RHSA-2026:68541HighCVSS 8.8

Red Hat Security Advisory: OpenShift Container Platform 4.20.39 bug fix and security update

Published
September 22, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-55204 — haproxy: HAProxy: Denial of Service via HPACK dynamic table insertions

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:2465258d254399a2354d817d675916bee0b53904c674874c20da4378db15a638_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:490d30e48a2e9687bd9ac37af0b0d59414da2da7c984fc1c9b4ea8fe7a20968f_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:52e0f771e6f5de4f482c8b10db9057648dc0e4bbd093f919b9c6481aa2777535_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:d7926b059a021dab5a84ea050e5d5cc892407522de6fecbafcbc6ee7da9660a5_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:13c9367f98ef46ab1f66dfe05bf75057c70471ccee42da6741b57de3bf6d7a04_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:87bce096ab350a7b3b98845b5a6172a6a698647e7a374319001b6a0a4c7e4cec_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:8b64f547c23c878d5765eaea3423d187917597771aeeaf3c0d347b4b745d6f3d_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:926e13da09de22c426554ad402a0925d8a543ea8048808a1061c8acf1afac1a4_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:029b242f49c6b697cf335e28d04d76ba186e30b929a3944b0de644105a3c30af_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:5e21409eee3c972119641cfeae9e7e4f5aab1444cc58643659bfb27b538f8148_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:81b5a874d626fdf3cc664bfafc7175582823cf59a40708ff106e5f8b33e3b68b_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:fdec8978b87486a42aec4b8e5dee2c062652d81a25cd4becea6c542230dab71b_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:0f3cc803b720ea1a0d4b7721a4040a7985c84a9538f99fd3a3e9b33d65c94849_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:124af2117cc7b065357e92644ecdd80c48528de8e37d7af1dd8b8fec9f8178c5_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:6219085d5565e093eaab22ebf82d1b1290e4db5eb37c6670a50ec8bbd124d020_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:acd59e8e1fc2d22cfd68d61d498b44d3c41847dc76d67541425402c76cd67e89_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:1bca9be9966f2eea991ce44ea816cc470fad6faeb7af4215b4a8e2e640612ff0_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:245b3e7a52f1ede8dfe53c7e8d55cef5b2518f627a02589ce3a074e341b82563_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:33fe3ad6d6f165c3a87dac7f5b9a153ac65c83026f82a2854d610f75e363053a_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:626425eb234f6a5490f1b23634bbac811f8d39494ce5bb71fd3648568552c923_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:0ef23f12d6254d399d7562bc7b05fd6fd7daf8fac48b26def47d2a4fe38c0275_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:564a1ec6b697f7ee796de22dc48fff89e69bfec13637456636d32f9c066224e6_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:dbeb005645d082f4694574aa21a01bfc58f3d88cbd4ad35702eb55ce57aa9ed2_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ddbdf9495a17dcbc02142a769308ed5f27a3dd351347fad42a0dd0d78f7a084e_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:2567ca39905460a6b15fa425b66e9ddfcec0f571e0f6b72c699dde5a67d778f8_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:3a094828202c0b759993e756ed3237f2e5b8ca1dc756b298570f1ada661717a9_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c3675eac9ff068adb8ba5a8095cb1a9f3de2e65c4801ddf366ba190ee75dbadd_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:deb87f16b1c75b155cef2474b25c545e69a4aa37e9248d0ae4c5de9f6c09f434_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:803d067887d2a6d34ee8e6a622f5ae9961b152f0d57368d773ef9d13b274a1a5_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.20 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:7bcf96bd0766436fcc30ac30d4bba565d27bfe5772d48177f1afd65878209850 (For s390x architecture) The image digest is sha256:4f79a1c1c536478825ec3573776c3146a5e56614a4472291efd9ec1cca27edd5 (For ppc64le architecture) The image digest is sha256:17c73ac24fd849434f46640851d4b20ac6221051c7a70c8b54dec6589c27f150 (For aarch64 architecture) The image digest is sha256:81f2d7d41ee089fa0f1bbc60c6ebd158efc64a12a28280e3586d16cdea1cc33a All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input.

🔗 References (14)