Red Hat Security Advisory: OpenShift Container Platform 4.19.46 security and extras update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-73643 — js-yaml: js-yaml: Denial of Service via exponential parsing in flow collections
🎯 Affected products170
- Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:04fa89c7815505bb7020316b2fcc3423bfa309643b8a30ba4135a761d6b8052f_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:23703e75e04f96e4e2a4c353a3480f5f533827c530ff42156dbca3804db6a3d1_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:538139abb03ba3e5674b0365f23aca268a433ef2f149d3d2347cd902d75e2355_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:9887f5ceb01df69eba4232f7e3a069b27886a8b7f99dcc2809faea4f19333ce2_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:0b783ec3d0ac34cecdbd96a00ebd28f9b5f772917aee94165223079d802cefaf_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:31523c86108ef18ccb2c15f5b9f8279d25a3165b20aad1abf021f54ab82525eb_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:3c09ae02967ecee2db77a0ddaa8e013d5619a8815f2456db2c70ae91e0fca6a4_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:a1670f9d0f55538b2445cdb9feb841a2dcf2f4e1aba0023806464b99d8d4dfdb_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:081844f8f054b1f1555fdf882ceb59981705b6c7f94a602f4a508b2e20a41dcc_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:536961cac07a79ffba1b5df8d2900204557fc22fd4c975cdfd924ba51e0c2628_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:95ca5a8e567285cd9b3c53726796e7011747ad2d997bc5a6f6891c5e2e766fab_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:b17f5fc22a9dabb67f0735fb8ab7c9ccfb9d52d49cb3379d8eb568ccf302b1ed_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:106a6871735d3a612316e72a73f48eae2a93601ac7c9627ebdc2ce7830daa010_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:9c9eb27dcdae0ec1b97e01869510fe460bf44da7a0266f47dbd0998da6d6a5fc_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:be356f1de2d8c7366e08657076e14ea34995c255a0d3c3735f2f73b17f26c3a3_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:ccc9dbdaffd850c62f1ad311ccffea106440194eda124cf3280c1cd420800d6f_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:09a637620e9d7a0723b3fdda908e7f7dda401217816f06c026cd1cc48fc66889_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:4ad2f47b27a0bbe4a32dadbeb2c503ba89102c2dbe54d3a487dde84e4198f971_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:79b59015e18f77ca0c2f4bb2c83591563499475501c7ed82202696e5e7a45675_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:8cdddb346ed0b6a713c6201b8f3dbe3ed02fec86da06c951c5d6c98ac823fcec_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9@sha256:061e241ad3745fa1b8505fdfeacd681ff25a6319bf0c42a84b70892c4158cae2_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9@sha256:466cfca02019dd17c4e7822f0b7c9b2c00b0d5e9cc3ed7afbbfbce5d8d61019e_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9@sha256:7b6f9767faf4de3cb462752b6553064604e4485abd82e82186635b7d7d4234e1_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/metallb-rhel9@sha256:a48f6f5a5c44221376f11e2a4a965a80928abf90240cdf6c7131d0484bdcd3b5_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:53353d38bcf8bd342e28f8dccd64fa0f958496dfcc4cab6899fcf59578f2a74d_s390x as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:8e1a7d7c2e10b7baacea28be7d4d05f91d13b8b1b391e0f4eb225612917d6457_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:9ee4e65a44d8b396d072e235b35ae97afa161e5bb7a6f116dc6d560afa02b1a4_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:9ff8b2740ad36b02a61acbcdc42fa9af69ba096574b60a2d2e0f20e4b2668cd0_arm64 as a component of Red Hat OpenShift Container Platform 4.19
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:11af6ba67862fe2844cdb06e7eb4dd3f30f47434676cd4711c95bb074e3f9f71_amd64 as a component of Red Hat OpenShift Container Platform 4.19
- +140 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict applications from processing untrusted YAML input with affected versions of the `js-yaml` library. Implement strict input validation to ensure that only trusted and well-formed YAML data is processed. If the application is exposed to external, untrusted sources, consider isolating the application or implementing additional resource limits to prevent complete service disruption.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:63050
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-73643
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_63050.json