RHSA-2026:7249HighCVSS 8.2

Red Hat Security Advisory: OpenShift Container Platform 4.19.28 bug fix and security update

Published
April 16, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61728 — golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig CVE-2026-27959 — koa: Koa: Host header injection vulnerability due to malformed HTTP Host header parsing

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:a31c0d7654d2495710df721e8e1aa57ae47f028966ca83aaa1b74a5b57f0a276_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:a657295bab1d29d15cdd77ce366dd388153b5783c054067ef0ecd1c84e76db4f_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:a95b88717fb16e809ea0b8654929e2808eb6fed3b84e45bbe3886e020d7acac4_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:e5b07464aedee0bfb213c132174a22fc66e279eb8f7688078a07657237a8d334_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:4273b3050117faf7bb14fd2bbcf71c5606b7b6f1326fcc1a36cf3ed51f6b3de0_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:5a2ecf041953f1ac77ef2ff25b6ccbb1c7b7741bcca8eab2bdeae706019f6c83_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:9874d99c0cb18c7120982f093f99fde589255ef5cfb1c67b6a6e95cf66f87a91_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:e5c889f9c92df65efd279220829dc129023a34fd6c4b4d93264739852581cd93_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:35cd98a46072b8c966553d8bb60bc4ed2f3c055eeaf3e7c4d080ec9605f6a96f_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:6a108c888888fc9a2fb0a3b834aab6eb2a6c0b691a39e3461725f87580062a91_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:6d2feee745979668785a904900f8c9d5327477f83361f26eb5879e87e081bd25_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:c17c46279d5ad92b5ad7a58a1dc1bb8331b15ab424e7274818a1c47898b528e2_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:055fea2fc51b9eb48327b78542f420a1d65dbcf786324f7bcbeda053d3fd35bc_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:1d66a8807c27cd43c86399e67ec86906edb97be4ca38b4a752bef1c880848083_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:980e2f5e0f0676e559e91d50e2927fb9bf2f598db0d1ba043440e04d76cf46b9_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:dcd241b04a6e196ad8b66a9d3cce0df26f126e99a85ce7a5443e61dc76194e5b_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:093a5ff464b31d0f1058c452843dd119dfd1798d91855dbe9fdbd5a45c912efb_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:2320a5d225dccf8f02379818bee2e93ae87a8444698f20141f6a0425b1661601_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:46adf0538ec9fbd67abc4565c013f2503c2a11191de264310a2c770bfb566753_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:d48ca3a08fbb356d69be5b61274d75b701d48803a9d57c8d377ce2d0df83169a_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:0b1b706bc5a0188d40950a1fdd30f8c410e68dd568ed7d07c1f09443fbde28f4_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:173800cfc487973c018e8d9badb7d60d26509bbe0803e9a56fba1d5a65070dc0_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:78a2368225915aca2a514c5d82ba82fff8e70e6123c08905c46839a821f4c8ab_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:e44aa77638b86f0ade3d4b69e150e8e9e95573ec90b6031224b87e404b5d6a79_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:313b7b7e1f619f5fd121ca2402d9db6876d021be227b496288809f63f1209561_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:5b232dcf5a47400d1b1d105895df8143b50dc74613b1463b275d6d304e0e0085_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:774dcaecbaa4f7b743b49c34a6a9889a27c6379110672a2f28fb4f83cb0f0fe6_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:8d55cc650683e44676413797328fff9b3563eb78a1aae4cabe736b20e9f15ff4_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:13cd27f7e445af565cef18a24ceca435b4ce2a0c99876b9ad087fdf50e343be6_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:b274766f7194a7dc825e335a54078790519c0dbe3431c029fd08dbba1c431855 (For s390x architecture) The image digest is sha256:066bfcb590ef6f34106e63861d420a3fdcdebd734bb729668c8c6de59b84c632 (For ppc64le architecture) The image digest is sha256:ff14e60b2b4760a6c2578e444b40f457fe2322f5211b1b838078b1fa6ea1b443 (For aarch64 architecture) The image digest is sha256:52b1e8cf83dd1a854194212cc94bfe2719afb2e014f7b1a315250a9c7273a600 All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this vulnerability, implement a timeout in your archive/zip processing logic to abort the operation if it exceeds a few seconds, preventing the application from consuming an excessive amount of resources. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates once they become available.

🔗 References (8)