RHSA-2026:63096HighCVSS 8.8

Red Hat Security Advisory: OpenShift Container Platform 4.22.13 bug fix and security update

Published
September 8, 2026
Last Modified
September 15, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39825 — net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin CVE-2026-54272 — ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:74802f2efec4117a4b4713ff96e635884e2e67eda910511e2b8bd0f73e9323bb_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:94d8a3622922ee879462c8a37781bfa83a49c6ad7b47d56d82089e29745827ff_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:a0e5ce8f366d0647b5752efa9264bd816086b57b1bc90c71775c383a098284f3_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:c1d4bd3b909ce0dc2393ab3e45db3928caf1cda753092cd5f483d328f0ea2d60_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:426b8a1575bdcb710c29456d614d65e77dbe1db34c119507faae36ed51c677aa_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:6f09b8d2effbcac8d420699485e73b51d44eed78fd2c1ac522f2cd9e989f0629_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:7c4526426837b3d3111c84d3a184a554cf6b4ee42671306afae180c51dd84434_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:cb4ad999ec5e59ff38f71e285e8ced495dc94802684a7c9bf02462c73e1e57b5_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:25e59b02462ef8f3f90d69d8705b1cf29348b8ee7c2cf7017cf97587adcde843_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:55725b4f8fdeb5bf8d8a3d8fd92163731ce9620293aae32c0a636ba5622fc2d1_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:ae6f5143d6053d7e8979cc378aafc1ccfa7e9b16bbd1c3b039f7a0e11a31c7af_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:d1558f1a5b086932131a0cbddf40a804d94fd706c0830d771616535f86cd8c60_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:1a279c7adbfb3b08bbb3624bd722ca1bec73a1a2158869c11338050215aa3fca_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:564d78e487cc70035fa8ba69faa9427aeb6ad2717cf768c97cf14c3476c8df8e_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:690f82b85ef276d943c7a1e00a713c71e52b6ce729571bc8f00d3c4f9a3e90c9_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:af47c98ebe3eca85bc13d176854cd7a82af3f23335881968b4e1de31744457e1_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:4954d349cd19097f07703a039dd190ec516e92260144e97237c303ed9e383a77_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:4b0fcbdfafa940a34b9a39c42374b9965a8621e0d80748f5f3662e1a91a82317_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:55334fdfd9abb190afa1364c6c1c2d7029c448c806758307ea97dd64a92174d0_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:94438b5b0ea2d30a3250162ef3161507e927862892374c6ebc2204cd7f9c2185_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:204ef7aa22dc1cd03a26644db6e2ba69574b4ea75d47982b54708e0acc347757_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:3e717f8440ccacb2bcb1f3420c8d3b69f3cedc45610f72a1cc8ab75c60d927f4_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:8a2844a7b8844231f5404268ac7e6dcec1dde54cd00d871c0aeb9704baa9cd12_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:dd90f16c3043d68a10837bbec70f72b9ce3e790ee453832fc82e0be0584da408_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:0069a3ec1a5d6f1223b1cf1f116c90f664fca1e877f1c163e66f8c28e4a9c413_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:657d35b0c141957d74602e6ab7f4ae2fe4899bc034683004e3d4309ca891aa8c_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:8534a0dbaf44840d3609468b17b6c6bdfe02706c185b129b9605d1fe72b4a116_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:a0c45ffea6bfdd8a5a5659ac8cb2b80ef9fd82a9908c444d73840d010e6378cb_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:124b41efc8d599f7d795a17c30db5754c3ae70d284c47ebcc9a3fca394b7dfd4_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.22 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:8f308b9156dd690ef5b9474f2cd2fe6f81c30df3669cded5d73ec5bb34c59fbf (For s390x architecture) The image digest is sha256:8837104fba3990a413f3edd2947f27209302965a9454c0bfad99d235ef3cf802 (For ppc64le architecture) The image digest is sha256:7c981cf39369942b5c8995565a39feb8403b725fceeed548670e3be750727de4 (For aarch64 architecture) The image digest is sha256:7b1249f09c40d019084788cb46d8cf5ba678cb5fa8a0758c2cc46546b88c6023 All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Increase the maximum number of query parameters allowed by setting the GODEBUG environment variable `urlmaxqueryparams` to a higher value (e.g., `GODEBUG=urlmaxqueryparams=20000`), or validate and enforce security controls on query parameters at the backend service rather than relying solely on the ReverseProxy's Rewrite or Director function for security filtering. Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path.

🔗 References (9)