RHSA-2026:74383HighCVSS 8.2

Red Hat Security Advisory: OpenShift Container Platform 4.21.36 bug fix and security update

Published
October 6, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-49329 — openshift/oauth-server: openshift/oauth-server: Quadratic-time DoS via Accept-Language header underscore bypass on unauthenticated login endpoints CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation CVE-2026-83589 — oauth-proxy: Open Redirect via /\ and /\t Bypass in Post-Login Redirect CVE-2026-96577 — oc-mirror__release-4.21: Embedded local cache registry listens on all interfaces without authentication, with delete enabled

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:040a83401d47fa33bd0f373f83ac517d4d0cf23631ae7bd3b37dcab6cf3e4eb4_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:72368a4edd9b6a4f6eb236bf1ee4e8cb762918570b29b0304f8adfb92e4a8318_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:99174b9a1f0e103732c4a0ae3d60f5c1d2d1080516d83ab14fa5266b590a3e74_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:ccbe0cd06d43c66951bb5c6c2fd4494293c2b4a3ae581fab65b335f696241dda_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:07506caf30c317408d68679ebbf00891a5491c5438c653e2a45be99e77cdc5bf_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:48b693ed707cf134e1319727403aa1ecf8d84fc77bdc02b9f8ce64627830dbfd_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:6803de313be6c2e6765c365aec724d6bd85b02a8fbf7113ae42bd96994f379e3_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:8e3a6c7d26907781dd28ca760176fa8e6af93db26e8adb63f3dd5c2a8f4e925c_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:2ec941d740922ef42d5b995180c05659088435e368ca361811d06616cf8e69fe_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:3ecde5ddfa3d96694b304dd8f64e90644a5e92fe65ee4bc6d664b6387811f524_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:967b4d9a3f04f10770839aaff504019e133ca779f61ce5f487f7f58101c9d26e_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:b6bd4dd3b28ea5e3292c9512a2537365e7e4bb060a4a16695f5e223c4e7c0e73_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:6af31319752b0fccbb54b02ff82d64cb83458686c442f557f09f81214d63158b_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:96a0185d735a68851c1d74a62b0a5747d4a6845cd5b4b2ea687d4d82c70ea709_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:9a40a080261171ad9fa5d03c47a21a99fab98bbdeffbb3e46cf02075fef066c8_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:fe846a1e140a01a8e385e36990a973334d368c2b9a6aca8a430030c293530f33_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:132bfb4f8f37bdf74d0e24c4badf4eabc5c114e62a1f00de46a13c24b17f7e55_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:3cc14873b82a0bda226f498c9080eee883be4e8f188af3547a804bc75719c229_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:6f952a2490c0c1b423936efb6c588c1360b959237301308ab2bbca484b8df22d_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:c9e997db24cfdbd70ee9d76f7d30e32d0c5fc84db359c9b8a68c3da7f7c99c5c_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:26d769d637b70946a1e2f11373d11ae9c26a3f8d48438ab9265b0a561299be03_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:2f64256f1f53c55276ea21e8f7d9e8c1b7ffbd3be76524442141795524fd3286_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:e79d5fdb039b8f10754648a33d43a755c723c759f819cd7f861ea9722b3f9e6c_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:efdc101e4b3e8e9c1b5113904bbeba61e6f4abc73253cd5d260fffcc5438b93a_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:24fd4d8f1e20cc88560be7f6c90ce1c4763c01b012258aa239b722adae79da46_s390x as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:83325d45b07bf3b47b11c0a120340b45393821aabf56141d83dc7d8bb647731d_amd64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d619c0b5b101861e0082663486978dce9b71b096bda07df70762e338728018f1_arm64 as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f0143b9571df4a61de6957df15669b32085dfbfaa9b95d0d2b7904fb8ceee0c2_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:2727d957c7a728dd2d2ceafad9974f7b762dee110df15eb21f46f39bd253e2a7_ppc64le as a component of Red Hat OpenShift Container Platform 4.21
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:d00a000883878045a9175d7526667104e3ac8a90b7fbaa0450d4e5f8fce6fa61 (For s390x architecture) The image digest is sha256:78e808c4fbb1903707b9a168d184829d9e4731e0f2378bc23524936a9044824a (For ppc64le architecture) The image digest is sha256:1d722b20ae1af97c9a71dd9b4fd7f06e2bb8dbe1657f5bc6ff0dd075c6d754ce (For aarch64 architecture) The image digest is sha256:de920f9fca92fce6816ce16a6d893bd13215939371d6e9e3534b74afee296dac All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: Until an OpenShift update containing the vendor fix is available, place an external WAF or load balancer that terminates TLS in front of the OAuth endpoint. Configure it to reject requests with an Accept-Language header larger than 4 KiB or with more than 32 combined - and _ separators. Rate-limit unauthenticated requests to the OAuth login and error endpoints as an additional defense. The proxy must re-establish TLS to the existing OAuth route, preserve the OAuth hostname/SNI, and validate the backend certificate. Do not disable TLS verification or expose the OAuth service directly. If an external TLS-terminating control cannot be deployed, there is no supported OpenShift router-only mitigation while the OAuth route remains TLS passthrough. Restricting access to the OAuth endpoint to trusted networks can reduce exposure but may affect user access. Upgrade to the first OpenShift release containing the fix as soon as it is available. Workaround: To mitigate this issue, ensure application code validates the size parameter passed to customAlphabet or customRandom, rejecting or sanitizing zero-value inputs before passing them to nanoid. Workaround: Red Hat has not identified any known mitigations for this issue. Customers are advised to apply the available security update when released.

🔗 References (10)