RHSA-2026:74434HighCVSS 8.7

Red Hat Security Advisory: OpenShift Container Platform 4.19.50 bug fix and security update

Published
October 7, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-49329 — openshift/oauth-server: openshift/oauth-server: Quadratic-time DoS via Accept-Language header underscore bypass on unauthenticated login endpoints CVE-2026-96577 — oc-mirror__release-4.21: Embedded local cache registry listens on all interfaces without authentication, with delete enabled

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:590ce4e772c3333a188ab14322a79739d354d76884a29f09e5dc86b0aefa178c_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:7ba3a3e6ea9d322bf2be79423f85521c0c5c1f672ae3b2a05a822d0d706e8677_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:8ad5f6ac1beef483e5db755d118af23ebb5f9f13c28b25823829a38e26b18148_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-karpenter-provider-aws-rhel9@sha256:b544089437083b8b2ba75daef8660cbbf1304a773651953497d84f9923c62ca1_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:5b71047d89af6a2980829a270b35bbaf68956b68c64176e0e64c8d7b878afa68_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:a5e0dc00b30a9a3757493cb0c91900291774690eb8f168c8e4dc96aae2deb1cc_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:afd4e59f9e630d5dc0b6c5477e8279cacbe94458ec00e9e0d49c99338f47e3a5_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:f6db7e6e78e6855b73c57e17df6a03c66d5e26b1f7c57a19566dd3f64443641f_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:071ca5938bc677ce9f3393a08ed427543dae791a601b5c246d4bf3a910f09a98_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:09ba0b79e05e59cc66440dece0ed6165af24ab90c99496ac53be4048e883369c_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:1dfa9bc1f351ae1b0bc13404cefe67903a340ee53230a1a4c7ff365296154bd6_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:6307da9377666027f413d6a02861ea9f32d1459e72b7b2767bf21a299083c8a8_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:0ffb071b7edcbd5e2801528cb195537c0f69f82b8c57313ea478cc05c1f9f8b0_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:719139e668a345962554b37ec410c0be699296d0e3f5d0712b87e5a1cde785d4_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:b768c358c4fd6b40f69db48fb438a311ba20f8c449e3979af9c3cda1a501b49f_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:d83387e7c79d0fe4f2b19fee3417f99cabc85f961b1941e4ad03ca414cb571d4_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:0077f0f4c5c275b68ae8066ef8a2fbafbc301d55fb17844c91aebce37b08aea0_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:230b6fc1f9cb61eddd8f71aa98f61f51a1194de9ec7c918d63168c8982f5aa20_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:4f351ea3dc538eef158c9a66bfc497fa6f8aa03181f6cf0050615939523aa56c_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:c6f319ad0e4abe890a9d8d70c05120fad85d392d788ecbd30053f3134625955b_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:56d3f34f4f2f6212d38e9e175081a1ef558d7d3cd42e6d810e75b405984daf9e_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:5adee94bcd3205dca2e1286a25a37f9a686fa56f0a361b87cfe95ed32e6b24dc_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:6f4a40d294d119d70c161495fbf3ed488d0ecadd5f510ec57858c51151321305_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:8dfeae2f37a6566a6488c26ea964e8357c0560deebc930f3a9ec8b5079e02c8f_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:13027dd8bc0456fba142eb3b0d6e4050146def2007c46a65eee2e58dc39215ee_arm64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:a720bab2b4fe34438c49b113ef1749e12e3c419a4c41537c6563ba0e536dcb25_amd64 as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:dd77e02c6959be065b1d063e274da9caf87baf6e254cdca92166405d381f531c_ppc64le as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:f88593feaa779948f9ab4792a3659424f6598cc836f9b3e3b7fb0162a4c8368d_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:4bec65cccd6b450f3f0c5486cd87ff2839d142eb668fe7609ec9556cf7e3d404_s390x as a component of Red Hat OpenShift Container Platform 4.19
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:5e25ea28cc7d21b69b894431b7966f19d96e1b5768c3f8be8883c15843b98eae (For s390x architecture) The image digest is sha256:cf8accc0813e05dbcff2171c08b1d5fe27656406679a701cc24806f5da058180 (For ppc64le architecture) The image digest is sha256:f6947b61d5910423440a69fdc4c02b84b4f6bccaa102eb11c18b90685703ca56 (For aarch64 architecture) The image digest is sha256:deb9dfb7b249f2a68efec2f32afc542df394fb0ec7f969a9f38940a288100ff6 All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: Until an OpenShift update containing the vendor fix is available, place an external WAF or load balancer that terminates TLS in front of the OAuth endpoint. Configure it to reject requests with an Accept-Language header larger than 4 KiB or with more than 32 combined - and _ separators. Rate-limit unauthenticated requests to the OAuth login and error endpoints as an additional defense. The proxy must re-establish TLS to the existing OAuth route, preserve the OAuth hostname/SNI, and validate the backend certificate. Do not disable TLS verification or expose the OAuth service directly. If an external TLS-terminating control cannot be deployed, there is no supported OpenShift router-only mitigation while the OAuth route remains TLS passthrough. Restricting access to the OAuth endpoint to trusted networks can reduce exposure but may affect user access. Upgrade to the first OpenShift release containing the fix as soon as it is available. Workaround: Red Hat has not identified any known mitigations for this issue. Customers are advised to apply the available security update when released.

🔗 References (12)