RHSA-2026:65853HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.18.55 security and extras update

Published
September 17, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-14257 — brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

🎯 Affected products192

  • Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:53a93bc8d8748a2dbceacf4e4f382b4c269c54c8414225bbe5f722a0818d1721_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:e4729e18bb9616c209e6dcef715ce71a70c535d654a90ab8601e1e6d16bcb771_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:eb875e789cd639c929987d6bc313b7d1cac6cd39faa49e8081c4a046ab2d6e08_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:ebd30373938bcc82720492117001d21d7a9572afc458d8ef8cc4853cba1608f6_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:224cd2cf95bab4876b726617f2b4c4207ba2885b6b8c3d5d84d68a2074d83ae0_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:5e3d7c906b8ffef84c1802a64a0fb34a51399442f44cf3448980fa7497c65a37_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:97e7904074d51a12484e66fd394fd2808bf416a717dbc5b875a5545a48062741_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:cb3593a5732b39e7ae4cf9b41a2fd9e8a337d4137594eab3ba8ae498402e4043_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:24e53672b507889c7e745be3fe162ac11f1691fa01bb24e00f2a7cef7ab63289_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:66b6d293cb70821137d5002dd9069b92faa582c860193991f87bf2af05caf841_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:7687f455c6699001b76bc761d41534eed62c490d9529db9a0116e1d79750fb51_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:f2115398336841e4039a2f8c208337afdd11c12a725e6aefd55899092720aa6a_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:77fad39368804cd3d530b176fc9b76360862ff5f8f3f75b7d48ad8a5f6114077_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:9a93f62889e0876c44574ff8e338532c855a89591020f5e762cf6b6c31240109_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:be1dcb7ac2a4985cbb687cdfcdd2ee601f8d221e44ba81fac7ecea4da9330991_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:cf268bdbaa6b2c0e1a963398cc98766bc50c5714064cdc4e17fb05c7ca12d0d5_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:8c2c96231c5b39e3625e32e57d3a8b3232b7cadfa0c20c2ee86c0c48cca1dbad_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:b5cfa84eb2df18da848b2441fa03d0efbbe99e00a2fb30a542338d944973b42d_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:d9017b13c941e51026e8f8e97b1b73bbf633abcbe63fb323d46885f3d4c734a7_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:f2ef6d61c945a37408af87b7e89d07265ea95de919d6bc02d17f0ac6520da63a_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:3f35cbf110d7cab1d61b8f0fbe1e46749c7f259a17c33aa39ce4927c63d15107_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:432a12576b59db48e5fcf92707cb4b65a47ee800425961438d89f0e45f8dde58_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:6efd034989b8a9f675ae97ee09e37a36e620f67c5582191fbb936860984a7079_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:775ea3e4e55822b4419d5185e52e3b11f639710f79c8e95f5cb5dc07b5b2841e_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:5104f7a144a515ef9a4dbd14194613f7878f02eb3d2fe05b9f6b6a3382800d36_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:84f1f551544b1cbacc3eed9255b2be8c03291af6d8de7f4b02bf1a60d694f3b9_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:b807b801a61e9f4546835240c390222704fc134b7d9c099ca2dc1d6a429f6011_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:f038d7379f978f1c83adda3a3314a00d5f8cf217ac06be0faf3532cb9db492e5_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:4290894ffbf716e9778d3a449485057c5ec10f1abf83c163c4b691ce1bad6abb_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • +162 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function.

🔗 References (6)