Red Hat Security Advisory: OpenShift Container Platform 4.20.39 security and extras update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies
🎯 Affected products162
- Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:16aad6f0c995f7ffb87544ab5262a04676d9c597b961516afe77db251569199c_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:5e85404434d52667011fbc089ab1eb93c8e5aed44e4791253b259617428dcca1_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:c86497018c8eef45eda6b4ddacb5340eae8acc756f0d7e20a094f9cd1883c15c_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:f2147427022793287888e0b15eee9cc868cc214e09828bc645f03e541f9f09f3_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:4871aa27de256b4cf26d3cc8caed9cb3db1fb664efa415015a4cd98f9caaf4f6_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:52aa8e31b42cfbdfc4e5378102bb67eacd9902758d29fbd5697be3b5061e00f8_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:71b021ffe76f825df3cf3f6132c48ea6183fb3376f432d9304e913bd81b39bed_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:7607bf5bd3d5d4ba42a351f314a040bc9d439b8ab4031179d749ff4b38e3a5f8_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:54debd6f1540f7b2489970966a507f5bdb119b5d81e4b28f50647b290db16625_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:91668f49eba4a0679fd215a01d3ef4260bd83a447a5cc3012861b23812e0694e_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:c78f5d913cdd4326daaa8fb24b22e31504e04358ec533ca25ff7c86dbfe0d1b5_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:db08ef489d0060242a2dfc202cbc07703b93c873207053c8b793f74673001f55_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:8207970271f4e6c9a6d487d0b103f003e539a411a3ead396a1a3e2fcf6224ff0_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:b272a3d2f2f9020bce93bf3b54fee4ff7ad87d36be348d97297c3a971137d320_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:cefff906138ae5c190b0c6e033ba1bd2cfd356d8fe8ea485ab074234375461cc_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:de52d0d0bf831264b80aad24d82400cee9796764de237fc32c662ec37121272a_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:2ce5d36f67b5d327f7d4c1fd8abe9dbe7674ff8ddaa7af0b4471951547b5a372_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:a01d5ec15c0c34f0d83b88f8251a4c7b3b59b817602973000fdafbe4f20780eb_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:d737b2ceb810c1872d9d7728e4965af62b2f4a26b48b7694ce9d9704349700cf_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:f17114d4d642ecc9120031bfcb25e76c96c9de3a8732278d0ec6b6c19566d60f_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9@sha256:4b842a18749d7e21dcd0dc7b444556d11ee8f1f240713ff16a533aa470bb61df_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9@sha256:55a18c0c4faf1f7c3a30ec13d158815c5fea4d98be0c8130028c418d91c4b75b_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9@sha256:c7614a254ade93f9f0da7d108e9ad23eaab652004e17ee3ac60d5c6751662a7f_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/metallb-rhel9@sha256:eeb03b1cd63bf2389527d3eac499ba5ef3725b927cf2ef20274706d6d8038113_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:2b2ba7f87ec405f7312fa5ee85dcaf8ce616907d6d76891bd190dbe273b8df2f_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:7d298e4fc91152f3d2f378294e0532914c97fce30dce90dc732ac672bfaf5b4c_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:96c6bfe4fc11aae1cdd84aa040837306ea60ea33b527b686bcbd80c84dfc7139_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:bfd262d934de49f1a6a65183afe38ab925e58334f6d720fb6f8fb919223ab3b7_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:1460e5c402441b2417e4d7a3f0adae7d59552698c6820a4cff45080d55b1f330_s390x as a component of Red Hat OpenShift Container Platform 4.20
- +132 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:68543
- externalhttps://access.redhat.com/security/cve/CVE-2026-84292
- externalhttps://access.redhat.com/security/cve/CVE-2026-84394
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68543.json