Red Hat Security Advisory: OpenShift Container Platform 4.21.35 bug fix and security update
🔗 CVE IDs covered (12)
📋 Description
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-75885 — openshift/console: openshift/console: Unauthenticated SSRF and resource exhaustion via devfile parser endpoint CVE-2026-75886 — openshift/console: openshift/console: Unauthenticated reverse proxy to in-cluster catalogd service with session token forwarding CVE-2026-75887 — openshift/console: openshift/console: Unauthenticated path traversal in i18n locale handler CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:2b2be5d0a2087bad904753c2701ff8ab90fa00d7b87d22119813c04ab0128519_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:4f002861bc5a3e7deda33a6d5d0ed799dc48f84ebd5e2a76b3f0378c1d7f036c_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:720230e0704b998a08a6d146c3b71b33344a20e6288d86278c69a1ba27c1eadd_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:b9acbd1beff43a95b5893e4b38c3210a57b07590ac31ce13b9baf881ecd6b637_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:2395da9906c34f2cd1ca7aa7c96cea57b6c1de279def8ba347e824b236105f7b_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:5c5053e3b66d4bafa3c2e45bb7dc9147ea3daae40ae940b07707670b28fe49f9_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:a8eb1f2bef9bd3b612efd49dcadee23833cabf29cf32fee5425752220ac7e908_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:f823e503f418ce92bdac2f6b173c3eb297986c11dae071fd27b715dc90f75158_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:38c9b64b9a0eeab3ad60e770393a6c519d91af623f47610049d5d6ba46ba3dff_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:4c1961ba8439f483d11b91ad6f224e3228a4294e5d888aac9d6c1bc836dd528e_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:98d708e85167fcd2620175dab9b72e057a2077a0e2aec1b0c567ae7ce7d96a79_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:e162ffa3f711747ecfb1f7938dba5b327b549dce5766bc34dde87c6526a9a40b_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:40876aee204b74345977a9ddbdeb60b9aefd1ac5b2261138bc4ceadae1e7f5b4_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:a7c927f747b6b157400ade80c34352ac9004d3ef7c14b93db65dcee6a94961c7_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:a9bddb418c2906131fc381e553e0c890947f465ef8706b4b661c9844a08bf206_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:c338bb2898affc6ff8ef77c1710c057ba4a0e549abb77932154e40b000033903_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:651121d0549e9d6899b24712cfed886890f6778255905c993c21d4809c2bbaeb_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:6707492858ab0d57552de9270367e16cc28986859829941f19e11b69b3e76e82_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:c07ae398073c952e8b4795db6ee77c506a06cb2b4b05775f115ad298f2947b6e_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:d19b8af4c3c704d593c1262bc312a3b45accfcaf7a2b8cc5ae919bd4f9c05ccf_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:6c614a3e137b9366d72062659d58a67fe8374cdb28ab3c35348c86800281355b_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:a898f51cdeaabd54f3981b00cbe18c874eeebe2529fc18fce8bd8b2332a4122d_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:c29aa52c3c45cbee8f86442a0e7debcb5fa6fe6b5756a5c9c3f664273d93febb_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f0a9990eb223ecef2c45538c794fc0b9710f655107acdfec0b0c14901a949e5f_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:3feeda26ab64f621ff9956156c7b0f34574fc95a22e50cba0cdd5f10b0c1bf05_s390x as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:7beb06531fe028d1cb29447ba2d7676dd5a8bee7848e776536b865b5fbc123fe_amd64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:92870384196de94ec3065fe131e6c67151dd7f989a973a102f9eeef2cebade0a_arm64 as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:dbf1bd68b4b905756b5662972e51f3dc0aa0f950b2f049a5bbbb5d0c0a2a28f6_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:1328a56607136958119d47f009fe37f7c83192521df77254359f989ca11926e6_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:1f8f423477982ce16193469c26f8941ba797a6f4fc3b3621a5d426ae19deb457 (For s390x architecture) The image digest is sha256:9b35c91c404bc64aabd3f2f6d76724b8b37f94fea2d70ea333113f18e9c21e1a (For ppc64le architecture) The image digest is sha256:def851862f1184cb7ea13d2466f25692e17e88d46d8dd0dd0ba818952eee9ce2 (For aarch64 architecture) The image digest is sha256:f74f869cc6c38939fa1f541814da83d3c56014230b055b20907b9c0227dd7c7c All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stringify. Where qs.parse is used directly, set allowPrototypes: false unless prototype keys are required. For Express applications, review whether the default query parser configuration is necessary. Wrapping qs.stringify calls in try/catch can limit impact to individual requests.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2026:71453
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-39832
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-75885
- externalhttps://access.redhat.com/security/cve/CVE-2026-75886
- externalhttps://access.redhat.com/security/cve/CVE-2026-75887
- externalhttps://access.redhat.com/security/cve/CVE-2026-82417
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_71453.json