Red Hat Security Advisory: OpenShift Container Platform 4.20.40 bug fix and security update
🔗 CVE IDs covered (12)
📋 Description
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-75885 — openshift/console: openshift/console: Unauthenticated SSRF and resource exhaustion via devfile parser endpoint CVE-2026-75886 — openshift/console: openshift/console: Unauthenticated reverse proxy to in-cluster catalogd service with session token forwarding CVE-2026-75887 — openshift/console: openshift/console: Unauthenticated path traversal in i18n locale handler CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:88c6586adb7df51b06492f37b8e090649a04c6e79f55ad76af2336feb3f501b7_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:b9d6f9325de5ba27a1f35ba34d1d9044d41a246f48f77967c99fcdd9ab2fc8ae_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:bcd489332393fa85e0ef7d9c1c6d20f4315fbcacb3709dca3749388399fa928e_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:f950e7c573fcfb83e8d1b379da525e9fc2a494786551e820f590a228c32d72a1_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:3f4725831dca9f69513ba7394be9f3d79dea4f8a303cbcae2ae0df9fc3257a02_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:63f610c84188441f923b6a957dc96a670581ce2616f95713b7834c1fe6c40169_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d6fca41bacc8a8b90ef943fd9f29dfbc3ea00423d169ecd01ad23dade2aecfc5_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d9bc6022b2aa3d71d14cf1ad5ce84518bb06b8134c5b9b37f63561e61747add6_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:4ef87a40a6a82ea4ce7c76fa16f75a6a108d2a5879559d715c61819a74591545_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:61c0ceeff4b72b69e39ec9ceb75b668f9d952de8f5d074bd65ed3f0c756eba9c_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:8e0ae171b42f6429a8f07ef5b1a37f6e6c6051e732cce9ac1ac596946d55477a_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:e2f3ee693e1952eec8556858e97c90e8be73080cc602d274cbcca0a08129e109_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:1a46f20a522e5c3d1c85097d9bf0f10606aa605e325d62003fe4b54ef7f92f6a_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:205d50be739b94e2ad2c1f3db5679a11aeb05a6ed1801d5b5ffdd31536265780_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d0c2e1d1f7b28c4abe7bf889d4e05c39230dae9f465a193fdb904dbde95e8d2e_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:e493aa10d72952247af2413330c77f110647f6cf6ea46177d38adad93c0fb382_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:4296e5baea9b2ec3e7b6ec983c4d7c429fafc81c579cd57b00724cd3293898ab_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:549e04970ec2b7cc24f3537c0e35d1dc2992132a449653862d31a05c76774939_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:a921bee9952659f9a563eaf99ec7916cbaff0925797d82e932f4ecad938a3907_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:d0835efb45492ac07a92aab13ae393cba29c9ffb56f09807e16ef742c1d4c97c_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:1a61d165cb7044001b8023d540ff1d20a635947264bdea87c1da63754d061b9e_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:97c4e01f1e4cb5bde80acc70e9c55eaecd30db162b3fd919cafc3a774dbf6f67_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:b988072326c31dc7a8a2dccc416650dc5af93335281d020a6a628acb7ed27349_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:fe0cfb76f9c5cd5d00472b478655f6b8b39351efef9e27bc3b871b65561d59f3_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:0207cdb92ffe83ca16bcd21af339ff56b39b9d9408df8fdc5b52eed5945ff78a_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:14957755af28a5e05a65b8dec1d1b272c5b0388c8fd75646861096436191a857_amd64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:4903bee58afed446273eac8c32712b4904df29a800245ea528a9d6bd926fca24_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:51180af5502d0dc7cc245a56891a681e134b192df1f68fcb79da117f51cbd3cc_s390x as a component of Red Hat OpenShift Container Platform 4.20
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:1510b99d596af610315a5f2640b1731f4b881f11aab64409b53a7416da922720_arm64 as a component of Red Hat OpenShift Container Platform 4.20
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.20 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:5e7b078005685058604a617d52e416d3d152a6ab9197e51c81f4d446b6c0102b (For s390x architecture) The image digest is sha256:5e3eb407ca4757c5af31605e0d2c3ae9687737c06150ea1c77679a6df5afc57b (For ppc64le architecture) The image digest is sha256:505686132db166172c56676ece9d6ca7d5cfe92a1359910af7c9f3bdb702ba39 (For aarch64 architecture) The image digest is sha256:981d67190dcbf0aa4e8fa6eff48a4fa5cdee1db079bdeb19a87d21c1fcf6cdb4 All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stringify. Where qs.parse is used directly, set allowPrototypes: false unless prototype keys are required. For Express applications, review whether the default query parser configuration is necessary. Wrapping qs.stringify calls in try/catch can limit impact to individual requests.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2026:71450
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-39832
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-75885
- externalhttps://access.redhat.com/security/cve/CVE-2026-75886
- externalhttps://access.redhat.com/security/cve/CVE-2026-75887
- externalhttps://access.redhat.com/security/cve/CVE-2026-82417
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_71450.json