RHSA-2026:68553HighCVSS 7.5

Red Hat Security Advisory: OpenShift Container Platform 4.22.15 security and extras update

Published
September 22, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2026-16221 — fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency CVE-2026-18446 — fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-45819 — baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies

🎯 Affected products171

  • Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:0db8af7001d10980fbe4e1ad23ea0b21ce856059e453d8a97edbf8af0765ef7d_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:7d242b798256381b70376ec0c48e2c7bc28bdbb124bb490a91cebb9fe5079f78_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:8391de80cd2befd4c6c245da693143812a390458086c679a0b74aa498e579b86_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:cfabc894d04414450c05336978b28ee25d3ff66db3c6f15efe81b0a164cf6e27_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:5a9066893d5ee9328a7eb8a645a40ccb558931fa337632dcba66bea071023559_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:5e3c058c08e1dc01c93b02a10408ee35f930c788eaf0ecfe9fd91f4595ed648b_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:84bc0a244e60d9238e6100f9b126f2dfb5b9d7d3ee49e6c4ba87bb6dc7999dba_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:fec6ea83eb05629e5f8ccb6580e1c80369420f33a7cb9dfc8f5c4751a7f6238b_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:275b9777b8cf9b30f954111eacd4f02e03f755eeced5adcd2a097b13c4840ea6_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:61c7bfdd0538aee83bc45b383c6c0a9024dec8200ea691add338318b61a6b543_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:cbc37391565319572f89e829a6d042eccbf2990b63c65e6b29406ad3d3c2c748_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:efa0784630ebea673f51751403035c0fbe40c1791a7855030b678940af7005ff_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:195c96b0a3b98ad0c365880ddbb3c4c042fc4bbea28c49f2348a23062fd267c5_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:be9871384392a123c7948d81d24d11e0f1a5a6eca5db4213882e0b6c565523f7_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:c7f4b082fe4b2d5e6ee9af4357b5616c7355bd76c18dae79d5c98b26ed805524_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:e1aa85f09a9dc2a336aaa580d9adcef62c02d186637c63763029e79f4ab80d25_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:3f45faa80f868d080605e1965459af05a124f58a185e449beddfa63ca2f23f88_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:8a1aa6affb4b0d8e7b914dd51ee60a5ca4f25655323a3a876b7d8c7674af8258_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:8f13a311d939022381a5b6ee4d5de1991c2da5a1ad54be7625e96fb59ac80426_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:df33946310686b4c561b0e737f49dacf89c62360aa3f5aac79db7caec04cc5eb_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:3bedd33b5e79106f94cef2dbf08dd081cf91177860b766eb0f013f34723ca9a4_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:5f6117d46e1284f7600e68f72f6f0ee180664f1bea751eb4f063fddd6177b738_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:be9cc15775e0129107dcaeed5711f70ee89116df62dc54eceaee57e3397806d6_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:fa526931f1b84bf6d626be6a61ab05140ae9507fcad47e1ed63f437110c28d42_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:02435dbe43e97648cb32b32359fe3241f2da3de04b5c3a845eb5fbbf235cecbb_amd64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:599692d1de811d319dad9dee84cb6cfecbd3b8ad03872bbd4dbbec7fc6c1c219_arm64 as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:5f6ecc813da5f82f71021db75936beb513458b84aed014cdf60a9eb13f304f75_s390x as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:80c32891da9181f96d01f479167d434a25a8156f1f19b6a07940425bc46fa2e8_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:0b7cf56ab4849e5900d6ef5cb6ee5d6e0bfc7ebc7058148c24e209aba6136c34_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
  • +141 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams.

🔗 References (13)