RHSA-2026:68547HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.21.34 security and extras update

Published
September 22, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2026-16221 — fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency CVE-2026-18446 — fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-45819 — baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies

🎯 Affected products171

  • Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:0342c6d84df585eea6eaa05aad0d8a1bf8ba359d9682aac92f11345efda98f55_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:bd0334d8270d178b5630d7075315d6384b282da9ab211e6e864362bfbebebd72_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:d81975f4f421826b3d911f220cc97f23361149e521d3e3b5348025696eba0467_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:fc74866b470f7be984d48792697fdfe8a5c0e0ca9646017ffe9b73476754e35f_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:496cd27b991d5a8973be71193df84c62fc5ffb1cd476380da0ac197e32ffd7dc_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:7feff0d81b3108738a96a7bd4b2b88f71caf4ccc44b2c300b973526c9efa703a_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:bee9310c48c938a7567d45b4bb02fa2411204122a06b626a66bd162471f2968e_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:e5cb8782389cbf8a7928310c8c9da7e9a97962349ed08df7474b99b318f61b35_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:2dbdb39a46c9f845f554e6c1b5791989077e94824077812bd479f0f7b16e69b9_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:c50c1c0140907efdc5ceb8c83d7b096c27442be3f8fc448f989e5ecc9bc58617_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:d2f6a0f14c7b13c3e4ffa61de06e2aa1a77a5fa4f773c1181a30c05198e575d1_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:fd0bc6d4c72673d5b6ce1274ef032f63f408603634d62ae0fbd1745462dfce06_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:46c87be5a7759e2b303eb77920fe21f79c67bef37a465b7e270c6eb593bf5472_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:bc28468ddbe0c7f56124ecb8af85dbadfa4c8a3a72033a8709432854de50ac45_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:c9d5f22435861a9b7824fed6a6389b2032b174b20bfb6981bdab83b1e48ead58_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:f6594a166bfd368e5326dde61ab2b331ac5e27b01fcbcbe5246c901f91c0fad4_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:0a642de41f64d8b952308fca9b680f1225f396057cced77aae821851968ca17a_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:4382b226b5bd931380de16250e9c099b2bcd7067787bfb0fa0ecf2ace03ea384_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:6826f78151172ef1faa7fe69a5d6445ce8512cd6de83e7aee5b21b9f7af2a43e_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:a915fe1ad4e9e38cf9079c93b5afbe3919c189d8be308e207b34855fbcac8831_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:3a8ce0cd0bce2c81fef323f39b8116002bf8d44e751fca9353f33007ea256a15_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:a2e69b859d971ddc69054ee4dc9ed47371f74e9eba91000c062bd7abf3442bb7_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:ae89579f6a8862339322df50b7ac6a02bc5b1280e1fd4da3272b1a17cdd75238_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:ed6f7619aa01170d0a824bfb86a280ce35515d11555d661f874b325dfe4ce393_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:203d505f4065d3a370c5920413a97c24aff2b0cd7f9503cb05a6432b33f4047a_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:6c27e17d7d4ae7e88f6287bfde36a34a33530cd16ad154d27d2b9b9de45b42ad_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:9ded64d3e1036bcfa6fb8c3cb95756b39f013ed6552708836604d2796a449386_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:ccd0f5e5bb118037707e0c2e348b4f7cc42960a567cd8840f1241d4344e93d41_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:0b4d7dcabb5a6800be709631b1708443fee536cdedac1b1549455153721718f2_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • +141 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams.

🔗 References (13)