c31ba806fc710f0e8504f0fee3e68c4c5eaef0f11_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:af0290150355551ae795105b77a946846b46d4f3110e32d0600ef70ca72cd744_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b92a4b923a05b13035ad4869978a817f4284c7c3faaa5e7ab99f80a308529323_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:81948511de1c5d982f8425226875d690188c2e15e0e984d1050f66080724e5f8_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:a674ce9ba91d447df18262c98bce7087a8ae54a4661f15a70972441f666a0244_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:cb267d353fdde43141b32e6141c5d22cb714f4d43892833aefdfcfae36220a80_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:edd81e2be485ea8b141cc6595ac150deae1aa7a2ab8436d6ed1cd8696ca70125_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:218f872846a6c64ee53aff8cdee5d86502b8e107d0faefd50558437b528e1b49_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:35a942c4650d69df727c75093cba6337ce6d5719ba20975476dba1d07993da3c_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:b470cbff10fa27db1de29b2287cfbdf2e3b97ecc271722886f4ed03656549883_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:b8d3e5c3cef479f9033976201fed94a33b5c8735d3db1ae18b1dce7ab7276375_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:1fc6a6aa270d42090bf70a8d1de12a6516b9189dee535b4a12d24a16bbc2fd2b_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:59538c38a05567454a1dfc53264bb00b4b11aa7dca527f5ad7d1117a76c9a69a_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c51ecce77838bec872a7791336b13b3560566536b13bbe5e5e2eb70ac7a8a016_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f1414ce8ce2273d8b223daa4fc85cf11a6d7fb501170034091388d2de76aff22_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:12d5b11700f0ceb1d5622e84202fd27b776e1cace92501838577e21ca3f86e0b_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:86fdebc072e8bc8c6caf035fe7117db670caad3cb05a7cad7a3bd1faee79d51d (For s390x architecture) The image digest is sha256:542d46b653e2d57a0e4d064835786957b575801023dfe26b91dc3cf8e73171da (For ppc64le architecture) The image digest is sha256:35f097a93fea57efcb9c5918e57b494c9565c87d716a359041142b5c0068157f (For aarch64 architecture) The image digest is sha256:502da7913928968aece6ac528ccc254506f6c12bb6b9d011b934a4c14c868f13 All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.

🔗 References (7)