RHSA-2026:74380HighCVSS 8.2

Red Hat Security Advisory: OpenShift Container Platform 4.20.41 bug fix and security update

Published
October 6, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-49329 — openshift/oauth-server: openshift/oauth-server: Quadratic-time DoS via Accept-Language header underscore bypass on unauthenticated login endpoints CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation CVE-2026-83589 — oauth-proxy: Open Redirect via /\ and /\t Bypass in Post-Login Redirect CVE-2026-96577 — oc-mirror__release-4.21: Embedded local cache registry listens on all interfaces without authentication, with delete enabled

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:6d27e1510a9a2348b6dfa5802e56dca1d96c919fd9e8836b3c74554c52846b56_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:eef9515efb534a105319c09fb00534c21de39a344f39b2580afefbf6de711300_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:fcbb85cf42af9d29dc1b177abda8295cff9cc0dc27a3625c127f6066392cd5ae_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:fd579e1c900d1b5684dcce0a2544c0e3ce306c0c72b00ba007a745c17f133802_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:308b33e83017f4424980fb882cdb75badc3fb5931af0c0275bbc0da261246b48_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:328f77ca377c95921f8eb0bdbabde9be1742b676e4eed379a6f36d6b7e61cf2d_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:5b271b379d5475f3bb0fb7ffe77a717c417a3c57739223207b2a6d9ee7f03e56_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:8fba9c839e9e0e5a05f7eb73a835d4bfc5f44f99905c5a24ff2a5ef0544cbfef_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:1471b400e5c22c0fb62c53db06844f2b7bcf09fa720da3bffc4b5fb7a50c9ada_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:a535f583c9d644fd73c5bb1b0c3aa24ce1bea7be63718c6fa8d4cbedacfb4b8c_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:c014d160d1ed7a36e15ad73f34c074bc4624498ba138293438391c2d7b2a3908_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:c617f77910f4b1f4d275342dfa1b0471c35b616ba25d911cdaefbf61f6d6c4f8_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:383e032fdb41a23939241c99456636e4d535e71d1a5a9819c6159b86dda22c27_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b18e3622eec023eccf5b84b45ee9ef0f6edb3c8a277ddf0baabab82b7afe86d3_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b47f2679261fb3a1152741ea95686f37d7c470ec4e1bc7b12611a3f680015d51_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:e75f14228a63750dddbf88a1d945135dc7b3a99716faa37dffe99404ccacd1a6_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:3854af31e0279525c60b261b840d47383c46d34a299b15f4e137fe107a6023f2_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:40069ac072af330cee248a75e61f9543a7c725df6c8bb33362e5fe01720454b6_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:42dedc6a5d529585fc0dcdafafdbb3d18a1ee7c500078f2230000d9daee130f5_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:daf3c3f955cc9e7b2255d8a5252c2de616e2eba067350366622858eaaa3beb47_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:7568afaae3e8966d401c85059f386bcce2d595f53649496445872f20d478a841_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:8d5ac2457c947db4c1cda557386480f6383f47796490fb01763c16af603229b8_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:b2f07d57254fbb5ac97e6b00c0c9f125de880efb67361433a553d9c0913051ad_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:c0fea123350f69bc4ac2562e1f49490a43b70ff14d5b882e32b63335295f2a68_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:40434d33a1faf3b126787a91e4fa1e6ae921166a0b2215b412574abd36648385_s390x as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:920c6f6bfa9ab740abb012b7b6d08adfd6e296139a48345c0856fe73a5bdb67d_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:c864ba5c7162bc8d198961319791fcac3a6367eb08412a8c87d55142867f97c3_arm64 as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:e128406f6ca198853f527f1b0a57c2bdb8cb35af0ee08b497d2225e840978cba_ppc64le as a component of Red Hat OpenShift Container Platform 4.20
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:59af1017e3407e9c372db3d55ac04969c917cadc22a728e887417254677b1db4_amd64 as a component of Red Hat OpenShift Container Platform 4.20
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.20 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:735d04d245382654d1d2441a8c7746bc84be421362af51bbb678e0d2cc7bc05a (For s390x architecture) The image digest is sha256:9e945e71cd108774f9d95c18af0b5dbb7e48123d93dc1efece727b1517a31d76 (For ppc64le architecture) The image digest is sha256:817b8dd9d1e230c340cdd4b6523b8ad30eeb766e415cfca5bb11a8a2223445b3 (For aarch64 architecture) The image digest is sha256:93c246ded6fbe89491a73f7a5e589d02f525a6547c14cbe980f0a9d4327f8830 All OpenShift Container Platform 4.20 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: Until an OpenShift update containing the vendor fix is available, place an external WAF or load balancer that terminates TLS in front of the OAuth endpoint. Configure it to reject requests with an Accept-Language header larger than 4 KiB or with more than 32 combined - and _ separators. Rate-limit unauthenticated requests to the OAuth login and error endpoints as an additional defense. The proxy must re-establish TLS to the existing OAuth route, preserve the OAuth hostname/SNI, and validate the backend certificate. Do not disable TLS verification or expose the OAuth service directly. If an external TLS-terminating control cannot be deployed, there is no supported OpenShift router-only mitigation while the OAuth route remains TLS passthrough. Restricting access to the OAuth endpoint to trusted networks can reduce exposure but may affect user access. Upgrade to the first OpenShift release containing the fix as soon as it is available. Workaround: To mitigate this issue, ensure application code validates the size parameter passed to customAlphabet or customRandom, rejecting or sanitizing zero-value inputs before passing them to nanoid. Workaround: Red Hat has not identified any known mitigations for this issue. Customers are advised to apply the available security update when released.

🔗 References (10)