Skip to main content
EPSS 0.7%top 50%

Red Hat Security Advisory: OpenShift Container Platform 4.19.46 bug fix and security update

0
High
Published: 09/09/2026 (09/09/2026, 08:42:43 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.19.46. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:63043 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/

Affected software

Affected versions
>=4.22.0 <4.22.8Red HatRed Hat QuayRed Hat Quay 3.9amd64registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:9f2a14e20042280f51bfec86c00ac87a5309c991efc1b8b6f1dd0afb7772c297_amd64Red Hat OpenShift Container PlatformRed Hat OpenShift Container Platform 4.22registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:0e16a3aafd2f71e49d1879721cc76bd1711fae7b0be615be35ec6dbbc7cd3f6c_amd64Red Hat Quay 3.10registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:de47c8f5fedac6402e34eea1d214a3bb2b9509df89ad8ae1593b91816eec082c_amd64Red Hat OpenShift Service MeshRed Hat OpenShift Service Mesh 2.6registry.redhat.io/openshift-service-mesh/kiali-rhel8@sha256:eff6e4643347f77c419cb3e32b4c9d914762b9f2114e832126964850b7179967_amd64Red Hat Quay 3.1Red Hat OpenShift Service Mesh 3.0registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:12ce2d6283ac3fe295e53ac099b14222722fdcb9c549fbe2243ae83069f3cfa4_amd64Red Hat OpenShift Service Mesh 3.1registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:c5926bbd0cb2414e4fd0117e11ccec6d33924c2ea255ca7f500419c7886807cf_amd64Red Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:6cc59e499071fb3a97ecfcdab32b29ed94b3e725d4c0c47f67b096205296e7e3_amd64Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:6759b5f712098d890c6a5124fb513097050f70b54e7e3723df4e74a36a40c3f3_amd64registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:6af9db4e27783405ff45495bc7a7b49bb35f7beb0fdf26ac25ea07c8e6ed45c2_amd64Red Hat Quay 3.12registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:555002449f4047e356874300069b4364498572151a0f537705f13d4b33f311d8_amd64registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:007e613b5b6b22468ad411bb6c86b2746c5a32940edec08d9eb4e921464a7fff_amd64Red Hat Ansible Automation PlatformRed Hat Ansible Automation Platform 2.6 for RHEL 9Red Hat OpenShift Container Platform 4.20s390xregistry.redhat.io/openshift4/ose-cluster-openshift-apiserver-rhel9-operator@sha256:9b4b1b0df3267ed02d64b2e8b6f8e278cbf5c3d2dc265278d0b7dea05666a5f6_s390xRed Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/ose-csi-external-provisioner-rhel9@sha256:1696b28f360fce436023b5d8241d066ab624f3f9a820e321d7c3f445fcac9b14_amd64registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:16d7437228941591eb844176c10227ec82f2331d2f53fbbcf1ddb4835c52a549_amd64registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:8e245c278c66405066cb31e9d48e97ad9cdb826511bdb1104807d26f896043a2_amd64Red Hat SatelliteRed Hat Satellite 6.18registry.redhat.io/satellite/iop-host-inventory-frontend-rhel9@sha256:fd37a07733418f4372eee13028d427201043b476b77ae562dc9c133f27477941_amd64Red Hat Satellite 6.19registry.redhat.io/satellite/iop-host-inventory-frontend-rhel9@sha256:41f3be239e4b29085e6e373c8c095580f33e140a4965ca3515cf78188e407182_amd64Red Hat OpenShift Container Platform 4.2registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:d5c9228f18d9ef7b387a53d7213d65d2533e380bdc0611a42c2e46c45a1fdb73_amd64registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:568c544f2daf1c0b33d022880a8ae37486774dde9988e41fe88b6fb573cd7a47_amd64Red Hat OpenShift Container Platform 4.19registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:de4678cf48139a644eb3670156f02e7d88fea344b0621902144a1c9965aa2e23_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 23:36:17 UTC

Technical Analysis

This advisory covers multiple security flaws in Kiali components used in Red Hat OpenShift Service Mesh and related products. Notable vulnerabilities include CVE-2026-12143, a CRLF injection in the form-data library that allows attackers to inject additional headers or multipart form fields by injecting carriage return, line feed, or double-quote characters into field names or filenames. This can lead to form field override and data integrity compromise, particularly in custom deployments that use untrusted input for multipart form fields. Other vulnerabilities include cross-site scripting via improper HTML escaping (CVE-2026-42338), privilege escalation due to incorrect Punycode processing (CVE-2026-39821), prototype pollution causing information disclosure and man-in-the-middle attacks (multiple CVEs), denial of service via request size limits and WebSocket memory exhaustion, and proxy bypass via IPv4-mapped IPv6 address non-normalization. Red Hat has released updated Kiali versions (e.g., 1.73.33 for OpenShift Service Mesh 2.6) that address these issues. The advisory notes that default deployments using fixed field names are not impacted by the CRLF injection vulnerability. The vulnerabilities affect multiple Red Hat products including OpenShift Service Mesh versions 2.6 through 3.3 and Red Hat Quay versions 3.1 through 3.12.

Potential Impact

The vulnerabilities collectively allow attackers to perform cross-site scripting, privilege escalation, information disclosure, denial of service, proxy bypass, and form field override via CRLF injection. The CRLF injection vulnerability (CVE-2026-12143) can compromise data integrity by allowing injection of arbitrary headers or multipart parts in HTTP requests. Prototype pollution vulnerabilities can lead to information disclosure and man-in-the-middle attacks. Denial of service vulnerabilities can exhaust memory or bypass request size limits. The impact is rated high overall, with some vulnerabilities rated moderate depending on deployment specifics. No known exploits in the wild have been reported at this time.

Mitigation Recommendations

Red Hat has released updated Kiali versions, such as Kiali 1.73.33 for OpenShift Service Mesh 2.6, which include fixes for these vulnerabilities. Users should upgrade to these fixed versions as documented in the Red Hat advisory. For the CRLF injection vulnerability in the form-data library, deployments that use fixed or trusted field names are not impacted. Custom integrations that forward multipart requests with attacker-controlled field names should implement strict input validation and sanitization to prevent injection of control characters (CR, LF, "). Monitoring vendor advisories and applying official patches is recommended to maintain security.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_vex
Csaf Version
2.0
Publisher
Microsoft Security Response Center
Advisory Id
msrc_CVE-2026-12143
Cve Count
1

Threat ID: 6a3c0d23eed863c81e23eb70

Added to database: 06/24/2026, 17:00:19 UTC

Last enriched: 08/14/2026, 23:36:17 UTC

Last updated: 09/27/2026, 05:25:16 UTC

Views: 188

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:33155https://access.redhat.com/security/cve/CVE-2026-12143https://access.redhat.com/security/cve/CVE-2026-39821https://access.redhat.com/security/cve/CVE-2026-42338https://access.redhat.com/security/cve/CVE-2026-44486https://access.redhat.com/security/cve/CVE-2026-44487https://access.redhat.com/security/cve/CVE-2026-44488https://access.redhat.com/security/cve/CVE-2026-44492https://access.redhat.com/security/cve/CVE-2026-44494https://access.redhat.com/security/cve/CVE-2026-44495https://access.redhat.com/security/cve/CVE-2026-44496https://access.redhat.com/security/cve/CVE-2026-48779https://access.redhat.com/security/updates/classificationhttps://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:33160Canonical URLhttps://access.redhat.com/errata/RHSA-2026:33163Canonical URLhttps://access.redhat.com/errata/RHSA-2026:33173https://access.redhat.com/security/cve/CVE-2026-42264Canonical URLhttps://access.redhat.com/errata/RHSA-2026:40262https://access.redhat.com/security/cve/CVE-2026-13676https://access.redhat.com/security/cve/CVE-2026-32591https://access.redhat.com/security/cve/CVE-2026-39820https://access.redhat.com/security/cve/CVE-2026-39828https://access.redhat.com/security/cve/CVE-2026-39829https://access.redhat.com/security/cve/CVE-2026-39830https://access.redhat.com/security/cve/CVE-2026-39831https://access.redhat.com/security/cve/CVE-2026-39832https://access.redhat.com/security/cve/CVE-2026-39835https://access.redhat.com/security/cve/CVE-2026-42151https://access.redhat.com/security/cve/CVE-2026-42154https://access.redhat.com/security/cve/CVE-2026-42499https://access.redhat.com/security/cve/CVE-2026-42508https://access.redhat.com/errata/RHSA-2026:41031https://access.redhat.com/errata/RHSA-2026:33183https://access.redhat.com/security/cve/CVE-2026-46625Canonical URLhttps://access.redhat.com/errata/RHSA-2026:42146https://access.redhat.com/errata/RHSA-2026:43052https://access.redhat.com/errata/RHSA-2026:48693https://access.redhat.com/security/cve/CVE-2026-16242https://access.redhat.com/security/cve/CVE-2026-44240https://access.redhat.com/security/cve/CVE-2026-45736https://access.redhat.com/security/cve/CVE-2026-46597https://access.redhat.com/security/cve/CVE-2026-49978Canonical URLhttps://access.redhat.com/errata/RHSA-2026:54770https://access.redhat.com/security/cve/CVE-2026-14362https://access.redhat.com/security/cve/CVE-2026-27136https://access.redhat.com/security/cve/CVE-2026-39882https://access.redhat.com/security/cve/CVE-2026-42965https://access.redhat.com/security/cve/CVE-2026-50236https://access.redhat.com/security/cve/CVE-2026-50237Canonical URLhttps://access.redhat.com/errata/RHSA-2026:59136https://access.redhat.com/security/updates/classification/#importanthttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updateshttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade2456187248409924843772486729248794624884802500041250997525099762510021251003225108252510831251109525119002511901https://access.redhat.com/errata/RHSA-2026:57545https://access.redhat.com/security/cve/CVE-2026-14257https://access.redhat.com/security/cve/CVE-2026-27140https://access.redhat.com/security/cve/CVE-2026-33814https://access.redhat.com/security/cve/CVE-2026-59869Canonical URLhttps://access.redhat.com/errata/RHSA-2026:57801https://access.redhat.com/security/cve/CVE-2026-32283https://access.redhat.com/security/cve/CVE-2026-43003Canonical URLhttps://access.redhat.com/errata/RHSA-2026:60477https://access.redhat.com/security/cve/CVE-2026-48801https://access.redhat.com/security/cve/CVE-2026-54423https://access.redhat.com/security/cve/CVE-2026-59877https://access.redhat.com/security/cve/CVE-2026-66138https://access.redhat.com/security/cve/CVE-2026-69152https://access.redhat.com/security/cve/CVE-2026-73086Canonical URLhttps://access.redhat.com/errata/RHSA-2026:60446https://access.redhat.com/security/cve/CVE-2026-73566Canonical URLhttps://access.redhat.com/errata/RHSA-2026:63373https://access.redhat.com/documentation/en-us/red_hat_satellite/6.18/html/updating_red_hat_satellite/indexhttps://access.redhat.com/security/cve/CVE-2026-45623https://access.redhat.com/security/cve/CVE-2026-67313https://access.redhat.com/security/cve/CVE-2026-67314https://access.redhat.com/security/cve/CVE-2026-67320https://access.redhat.com/security/cve/CVE-2026-67321https://access.redhat.com/security/cve/CVE-2026-73088https://access.redhat.com/security/cve/CVE-2026-73089https://catalog.redhat.com/software/containers/searchhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.18/html/installing_satellite_server_in_a_connected_network_environment/performing-additional-configuration-on-server_satellite#installing-and-configuring-red-hat-lightspeed-in-satellitehttps://docs.redhat.com/en/documentation/red_hat_satellite/6.18/html/installing_satellite_server_in_a_disconnected_network_environment/performing-additional-configuration#installing-and-configuring-red-hat-lightspeed-in-satelliteCanonical URLhttps://access.redhat.com/errata/RHSA-2026:63355https://access.redhat.com/documentation/en-us/red_hat_satellite/6.19/html/updating_red_hat_satellite/indexhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.19/html/installing_satellite_server_in_a_connected_network_environment/performing-additional-configuration-on-server_satellite#installing-and-configuring-red-hat-lightspeed-in-satellitehttps://docs.redhat.com/en/documentation/red_hat_satellite/6.19/html/installing_satellite_server_in_a_disconnected_network_environment/performing-additional-configuration#installing-and-configuring-red-hat-lightspeed-in-satelliteCanonical URLhttps://access.redhat.com/errata/RHSA-2026:63047https://access.redhat.com/security/cve/CVE-2026-69153Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses