Red Hat Security Advisory: OpenShift Container Platform 4.21.31 security and extras update
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-14257 — brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-73088 — browserslist: Browserslist: Prototype pollution leading to denial of service CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results CVE-2026-73643 — js-yaml: js-yaml: Denial of Service via exponential parsing in flow collections
🎯 Affected products171
- Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:0e6ca3ed4c42d4f72f4807f2ca5ea3e8b207a323cee11e4041cc8789fac1f92a_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:1cf0dfec681afa18868ad2f376e8f4f250e0e9a9b474685c5ec20f2c0ed4dcac_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:25917413d6052587c71642f971b5e7c57398493421872f4a549c73704fc70e91_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:791e104a1b102416e3edd9c672e20c7ec27d92232c993d1aac40f0fd9d747c5c_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:1f054f899609cf5636ce0ab9bb8908d4e6c70ad7d84b6d7790f86d97d968b1c6_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:351a13c6d2ac96c20b35932b8e88a6794ea1e366136acdfaafcaf31cfb223dd6_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:35d5502ee611fc3acecb22e8865ea5641021fcb7e8205b7fa3d69bc7b13178b8_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:87b977e402b4d41521709d315695808fda2ef0e3149d42d6b069faecb0bcc4ca_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:22ba5563fc903a699ff71c895c78b9f7a656096e1559aa677aae93bf3cc486ba_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:734560578cd8ea2766b3ffd425aef18a80f44430fb3bb2221bad02864598c50a_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:ba57ba192077f290bf80764dd13819ad0f33ad3bc94c38718a3f8a008322e776_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:fbbb330eccb2813a713a6997c48e77f20bd04cde8244bf65dd639cb3f79d3100_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:2b435983e6f7ed4a4671e4f199bc5cc41492bf27182e33cdea159af1fd005d7a_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:9248e1d1c2503e4f0be0a101468ff6cb52e94e52a7ecf86d384bb0ea780d2028_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:add05fff26aa67466c15be5488382140386778af6ed274764b7a0ae59843b941_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:d70d78d0d78db1d316a83cec6953ec1bb21958e7586bb753451c1b4a6ef9e7c5_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:0e9cdfe602442b7765f9d07874859d31e78d0748ca11889687424739c1c39410_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:4754d2aae1b852cab0417368bcf47a2eecc707da49f38539602bc5c6cde3004c_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:85044f630c4ca4f3ac6aa3249d9c83c3c039162d5bb09fd4a64417d60f8691e2_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:b94487a221bad2b170ef9914d64ad3e669aa05224d945615943fb8817aeb4455_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:3b1272a4d69d0cfdba2bb892ea6909b645c5e34b9e1507949709691cbcbd137e_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:6c226ca3a69bf711122eedf934f249cd8cfb68b94b471e0f795338e848049dba_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:adcccba24ac642ea15ec8ed1404239b50270368f758df81a0782cce1ba5ec060_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/metallb-rhel9@sha256:ffa9c4f969b8fa24f4317fdcf75b972fe1d340d971f4121a424bd0368c3fe2d5_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:7e6420eb90a6d810195d2483dda0b4e75b184fdfebfa9a630f5914bd0e35b816_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:a03d10bb1e92731817a395140c3b4fa98b4a7ee0b092b34f6fff366cb3d07100_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:eb6d570f74a3d732d0aa4be0188665e137ed91b1264fb2ca753d632ad221cbd9_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:fd938cfcb898f004c195d4d0b41209e607b4a2fb754bc9778ff192c23500c875_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:22f21f878d2b9247b54a996267f6aeea0f034adc2e9c15aa630b076a88209a29_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- +141 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: To reduce exposure, ensure that the `browserslist` tool processes only trusted `browserslist-stats.json`, `opts.stats`, and CLI `--stats` data. Avoid using the tool with untrusted input sources in development or build environments. If `browserslist` is integrated into automated pipelines, validate all input data originates from trusted sources. Workaround: To mitigate this issue, restrict applications from processing untrusted YAML input with affected versions of the `js-yaml` library. Implement strict input validation to ensure that only trusted and well-formed YAML data is processed. If the application is exposed to external, untrusted sources, consider isolating the application or implementing additional resource limits to prevent complete service disruption.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:60478
- externalhttps://access.redhat.com/security/cve/CVE-2026-14257
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-69152
- externalhttps://access.redhat.com/security/cve/CVE-2026-73088
- externalhttps://access.redhat.com/security/cve/CVE-2026-73089
- externalhttps://access.redhat.com/security/cve/CVE-2026-73643
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_60478.json