Skip to main content
EPSS 0.8%top 46%

Red Hat Security Advisory: OpenShift Container Platform 4.19.45 bug fix and security update

0
High
Published: 09/02/2026 (09/02/2026, 07:58:24 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.19.45. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:60452 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/

Affected software

golang.org/x/net/http2
pkg:golang/golang.org/x/net/http2
Affected versions
*

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 20:02:18 UTC

Technical Analysis

The vulnerability exists in the HTTP/2 protocol implementation within the Go standard library (golang.org/x/net and net/http/internal/http2). When processing HTTP/2 SETTINGS frames, if a SETTINGS_MAX_FRAME_SIZE parameter is set to zero, the transport layer enters an infinite loop writing CONTINUATION frames. This loop causes resource exhaustion leading to a denial of service (DoS) condition. The flaw is categorized under CWE-835 (Loop with Unreachable Exit Condition) and CWE-606 (Unchecked Input for Loop Condition). The CVSS v3.1 base score is 7.5 (High), with network attack vector, low complexity, no privileges required, no user interaction, and high impact on availability only. Red Hat advisory states no mitigation currently meets their criteria for ease of use, applicability, or stability.

Potential Impact

The vulnerability allows a remote, unauthenticated attacker to cause a denial of service by exhausting system resources through an infinite loop triggered by a malformed HTTP/2 SETTINGS frame. There is no impact on confidentiality or integrity. The availability of services using the affected Go HTTP/2 implementation can be disrupted.

Mitigation Recommendations

According to the Red Hat advisory, no mitigation is currently available that meets their criteria for ease of use, deployment, applicability, or stability. Users should monitor vendor advisories for future patches or updates. Upgrading to a fixed version when available is recommended. Until then, no effective workaround is provided by the vendor.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_vex
Csaf Version
2.0
Publisher
Microsoft Security Response Center
Advisory Id
msrc_CVE-2026-33814
Cve Count
1
State
PUBLISHED

Threat ID: 6a1ca15de29bf47b505e22a9

Added to database: 05/31/2026, 21:00:13 UTC

Last enriched: 08/13/2026, 20:02:18 UTC

Last updated: 09/14/2026, 00:46:51 UTC

Views: 220

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEReference 1Reference 2Reference 3Reference 4Reference 5Reference 6Reference 7Reference 8Reference 9Reference 10Reference 11Reference 12Reference 13Reference 14Reference 15Reference 16Reference 17Reference 18Reference 19Reference 20Reference 21Reference 22Reference 23Reference 24Reference 25Reference 26Reference 27Reference 28https://access.redhat.com/errata/RHSA-2026:57845https://access.redhat.com/security/updates/classification/#important246780924678202480756Canonical URLReference 35Reference 36Reference 37Reference 38Reference 39Reference 40Reference 41Reference 42Reference 43Reference 44Reference 45Reference 46Reference 47Reference 48https://access.redhat.com/errata/RHSA-2026:60442https://access.redhat.com/security/cve/CVE-2026-73088https://access.redhat.com/security/cve/CVE-2026-73089https://access.redhat.com/security/cve/CVE-2026-73643https://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:60668Canonical URLReference 57Reference 58Reference 59Reference 60Reference 61Reference 62Reference 63https://access.redhat.com/security/cve/CVE-2026-39829https://access.redhat.com/security/cve/CVE-2026-43003https://access.redhat.com/security/cve/CVE-2026-59869Canonical URLReference 68Reference 69Reference 70https://access.redhat.com/errata/RHSA-2026:63048Canonical URLhttps://access.redhat.com/errata/RHSA-2026:62551Canonical URLhttps://access.redhat.com/errata/RHSA-2026:63639Canonical URLhttps://access.redhat.com/errata/RHSA-2026:63636Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses