RHSA-2026:66371HighCVSS 8.1

Red Hat Security Advisory: OpenShift Container Platform 4.19.47 bug fix and security update

Published
September 16, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-48801 — linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability CVE-2026-54284 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:46bfa948692d2c1b83a6950d660f0936d7e99b21cf1fad88bca7feb8bc41102f_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:517b0ebbb71810e053e67ccae479a085d4fdf8ca6b152309382335da3a933b61_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:5e669d0a14e48161266ec989c2356d8f87ad2cc46ec0ece30a6e2457b460d6a1_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:c6b5a77de86be57ba175dbf2325900491555f08b7b02b51f67aa3ab4c358b795_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:085dde6e9fe76ae1091d00c2fa6e1b6e63817baf1eebe2c4f993a6700bbd0108_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:2aaa44ba30a1e34575f2bc03bdc1af1708a2f4d9e8a74296940dacb6a862d2d7_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:422f7413a4ee172e455cf32abced86c008768f3f61de811dbd18d9406536fc9d_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:b2613917240b7ce4bbf035afc5f4680aa0345fb4c77cd5640d796b66866e72e4_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:235319249db8f5b2e0c5f3d464f9c12a04d91f38a7be7f342d0abebd7b855750_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:437dc08bc22f1933d4f9c0318c62473bba4f2b5c018772966f8de05561f79a4c_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:85247a8c15d946819143025e690f7fc0b0b6418338821071738ca19e5792da70_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:9ee18d7a3c9ebfe37275504ac9a68c4f2d4234f6aae7be69e00252c9812df8f8_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:37b8f01a3fd50cfe47cbe73ca0ac93068a65c8d1f8a02e67c15e0a9bdf7be34a_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:7ee934ce2cbb8df4a46d679810e6b794caddfa74330fbb8755bb9019930016d7_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:bdb98fce8c8e9667672377e5265ebf8ef891fecd07b8f930f3a19f22dd251d89_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:de59175af412cf0f9fba41a8755fcfbbcacf102d9742409fe717c87e98cba1b5_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:15fd43a734e27aba1b4f23c91e49d78fe938388bb1d73b5232aa806827f0f7c5_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:4293f4f67aa68894cedee162a4e14c0bdf19f09b47f47d5d648a3a6bd063f1b5_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:ebfc1188b8048e8f7a257ce3379297bf52ffadd3d8664f94c3a25decc501d801_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:f10e118ed419514c320f55c6f14ff1daf9f2cb8585b5de374d3a6316a8f925e2_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:082529127851ccd455608912b07f8e1d632faacd2dd5a3a3c17e0b32a15abd98_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:2dd48ca32df9c69f16d22d14f0af515aecc4b6711addcf30f01aa588e6a2cd36_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:7957572ec7f5c99b62c8b93d9a42099ec449a961d607c6084f77ddcb2f4ffaa0_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f9f64d4d242b577160f7f8bca3245d2a6a1a3d8ab05f84fa80b51d86f2f07bb2_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:47e6c0126ca5c11a18963bbf9a542d8ea7f298ab397a8c7e48777fe96de04721_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:6bf064656c3bc7aa2018ee349c4423149896177b442e4fe2fbb3e5f01c527fdc_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:6c2eb78afd9beddfb5934b40f37b6fb92ec140f86811310db65a6835bad4a617_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:7f6a4b5d95ffa6cf54275dc00b0297d1fe30fe9cbcd9f0aaedba322676ca1038_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:5ef711493210b2e596058f3b2ccc8a59ef8b3be151457228cdd00ea60a448389_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:e72a985ba7ebf982562106d065333006d7b195712a157698dbf0395fa1844a13 (For s390x architecture) The image digest is sha256:8e00496811f3df48f0f5a1e2d86939ffa9e7e617777bffcd091d114636d711d1 (For ppc64le architecture) The image digest is sha256:d10e7f6be85a49dc4da3c4f7415330c109b5be435e603eb12510a37a1c111b6b (For aarch64 architecture) The image digest is sha256:d2423d27cb8044c050646ab98b30c96e3e80a100ff92055c113d52301426879d All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (9)