RHSA-2026:66372HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.19.47 security and extras update

Published
September 16, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-14257 — brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

🎯 Affected products170

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:43e158f2b467374301238ba1945e6964358bb982c6db9219555dabcc033b9286_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:45c76551598646bbebb7e0106ec5f0e4bbb4560c24f48336c7aa46175fb20ba9_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:b2ff76596e02587281e9f93d79688fc7d53433d328bb582908e11d550f10de4a_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:cf3fc0ef43b49321ad4da88319a011f6e76e102d06d70db268c5d7c65755f683_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:0b8608f03687ad2211d529c830cb57c1c62a88bae72809bba368e1ecf2002682_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:26b6805e1c614740ad77a655caac9bb226d8a57e3273953d217cde12252abf12_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:709a9edb8421fa09612281b41df8f1113a9fa294460a13e11dc6d778801641ec_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:eccf7fedb581eda72a33e814d0f3d39cecb574d20d26ca30213c4ed8252d2835_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:2e4e2e2fa1b3e018b92f250802c7cc197829e70ab3d41d1dd130d4746a028b45_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:3e79e96f0cdfe3f484a52ff37ceb29df66661fe06bcb6413e321010792163988_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:a3add00059f53977088e56db8ac4124faf5f1e29356147ae30f7218fcedf38de_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:fbe3ff421591ce27419f37c3cd42c04b036612141adee5cf9d981cffba217b6e_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:34c08f639e9eec1f23256ed456463db2a08c608af41d818e4ea629208e7bebf5_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:3543212c1a173bbb8649eb4998f3c49bb7a9ca74ebcd80d58b7b986da1bf6aba_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:5d1e35abbfb688f4ed7d58e28d20f9c508b912e885451bce86aeb43957dc88de_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:88a8a561553a7cd5866aec907d3196c9c27490631ac4c3d12248d1dde2416f12_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:668db3aecde4fe769f6875b0bae34438ec9fe06d7eb8258aaa797e476523eb9a_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:cadf26b5a46b10455130b7406624409f9467d0bd47fa0fb9637151aba1042d64_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:d86f389d8f237377201e27b92061d7616cf6b23647f38c7b61505eb3ffc82797_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:f37c67da10062619675733b0b3d6d7b22d39526b088c29d4f0c85fc0ec92bec6_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:33d49d173be4690da4326907068550a69b19dd3b1d2b2c382292e414d627ffd4_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:5cb99961884bf8ee20d9ebfe739645fe15e64b419c55df65ab095f884510057b_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:7cb85351b0cb055a6bd32c2a882a9411c52dfb330a02f2d73037eb0f945a1f80_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:a1369f4ee83a58b9475a8f6e6eeb44c439231d11531b893fd9d1bfc2c295deca_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:7379b65ca581b7782f3c5741f6385a210f9f547c7bfffab8aeda07f188ac05a6_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:b7fd4b4f0196852e7fd9a95c0a7ec51ff459afcd6be341863f64534f878e26e1_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:c89eb4a85af8ad60e6c07618d429039d390e7aef0d6540c2030f3fd8cbdc9d53_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:f60ec2fc3e80695f3aa93a4be3298dac4e892d19238d5b1bc0cd85161435bb00_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:45bef9006104b3b7fdf2a28f9fc93ce799089ea62c068c9471698c44f5b3747e_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • +140 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function.

🔗 References (6)