Red Hat Security Advisory: OpenShift Container Platform 4.22.16 bug fix and security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2026-18446 — fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-45819 — baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-75885 — openshift/console: openshift/console: Unauthenticated SSRF and resource exhaustion via devfile parser endpoint CVE-2026-75886 — openshift/console: openshift/console: Unauthenticated reverse proxy to in-cluster catalogd service with session token forwarding CVE-2026-75887 — openshift/console: openshift/console: Unauthenticated path traversal in i18n locale handler
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:8264780384c28b0fae91b8112f5977c0f151ed9d35ca6c6a9e43c3383e78e9fd_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:86bc9924d63e9221edbe1259dbf81e09c7f60b0e3882a975f6bbe8458e1f7768_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:def36c760b156bcdada38b90c7f8c265f76e05f318a4546dc472a3fb332b65b0_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:e5d7d9157e82017340d166261d3685f90c609c09a555b08033d2ad3ddde2ceec_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:07d454ba0b63df343914f3fd7fc624b580f52fa49431873a2a883544e6451485_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:1b607796202894e2b6e81125df9676d2465927775dad8ddc7c82c5a1629aca0d_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:91c72d4bf67b1413cbf3d9a6959b3a39eb41acddf294681646e2a1e3e9061dc4_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:feb535561037bd445c0e977a967961180dbebda1c0b0e0c78e7e45764dd2d601_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:8051451cec40a67652d3bc8e7726bb968afbcc815d753617a14d9c54cd1e310f_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:95b8373f87c978b9ab3d081b862e8779255e905bb8c7a673d81eeab1bd271e7f_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:b5523f13de44ff564b8780cd3d3b9c029328accc9bf66da143504c73f95ccaa3_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:cc3f8bba3f0241e23d2a05a5844ed6a0531e652bbcdf4f29ec4b99052ec964d7_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:551be35e8917e5434e258bf86bba9cac7954ec8e4a150e3f4e8b208dce7b62f0_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:61624c9f06b07a5f8001590794b2b5645356eff7a967906f10376a8bf06fa053_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:acc7e6ea7e9441f39a653a877de89712d18d0d3c17cad1cfbb002437ac02e714_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:c2c0fb887a453e1618ddc017e5a712656ec38e7066edaf839e8f44d8096bf5f5_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:6d334871cb6afd5e6d1e911ef48eb0a6caa3a43e6d48b397496d012f78afb810_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:be518398a2b7b96ab6809f79a6ecad1ef223a75b0cb1560eea85f7a1a2edf3b2_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:c4255c17ed2ab59355825bf8e10510e2c1eb824645695a151289c2361b0e9132_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:fe0185513430665e71ac34f7e6c531a6f15a4c2d027fd618e3dd23bda85357d3_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:4a2ae350d9c6c555cb25009b432938dedea1084c708b46decb56e368fe45c538_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:9022d62cbc05bcf1511a272adaa9b3e64dc926f1365f76013979cf74e170071c_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:da2e9e61b0e4bbb2b4cbd3e6b0fc4aa37c418c7f284fdc07721d8a697029f4e7_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:db89bc9a7006973927d1fb32cb60aeabcaa4129fba8f1b52c6616894fad064cf_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:08b01837e50423dff40b6559571cbb93218fbe6ef3a43bd0280fd9ef364c75a1_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:57c2023d24bb8b8a1dbbccb82faa30381ad37f5bd04f29cc35f18c19fa64e74d_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:8944366b6a976349558861e9576101ce39db0a1d4138b7aa21cef0d4eeda4706_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:d8b5405ab1500f988b46fb7e7a13342ca938bad729d4f925f712034443863b49_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:298df6d22a88c3d8f26f11b29b2c42770c0133d748a15528a1c81f23887cd403_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.22 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:55a0c0c8f9a285fa468009511dd878d5492436ceb4f0207933b6403d19353876 (For s390x architecture) The image digest is sha256:f45ad2f2c1d8a45f339a69879d6baa5f4e5ba0c922147bf75f8451fa4cf38847 (For ppc64le architecture) The image digest is sha256:f29efc92dccdd9133824f9f083576c900ca7800bb331095581144d1b982e37d2 (For aarch64 architecture) The image digest is sha256:dfebff37094c5a2921e1c4070878293727c48e6dc6754a88bd7bab91f0a3b869 All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:71454
- externalhttps://access.redhat.com/security/cve/CVE-2026-18446
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-45819
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-75885
- externalhttps://access.redhat.com/security/cve/CVE-2026-75886
- externalhttps://access.redhat.com/security/cve/CVE-2026-75887
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_71454.json