RHSA-2026:66377HighCVSS 8.8

Red Hat Security Advisory: OpenShift Container Platform 4.20.38 bug fix and security update

Published
September 15, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (12)

📋 Description

CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-44705 — tmp: path Traversal via unsanitized prefix/postfix enables directory escape CVE-2026-48801 — linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin CVE-2026-54284 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in SQL parsing CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:09871c1dd60dac4dcc0cb47c6f4d66facda6e12a48f69283cafc0ebe952c519f_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:180e2b88c4cd6bef57f7743eb5ce5162e819ee0092acb5bb1f401e3ea27f4564_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:915f86b799943b72973f9c0c3e9703978e2cbc707ce136ba81bf818bc91cda93_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:d2d3ccf617f3ef6ebe7ff2be0bc2d94991eec6633cb21ce68b921a43dbcc88bb_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:0cb9501d17452b719e91187f62a91c38beb35fb8b4056036814be53a791019cd_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:51e07ad0283cd40960671621ff1993ba2f6347d16cf432758812b1a6cc557718_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:6a71b34fa9cbefccde5393a189e84dd38c80dfe462f4ac9494400a45e3c9c2c0_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:98ddd2d64d97ce4c982997f79d32debf9aeae140166c42531d9e9a931876260b_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:63be9f8c4f2894044e70bc0afdc9c3ee479712d986986c530e6d2b3587d7fe77_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:a511ce0ebc53d934389cd664ec4ecfd490d7c275dbabf8163187137c4e6331ef_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:fa49c39559f5760feede4013b28aac58c21b1d4cfccb3092172a27c91152c064_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:ff24ea701c0281cf5b56031412f861fc6bfe53c0571707c79f5b8fa8ebac8665_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:924d3fd493f793538eb8cc1cab0b77d43850e2f94823e7ab0f3a5dc51c85c20a_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:acf891c190c314899c04f19955bbba0c9e2641734ae28cf3f67a6b6ebddea14e_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:af55c80c80fb263eeab85ddc566720e8f2ba8d144df8501c17e2b58ecf7f1a32_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:bdb95afca9a8375094197e929bb2feb3df230422d9fb32c7442a8baa6b9040d7_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:6607cac3b7a94bc7592cd2d56dfb13fa86708c93668c5e399711809191772efa_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:7c8c579b525ff8966b6a343ec3cfef111e85cc5f18a05b1890d1e62191c18fc8_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:b9794d4c1032360746ebdb3484ca3e891919cc6edfc21539d4bf688089d4343d_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:c56e42b739dc5f887c6bec929835beaf57048e6805d7484eae27d74b42cde9d0_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:4ad1dda75e690bc20caf3e19d2ce39273e99b767417a9b994f4f10de7435f0b9_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:75bdc54ca589bbfceff915bea0636a3521998a11337de2559c7ab45654d91d48_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:a5d8513ffcb9feb548a7de1496ea1e6253d654449dcbe2324a77e7f2cf2da8c6_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:c298a3dd702a0d049c81ba14ad582d7d1e25195107443025a101208e4fd51e9d_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:1bed7042c0637155572f0875a160bbe9e90c875b613adaea7ea585449bd17455_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:56cf3fea6cebaddc6877eb22854ba5c7380807f8b546db81b6efb292b2771e89_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:7a408cc5a254a955e65a489c87fcdb182e304b5a8bedfd32f2a553145adef0c8_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:9fec68ade0435d9db412007442100f399227c68a5a78939a0d593265d1473266_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:1919f2600ae22d8ea3aaef9f01c3f57f78f1375efa2bb6a318951325fe369ad2_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.20 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:3f0d4394db6d0248681f0cb1ca1f724d3a9030cd8fe39d24d9a6b6bd1e08c410 (For s390x architecture) The image digest is sha256:b0ea40ef98999507e414966718a874807ebcc87682f486826d88ca85948b92b8 (For ppc64le architecture) The image digest is sha256:51c9d537744592a8e76365293adc80622aeab54d7e141fe67b29d17294607dd6 (For aarch64 architecture) The image digest is sha256:3c52d4f3e5b4525fb7cbafe696b2f19dc4fcad78b894ff62c3791883896c5a62 All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this vulnerability, validate and sanitize any user-controlled data before it is passed to the prefix, postfix or dir options of the file or directory creation functions, specifically rejecting or stripping input containing path traversal sequences. Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path.

🔗 References (15)