Red Hat Security Advisory: OpenShift Container Platform 4.22.17 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-49329 — openshift/oauth-server: openshift/oauth-server: Quadratic-time DoS via Accept-Language header underscore bypass on unauthenticated login endpoints CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation CVE-2026-83589 — oauth-proxy: Open Redirect via /\ and /\t Bypass in Post-Login Redirect CVE-2026-96577 — oc-mirror__release-4.21: Embedded local cache registry listens on all interfaces without authentication, with delete enabled
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:0ba81acc4c352a5635ae891bc0e4aaddd1baf33a9db03769b4adcd3b1dfcf9fe_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:33101aee82ce051844477eb34b0ca332282564a285e910d6c839d11ea6a95b26_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:da4bd0b1249ee55fa17087c06f1e4dc182c248dbae06f9f7892d288fcc2a2470_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:ecdef0706954d27619cb179c21c161423bbce3de33d3f246ec2e1e11697eae08_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:5fa5e3525ea621ef39b5e49bc40ce7df291a4e6a7244c5ba953a70145e717ed7_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:96f3cf069c224a3d9625beba46ff1b1cc4fab95fe9cfc329702d73d778c1d477_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:9744e688b4da93a4d620d762e05831d0158bdc8bfade81f5ad6386e44e828155_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:ddcf386a7780d541f3c0d5e780c0f1da5da8f89b8d70d42dc87a9ee251a030a2_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:102972bd7baddf1506ca26066f17fa2fd8e2899d37a546b4026e0dc53fc6e1e9_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:9211fa8481dcfd6e3d0d62ed2f34131ee5e4d72d1edafc4afdca79ede70cf834_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:b25d81e3c9dc3d64a656d25db1e2bc1f2effcf37f45448e62031927bfe9e1c2a_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/aws-node-termination-handler-rhel9@sha256:f9a0b83ddcbc5b426cf792ed2a1699705577f97e27198560b711920d4110742d_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:0da245cc8cb69acafd6e7789b41442aa969f73153b5a6b31c031b4393ccf71ff_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:11005ab1b800511d051388bb432037a1c1ef770a3e88cb59337283a5481f0112_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:3f271b92c8a0806f6bb5f28781fd725bba27083c23f6774e2c450dde17742e94_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:ddb6df18852c906ca7765fc08ce2901feadafab429a2f74d8930e4762abf90b9_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:07d6fcb4db59dceb7945d8ae0edb52622cbe5d7aa25c31ac4edf3ca5f4a032e9_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:18182de17e0c96182a1df2e5fbc9984925ce793daf66dcdbaa7e723af968a15e_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:39fbce9ae226fbb1d0c64bf9c9490103f6c2a9209aa659efbe4edcfa3b14cec4_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:780a68d32398ebdf5332e77c3ec9258a19398d5a5399462824fde1de7008a61d_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:08a6e880a3a22ae446ea22d20e928118bfe284be7f7390a070811e5f9099cf7f_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:61d55c2378be0302055d6a2840cb82667025f493959880e575df39a26bbe7317_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:9663321a3f4e1e99a4a676e5bb23079ccd4021ab3d2c7926e0c5aa4cee4ba75a_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:b159bb0c29ddb6ae074f225db243d82e73589c67d69838c283b0685b5a4dc9c6_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:0406d316ea4b86368702b0fc7ed4eb7fbd8eef2f13869a796a28e154108a701c_arm64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:22ba8dd167844f7be7b4c46d35dab5db0b17685fce9130260d01f49fb7a47bfc_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:5a4b8568f1970bae9dcd6dd6376d6ad11be239ac81f77958cb67a492a2fd6d72_ppc64le as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:892c15454b4a2bb8911f2e434dd4bfc85e50b8d60a5ff3d7b7156b84776eeab0_s390x as a component of Red Hat OpenShift Container Platform 4.22
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:4fc954ce5ee630ca54f46533ed3eecb2bcc8988f6fbc36514339687affa2f0e0_amd64 as a component of Red Hat OpenShift Container Platform 4.22
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.22 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:9bde31879df303de7db7c100878393a520215f33815d0d9b188e3b4436c876a7 (For s390x architecture) The image digest is sha256:41d57f38fe018b5dcfb3698eb4630f406ec7546f67819d55acd134c3a2e5827a (For ppc64le architecture) The image digest is sha256:160d848722ca2e69777f512ff36adbd5485854b9905e0813aceecf83d549f5a2 (For aarch64 architecture) The image digest is sha256:b040b4af870284b4fcec18283bac700a5d3a0162cec2101a235dfa9a5f005b14 All OpenShift Container Platform 4.22 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Until an OpenShift update containing the vendor fix is available, place an external WAF or load balancer that terminates TLS in front of the OAuth endpoint. Configure it to reject requests with an Accept-Language header larger than 4 KiB or with more than 32 combined - and _ separators. Rate-limit unauthenticated requests to the OAuth login and error endpoints as an additional defense. The proxy must re-establish TLS to the existing OAuth route, preserve the OAuth hostname/SNI, and validate the backend certificate. Do not disable TLS verification or expose the OAuth service directly. If an external TLS-terminating control cannot be deployed, there is no supported OpenShift router-only mitigation while the OAuth route remains TLS passthrough. Restricting access to the OAuth endpoint to trusted networks can reduce exposure but may affect user access. Upgrade to the first OpenShift release containing the fix as soon as it is available. Workaround: To mitigate this issue, ensure application code validates the size parameter passed to customAlphabet or customRandom, rejecting or sanitizing zero-value inputs before passing them to nanoid. Workaround: Red Hat has not identified any known mitigations for this issue. Customers are advised to apply the available security update when released.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:74429
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-49329
- externalhttps://access.redhat.com/security/cve/CVE-2026-67213
- externalhttps://access.redhat.com/security/cve/CVE-2026-83589
- externalhttps://access.redhat.com/security/cve/CVE-2026-96577
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74429.json