Red Hat Security Advisory: OpenShift Container Platform 4.18.56 security and extras update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-73643 — js-yaml: js-yaml: Denial of Service via exponential parsing in flow collections
🎯 Affected products192
- Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:302552f5442804c653e89c5c57e8f17422c89fc706ed5cdcd4e2508eb3918847_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:43f67a0215a4e8b555950a4e561c83cbd55bfcafe683905abf542e6f7ebadd75_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:99655fbc1f3173662b889ae833d83d433f4e4f0c4c7f9838e1bf3aa10450ad9b_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:e555e0dd6033479d887546e6f1c5aa1fbe3c0d27b58cd820472c35c6bb1f9f94_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:5c9583d6aad6d47e180a27f7aa73d121fae9fae20824866b08691f8e2ccea7c6_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:b095dfd1471c03c19a934c2c9877ae78d72de9940cc5c7cb05ab03fb06ad2836_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:dcd52d2b3d91082125daa9f1d412c5eaf926ff52f5022b9b64f9ca9c6d888234_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:f20cf4eb1388d5c8072e48b763641348300f79c43092fe3f89e799088536d7b1_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:0d97668fa8ff87ee7c51f7ffee47d48f8471a7144918782ad9991d101dec5248_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:19f7dcb26a4f6c6c98d7e618ed58f64864d381c42c63ca1b3afc22c67d8e03bc_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:4afca7b22c90bcb225690164b81aeb89b5f67b8587c5fc294220d05839b24a5a_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:ff31789a3ee430625646fdbea3adb20b73ea1098e25d430698971609f65e7e28_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:028046694393461c56ea4f4dcbe78a8224817f15f0269efedfb74dcdc414bac7_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:2b8c951ef7217b1a5fd96f311f9906f196481e5b5fcc0053a1067b0fc180b4fd_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:45790a991ecaa2d58a822f49e4d1ce910947e3fef94bed39a2eba398c16649f9_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:5e7940f67fdac6dc56be740e658e5e001c9c9150029154ce4d1abb77de09cde9_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:165a5af273aa9766dfbc37a3e08ba14e1b3d7e174eb851f6cab7e5861da5c33a_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:9d807014253226b24895ba701b1cf257ad5e7f0920d568a4eb2892635825243b_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:b6cb08304090de7136a7e061970225da5a3bd75950232e6868f4bfd9042e967b_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:fb5394fb874562701de270bcf6ac82f07ec80ee563b404fdc385efb3667ae972_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9@sha256:2773203371448fdea49a7c189564c3b2339f9af04895b446cc5835b144fa1c99_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9@sha256:754f02498e40a5418333dd89e744988ac9a07b87a23657fd2aca5393183ec9e9_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9@sha256:a305a60723c6705657fe5e585b7071263c2c34e0a6066b425bfaabdefa6e7493_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/metallb-rhel9@sha256:f88f872e8988f55dc0667e50e83c1cc61be813a77e1529f8949aae1313d2316c_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:5ed0511c256af9d6bc27b941ae32a4122d953813ffbaac168eec28d75a26a902_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:70f70dff57cb996a32f1d444fde3ebb4238306c623a8360389cb16d3e8511100_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:9177846ad2d62ee72f7355fc2ea198ace7020517c9d685b4325534721acae877_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:eaea3966e9c061f41fee240c424d86a657b38b5b095ebde982a6edef6dc85251_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:07a4b073f944e3379c4e96c157a114cfb688593e1e0013c4a8913d37708b94e4_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- +162 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict applications from processing untrusted YAML input with affected versions of the `js-yaml` library. Implement strict input validation to ensure that only trusted and well-formed YAML data is processed. If the application is exposed to external, untrusted sources, consider isolating the application or implementing additional resource limits to prevent complete service disruption.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:70618
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-73643
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_70618.json