RHSA-2026:8449HighCVSS 9.1

Red Hat Security Advisory: OpenShift Container Platform 4.18.38 security and extras update

Published
April 22, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:2a95a7a72b4bb72df3ad735daf473d8cb741f3b724b04d1fc4c3f922385e6f31_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:885187f03bee5cb33e165033f01cdfd45a89623894a5cf8bb15f9382cefec06e_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:c4c796c1f46a55a1b987f39dff040e2bb1294d83485d99e1ce640da1730129f7_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:f7533fb49cc7722fc6f44ca14d258e98f40b148cc4c2becbc3f006c616fd6317_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:1fd7b0e374a3ff76f7f5bbf9a6afeabd971e15fd1714d3f4eb07e4aa5164e0a8_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:587f10b20e54ccfe3306dde5bf10e8a2d73b48c75747805e16bfdb1cb1c2fa2e_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:9000c8b4432cac4f0f857488472475e9d47685eef67aaab5dc1c1c2c70019dc2_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:c0c2fd90ec7dbe4c76b8d513eca9ae2fe4c534be4c6fa7efc2724058382e80a4_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:32327bda044afb4274385067112612d173a746a37599dd72358ffa8148b4792e_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:713ef2fe1d4a30d28da83a5c1a72a5ff2edf8393b678bf39ddad3b18c1484719_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:a4da9f5fb7925592dce498d87567a56ca6bdf49273cebfddcc05dd1fdb316969_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:f4a720ace133d6c1f5fcd45a2c303a8e7aa76c76c7b1da2d7f702180c6b399a0_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:1214f8056d2c84ea40da8684c5095cc861414c9c34133db16e59c475a2b18c41_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:1495020a04a1d74dbc7d60917a8a50f6c5d3910465f2d60444f3be93159b7f75_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:64b0e890c8de3901fcc1844d01c2ea6f5c3d0395ee51a0dc7ce945230072d13e_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:896cc1797313b8506187dca1c433081ae56578401bd85da0d4330cd3560c0a06_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:46936f2ad5ef1c5a9e4d949c8f8644baca46c8b5301b367372470125dbf84ec9_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:495fb951ed8b3e9b3f612e42c2f60af25d2b35e220dc6b37444ec47713c9da3e_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:a61151f9c974fc4f99148d03c7a870f047f925aab96d1deb0273b4287f68e0ac_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:e3bf7627d8a87795c8aad6c77f7c6a484a4ce03570302f86582d11faa0ec36a4_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:67ec9437477701b3c315be2a8b3fc3adcfa7552e29627bc0cf04b51179a77793_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:abd03a1bd122b5f16bd0abff44c630c06f31fa7deb8068ac49412831037f5b1c_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:b3a12d20bdcf0657dd32d9f2a64caf4bbdc2f9d5c33fac7f03a8cb92e769581d_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/metallb-rhel9@sha256:ba1a2bd374d6579bf16d324003dae5916ec365dbb94f0ae758d42335a861be22_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:144acfc8051b87aeb089d1cfca45c873eb6c14130e511763ff113c3e6e1696fa_s390x as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:1eeb0b9b7726c2557b77d418810884f12a7c2047cc5b13fb8d645593649820bf_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:4ad4fe8a96b04a14d62e9efbc05761e08a29ef738b609152f9f51e351ae6bbc9_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/nmstate-console-plugin-rhel9@sha256:875131bbf9f3329414a18be1cca576e4256e973b19c2ac9006d3d81ea05a681e_arm64 as a component of Red Hat OpenShift Container Platform 4.18
  • registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:14c4bdb3a4af3c06b0c6b4d1dd87bdf2cca0840dfc5fbacd6ffb9b1b07ebcba6_amd64 as a component of Red Hat OpenShift Container Platform 4.18
  • +170 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ Details on how to access this content are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.

🔗 References (4)