Red Hat Security Advisory: OpenShift Container Platform 4.21.32 bug fix and security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code
CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass
CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input
CVE-2026-54272 — ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification
CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL
CVE-2026-73566 — tar: node-tar: Denial of Service via crafted long-path tar archive
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:12ba23ef53c7238f182c45f84c8145cb81ddf26d79ffab637650a8f20a9f9da7_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:6d5a39ae203b1e972ab0239447a327e9f7436408a0091bee33f605ba3e1b602e_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:cd45514d9c8282a3012a1fc358db7be2a55e2547ba80863cba0777b560f5355d_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:f56ec4560a28614072531c3b0c9e958ed9fb2a8318fee70ee1be8a8bf5034f6a_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:3376ea7b20361197c7a0383a8cb326fe22f4c6dfba7e63a0effbfd19fc87e19e_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:5ecf127922ce156d5777aa8fa76588c8abca801a22247ae5342f78fb25303ffd_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:66b135172201747d0448adf2de59d0ee85b830592f1b1833478abc346e7074d9_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:994ab7db17e7c307c09518ad9f1b3d147be59d3a2492e62873a62c5c85004d3d_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:681c53a8a8a0ffe93641f80079728371d4e355f9ba29ecbf7370c60c7ecfdd4a_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:8b4ba37e65d1773be6ef49ba9e5ea434c4f3a1055a0e27afe65fd54db499cc6f_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:cac4f53e54b121c03da6612f5453c15fd45d660f24d78c76f03f4438e89dae0d_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:e8adec6b80192f1eaac285a478d20952e1e78ae1993ced3489432ab944ad283f_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:45cec57176ae5f9c21b3e22913163855fb54ee620043b7488a7521a48704cd37_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:a576f7edc3bbb1ec9f909ec43b0c53179b99f9df3ccde9ce0c88fdd031d052c2_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d1375208619cb2ccbcead141c9feae68fa78c7e5deefb5d09e24cb04716d1afb_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:dd88a733a2b80f0c6ffa4a462c5f79c0c6992c43cf1a70f67ca8526c283ae07e_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0ed05ba0ba0e07391fc2555b18c1516cd9fe1a84e640e7de4a9f4b69806e492a_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:48077e8b9127270e3eb730b540328bac3ec7f8a3e75e2e0dd19c4403932b62f2_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:7d271ec23ee78642f512d32f64962dab39bf9c8b513c2a7bfc5e55d6c0d0973e_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:abd0f68ecbd281df878fabff2260695d20252b4ea188dba6eaf64aad4b061f2f_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:32afa61c14072a8268e9631286d5eabeb5dfe8ff963f2280c435ac9b030d26d5_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:909636829a4c5b8110c005edcd10b95e1ab2e86337029e12d532bfcfe01a7c99_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:b4e76354832799319848e988eeb5dbf91f470636465a289bf45756d4d0517ac4_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:be2280c730c73a6f028a69ce084711b9aeb3c7cec46db3a1e2dcb2f34a48d51e_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:38c34dd7880fc90da3d8fc8d73bc83471efffaf6459f0a49fcd317282dad1a0d_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:a1f8a7e64075a7644d3174bdc73e323d1f75645cfbe19b17a7f41190da58ad17_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:bd098467529255912682ac53f99a9c60ac2240ae270f580e6d3990c2653ff81a_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:dd65a519b45e33b409eef09606e22723f68882095db8714d0cfff4040a32eaa1_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:4feac4359a8b8e942fcb31596f53d4ef75f0c04c7c8f44295f5b090d2413a256_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:51a2690f608613a1fc11b8b5f8cc5e6e311ae721c6851be6e79dd8f2697ba97f (For s390x architecture) The image digest is sha256:1281b13e6ccc78bb0edcc6a21a50c66aacab47a2997b946c71c20f283b6006b3 (For ppc64le architecture) The image digest is sha256:aff00f86eae7ffeb049441e825cfc5725d0b98168888b4789a36377b2f518a13 (For aarch64 architecture) The image digest is sha256:b1d17b8b1e403ca296a69de4715eaf5b4ecc4a8f741a1a86f6fddedb00dd31e5 All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:63046
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-35469
- externalhttps://access.redhat.com/security/cve/CVE-2026-44990
- externalhttps://access.redhat.com/security/cve/CVE-2026-45623
- externalhttps://access.redhat.com/security/cve/CVE-2026-54272
- externalhttps://access.redhat.com/security/cve/CVE-2026-69153
- externalhttps://access.redhat.com/security/cve/CVE-2026-73566
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_63046.json