Red Hat Security Advisory: OpenShift Container Platform 4.20.37 bug fix and security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame
CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API
CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass
CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input
CVE-2026-54272 — ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification
CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL
CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:7de320196d58210798fb7d811065367e8cd69ff6b4f53ec7f48a6a0ffa978dfe_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:92a3110ac0d5f059d70bdfa5f56b9c7224541ef09e835ac70cb874ef86401e2d_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:92c4cff4e9ff6991f2eb2c7de15ca1cef938b5235c7cd052e09e5c37ed215595_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:e191a8be789cee7f00c65592e66ce609afba034a85322b749679a9a5788a0edc_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:0ca0a7656fc295d4dc61c96ee85964234c84e0b6c8945c5625212aad10a37973_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:166d0e6b44c52db3944e42f479140b0a1a026e1ce575e6c8d8dfc1e132ff9195_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:c7f0a405c8597d0eefb227c774a83c5def494c5d3a5517a91bc259eebe527eed_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:fdeaaf7b847306ddc1f52eae2a393434a75a9b62bb31846716ee6ffc19d340da_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:116b2e4bfa10d5398f82157e8158238299b1af551d36f2eaceed4e2ba43963d9_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:1e957680002dac391381f6ce8bb0d5ecbc9925c8d2cd86f944785fa87c0d1df4_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:7d51e904e0a41443634f33cf62d9586c5aeea1a188a48d9e10a71758bfc3329d_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:88999690cac30f3d252c6cbe1ec26dcdf2e0f35f4088c30fcec44cbb23c732e4_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:1a8861bada16e826db373bbcc54c745d7b4de9d6b9d29b9f26c2875ffeab2a08_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:30451aeb1e7dbf4cc11141f17a6794ca041b393e2fd066fd9bf3dc9a1c7f2d66_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:5425e3c7280da6e5291e73ec6b8ff48ee030c85e9096a00337ff55f2f311befd_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:ec7bc340f3f4e794b717462b5c26fa6a973b0a4b401dbf5eb1ae459c2fbbfc31_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:4f6ed53803e2af8bb70b0471268ac15381b7d2d2a6e21d73dabb508833007827_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:95e6a0de452e04bad75e43729c14f05e97d66a2fc6e9dd95eb8977e0791474dd_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:cfa1f20b12108d6e36d98c0986fb18aff96ce5bd7dfa2a49dfd37f848d20214e_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:f74f66ba9e9ef01870b5f3b250b182268e1565486944b4606f6be5726461834b_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:0b52463575f6b1219553426449bc8ee37351bae2c5eff2262dc8c1f95a4e82c5_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:38a402d8a2ba9b970fd71e477648009c97c545fc5cd0c060581f267b9e98e675_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:91c5bcb817407f51ddedaf8fcf67a7b0b175ea7df8d711145229d1584ae9d346_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:dd1a4cfb89b987e7157052fede3ab2bb81d57520941b5c4b93c5d89f8d58c027_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:0b06ab85b877163d2fc04ff59bfba0f568a678f673367439f91f3bdb04c215d8_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:66a0a429ceff365454dbc956cc507ce823493a0f047de1f18b1cd85b3e524c37_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:6c999cf5cf91c54876c66fbaadcd850648de826e29115e8f0dedd7e151f6a94d_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d61bed436e55fdec2cecc81c2264946a035c1c73fdd26322e20fa580bfd2cb8f_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:26e2d4a6c66d3b67015e0b824054d1e32593484e499e43a86517010deb6ee9e8_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.20 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:d8d5978e31ff54deb3e0b46d881aba8df4fcceaa9299b947ec38a5e9205834a3 (For s390x architecture) The image digest is sha256:3c5337ef4726f3928e52e4ca26300282baebf2426d12e7b7de632318bb0261c2 (For ppc64le architecture) The image digest is sha256:9d62a09fa13894c44bdc69b7747b12dab6241b07d6b00a4580ef89b3d5fd30e0 (For aarch64 architecture) The image digest is sha256:75873185de1563b0c6af45e73370314cdf676bd0ae371e049aeb485e55996955 All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:63103
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/cve/CVE-2026-44990
- externalhttps://access.redhat.com/security/cve/CVE-2026-45623
- externalhttps://access.redhat.com/security/cve/CVE-2026-54272
- externalhttps://access.redhat.com/security/cve/CVE-2026-69153
- externalhttps://access.redhat.com/security/cve/CVE-2026-69192
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_63103.json