RHSA-2026:7245HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.21.10 bug fix and security update

Published
April 15, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:3a3d25f7180a8a0a348b44fdd0295b963cd2d9111947ae67df2b06e724b1addb_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:5919f09a495ea27592f3822b40754a8267abb8523f423e2fc58547be0e5aa014_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:7f5a683f866cb1f4935ca49c43d0a7f0d3e81d911bf6ca1561dd096200bc18e0_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:c277040bdd27faf95454103bfa61d619df3ff06d73c31ef0b74c77087f531132_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:25a833b80fb66c1ad962f260fe8997db16e16f8b69f90feb2509fff2c73dc9bb_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4de898e01c634af85d650e6b3c899bd7592f15d1d34a473192cb94f6d514cae4_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d1a5129a98086e1b1d0c69832e8e67fdd48755eb49f9b1bbdf4369e7329309e2_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:d84b63948e8cc3f620dd1026781a69fe60d1b434d6ddeaa77abf809beb66b3f1_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:08db103cfaf7a535766aae3b4f846453d5c63b58216245e3cc7755c26f7fc062_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:265c8d85cec145d36f464a48a8da1a68e4e1ce65c8c7b40bbea14125a8e1978c_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:351649a62ad35707926e1bc5cb160e22ad334fba121d3df9d71557b81f583212_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:7e327002e942f57b4b08b854952e9b1505c9ec0311a3084255804f11b125446a_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:86793d3d96030c5c0bc897b6a0945c7b53ffb81e7a0cd93bf6813fb2d5707c71_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:962243c30295d270b6001119933075562809911435c8580c578a59e60d7b95a0_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:a946cbb14fb492d41b6d63328cdb3d04ce9d79c13828d905c004b52d107afd19_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:fef1fa2e0e2e540206abab1d17be739e18f001a6d4e383d790c87267ebb84137_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:7ae2dd55ca33aba25e2cb9d8503f58317bf964ba9ffbfda809390edaa7c0a003_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:d699c7389d305a762aa6ab8449aafc39fb325631640cd688bf34e7c60ea39a29_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:de500d81605c96fcfca26b545ac8d4632642cb72dc9227bfd3948a3ea7c20148_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:e01170545891bf21a5201eaa40e1a1c3f342314ace6c8da8f08d25ea362e267a_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:5cfe030248e5c7ca6ec96047b1da8a8d612e91a34a6fddee404be777e8a8de4f_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ceb62751b04e70c7be05d528b59810ba76677b78676e1d23361ac6c2722d40a0_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:ef72c064fb0c917626139a2fd731a978eae71da6aafdcb4e09e73961ddd0ed0c_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:f5639fa5e31715e424d4b5b9f1138fede381268b32913543ad9e11acb37bbc86_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:1b85945ef9fb97e3369e007b333e997874508cf8c3b33bfc760de072ec09bdc1_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:b3e4647b84f356effe73d751feece9327e235b70de3cf6ebb084f615215e9703_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:bf00ebabdeb01eb946bfc296dc8011a5eb1e3881fa6b25772a716887e34fd69f_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d6b0298e20c6a2485602e57327f3925a4b8d370767c859b2b3b66b8a3c2b3239_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:2b47bdf966057227ff9e4ccc4ae734472872699928a68984b6f44a7fdc7f1b45_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:5d591a70c92a6dfa3b6b948ffe5e5eac7ab339c49005744006aa0dd9d6d98898 (For s390x architecture) The image digest is sha256:57ce8750af38a4b2fe4cb8ebde95968daec9a565f81f613ddc279c1bf4917a26 (For ppc64le architecture) The image digest is sha256:43ad23cfd2db3851e66823a24333ebbf638e223b89d2610011a2e36a4ead977d (For aarch64 architecture) The image digest is sha256:e5987c2c35e6b6bd597332fc795ef6ea25114e8563e7fb8e2dbde788dd3e4ca0 All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (4)