RHSA-2026:71447HighCVSS 9.3

Red Hat Security Advisory: OpenShift Container Platform 4.19.49 bug fix and security update

Published
September 30, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-55204 — haproxy: HAProxy: Denial of Service via HPACK dynamic table insertions CVE-2026-75885 — openshift/console: openshift/console: Unauthenticated SSRF and resource exhaustion via devfile parser endpoint CVE-2026-75886 — openshift/console: openshift/console: Unauthenticated reverse proxy to in-cluster catalogd service with session token forwarding CVE-2026-75887 — openshift/console: openshift/console: Unauthenticated path traversal in i18n locale handler

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:07108b49fee91dcf5ecabbaf949f205385a6f42a8edd8c39530593a6d32bd71d_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:57141f9d149fce71322ffa092c400248370bd0ad2568b007814d1b032d1574b8_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:7c10533db280c28b7f80c8f9c104ae18cf5ce2bb213637c5150d905e5ef9364d_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:e2b9ca38b172679c6a1fabcde59a65a090939801451e87d9ab8aee6edf082a00_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:07fc1454ec47e31de1e0944d263c6949d94165f400e141001dd33086585d412d_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:310dfb640d0970c037999cb9c820875b9cb2f7867ccaa07b0fdb25a79386f7c8_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:3827aa53e1a1e328c9bf745822494415da7622350309471497c2b68101b8fd05_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:a04d94eacf444c2fdf1ae6cce183f71c76d8f225f77723b761608091e9736b28_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:35faaa67c1eacddbc11a115a8644b1605f424e45e59830022be67bcc65767932_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:55a4567813281979bd2775051411530a6ce4add0c927a77ae1464543024ee14d_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:dde0a783929f260ff888214e0821116c7e82871e8cb54bd787c58cb93c2e2236_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:eb570c0080ef268f90f54b247e250bf214bb00c05fbd18e641d32a49b5425944_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:0476fc380d9a1be206f80a625d46b36bf276cbdc856cb2f072213d6c06efd244_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:187c45baebe9bbf0d57e68818624478b6e3a87bb5ca284a8df2c36c2f8850e68_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:6539a6412bd45ee747aff149d73314b12765b7ccc6c9c9ffaca26b560ced476e_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:bcd53da80fe979fe6939899a624117679b936aa94fc16be64e344c66bc6127f6_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0075b335f351a7d16f4a1ede8a04121225a99032ff7d22807293d417b7b1ed55_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:5f2223154aa56fe909ab9a3aa0bc4471ceda6d035951e8aa85c5a36515b4f76c_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:6a17c14eef4ccc0569e0567a067f1a634db7d21ea69501bf0f1fd4ce3b93c2f1_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:916868b95a4dbe7e8da8cd78d8d76f807e4f0a62c47dd5ba3a247c7f3fd21417_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:1a86e590ece02b8bf1caa120fdbe5a5b62d0faa732f82d0dfcb66658d36cbda3_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:36e83823ea728ba526610ec25c0ef4bd854323afa403ca89dd220a2991855584_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:3dda03ffcb4a282f4e3b74537e0e72f115e4702de6c3ac695b30b11959750f9c_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:413dca3ef2335b7c3509137178c36a0859e360c0f9a4a1377739f195c6baa1b0_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:46a91a754f24e32eb73ed84f3b65b5f77115a85f9df04b4200d8bfd4dbafd1ad_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:63f368d05e8c35a5e4b97fbb4a228bbe66636b5753dc9666b894053104a7a91b_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:9c1977b35efe056fc60f6bcd96501ee254108bce4412e7e1da35a26c646682c5_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d2794bb3e2904de10d49c262633dd9549594fd65d2a2aed15b264011ce0edec0_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:5f865d1046d357630406350f637d11be1c0eb1518f4f473bb50a4eddc4162457_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:0aecc463d262ccbeb2c107d5a35d3f2c42904c6844403074390a576c76658e9a (For s390x architecture) The image digest is sha256:594340955cc223d6b931b984994e49b5b7fabb06c4b59562596c8a15582e4c3b (For ppc64le architecture) The image digest is sha256:ef82b483578322578e1b6366fb30d0a6c1040c0ebd697735fe21dd5554401ae5 (For aarch64 architecture) The image digest is sha256:9225274bdd4c71d351a4ff5d58a391e89a5bb1bba4616fae21f89b4ba8552c69 All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (9)