RHSA-2026:73869HighCVSS 9.3

Red Hat Security Advisory: OpenShift Container Platform 4.14.75 bug fix and security update

Published
October 8, 2026
Last Modified
October 10, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-44918 — openstack-ironic: Prevent rehoming resources to nodes with different owner CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-75885 — openshift/console: openshift/console: Unauthenticated SSRF and resource exhaustion via devfile parser endpoint CVE-2026-75887 — openshift/console: openshift/console: Unauthenticated path traversal in i18n locale handler

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:3c5090b3bc72c7411758a9ecbc0b648bb52298d6f62e79b6b4c1a1306da870d3_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:862833cf54a0a85d5398750b186d2978701179abdfba23295bc01f2559357f08_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:8af029e484284969e7328cefa4a517abd1c9e85b4953bf77eb0502e754de2a57_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:d737e1d2e1e5ba1e21de358fe50a1f12691311dc5584b63c339d962101695ad2_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:2bb1ad141fc86c540ab4a840fb3080cb1c85e74f66ee6731097f2a6cb5a33b96_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:6ac2db8ec70cfc4614b89c387f35e1e40d01f19ceb1a948491f6065c7c840e1f_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:b8bd04338a115ecdef1ffa398c370bd5fa9b6e990c8fa8382b8f6e667ff3521b_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f6729debbaad1286922008268a27f42d99072a041923d55ffe8bd76aa15576d0_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:46309df6cce836605b98b2dd68a888e30c00c016c80d3870ff24db28ec3a7ee9_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:574ad05cf7cec9424f40d3038fc026b31feb305fa1278d5b21d12ff603116dfc_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:89651ccc02882a35492d1d797b9fca8b791e9ac14d9a4cad6e21affaf481dedd_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/egress-router-cni-rhel8@sha256:aaf928492f0ba057fa84d1c3142f9e8a1b5f2cad2710a2f50adee408096b77e1_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:19a1e02d626e22ca58f24bd5ccdf18c1a57a8a88c830c07177ad5be113965783_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:7e6a1d255366a40642f0e484937e23237384030045365563522314081d347747_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:8df1098df123c573b561d596d40d00c167a88014fe3b64a50921df73675203e4_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/kubevirt-csi-driver-rhel8@sha256:fdd61e32d704f1bf08f905a2461d2742e219919260a68772cb6442306f2f813f_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:4c5c6c0e711db42515fbf778c7f175f98bec1a479e2e1fd8765049eb3e4207e8_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:6c8b10fb622dd00a0dade8bd61b8776fa2d3382cead99e2ceae093c07e96869a_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:e6998a494754858518b8dc4b116f4a042ed2722602be5826c7a602e3fa9ebfff_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/network-tools-rhel8@sha256:f1a3095f72d08badb674358bd40b1080666562d2c82ec12dc158870b073a9e2a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:09aeb25323b28610317bf66d5d7217b38cba6bd4807c72c0393770722b2e0c75_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:8522cc9f7885d645db8903ecedd1e5c3eb628097d3e52f15ddce60e5fdafa18a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:86d496ee1725850bbfa9d8c070b7867a6aed94e74bec374be8a9c507d81b4ed2_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/oc-mirror-plugin-rhel8@sha256:fb82cf5475f6c289cce7ec1d4a8913236054272209b7ce643a6e7cf2df8b1c77_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:4a5da12b1cfe503eae3daf3a60f90f60afada86a3eea0880dfd0705b66fa12d0_s390x as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:8442347815351253f3520cd14668e8327f5bc6b17b2c841cad35e88c2028e2c9_amd64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:98c2de27103fb044696016126a1bf8d86e6081faa37a19e56cebfabc4b2dcc82_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:a2db652743cc33f929ed61a9ea5e587528d00cb8b59a7ca522e1b3227be7124d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
  • registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel8@sha256:074dd4fa6d8126a614653936d93d37f869b1f7d00658792ba367417d602ecb1d_arm64 as a component of Red Hat OpenShift Container Platform 4.14
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:15fc6659721704443287f3783e1eac991755dadb376891867f52453a147e048b (For s390x architecture) The image digest is sha256:1f7a7d2c624165f036df13e2657b9ff4ea8640cfb2d3dd13238a0924a0ca3868 (For ppc64le architecture) The image digest is sha256:f9a5c2fd0282712d0071e538d22545a4d2ec164425f39cfb7985ee7741681010 (For aarch64 architecture) The image digest is sha256:984afa68f5489487eb35c90fc563fba0ee4db3d69a84d44f0983f3df005274c3 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Operators who are concerned they may have had this occur are encouraged to perform a basic audit of node configuration, for instance, ensuring the expected number of volume targets and volume connectors are present. Operators can also use the provided ironic-status upgrade check to identify misconfigured nodes. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: https://access.redhat.com/solutions/7148487

🔗 References (14)