Red Hat Security Advisory: OpenShift Container Platform 4.19.46 bug fix and security update
Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.19.46. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:63043 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/
AI Analysis
Technical Summary
This advisory covers multiple security flaws in Kiali components used in Red Hat OpenShift Service Mesh and related products. Notable vulnerabilities include CVE-2026-12143, a CRLF injection in the form-data library that allows attackers to inject additional headers or multipart form fields by injecting carriage return, line feed, or double-quote characters into field names or filenames. This can lead to form field override and data integrity compromise, particularly in custom deployments that use untrusted input for multipart form fields. Other vulnerabilities include cross-site scripting via improper HTML escaping (CVE-2026-42338), privilege escalation due to incorrect Punycode processing (CVE-2026-39821), prototype pollution causing information disclosure and man-in-the-middle attacks (multiple CVEs), denial of service via request size limits and WebSocket memory exhaustion, and proxy bypass via IPv4-mapped IPv6 address non-normalization. Red Hat has released updated Kiali versions (e.g., 1.73.33 for OpenShift Service Mesh 2.6) that address these issues. The advisory notes that default deployments using fixed field names are not impacted by the CRLF injection vulnerability. The vulnerabilities affect multiple Red Hat products including OpenShift Service Mesh versions 2.6 through 3.3 and Red Hat Quay versions 3.1 through 3.12.
Potential Impact
The vulnerabilities collectively allow attackers to perform cross-site scripting, privilege escalation, information disclosure, denial of service, proxy bypass, and form field override via CRLF injection. The CRLF injection vulnerability (CVE-2026-12143) can compromise data integrity by allowing injection of arbitrary headers or multipart parts in HTTP requests. Prototype pollution vulnerabilities can lead to information disclosure and man-in-the-middle attacks. Denial of service vulnerabilities can exhaust memory or bypass request size limits. The impact is rated high overall, with some vulnerabilities rated moderate depending on deployment specifics. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released updated Kiali versions, such as Kiali 1.73.33 for OpenShift Service Mesh 2.6, which include fixes for these vulnerabilities. Users should upgrade to these fixed versions as documented in the Red Hat advisory. For the CRLF injection vulnerability in the form-data library, deployments that use fixed or trusted field names are not impacted. Custom integrations that forward multipart requests with attacker-controlled field names should implement strict input validation and sanitization to prevent injection of control characters (CR, LF, "). Monitoring vendor advisories and applying official patches is recommended to maintain security.
Red Hat Security Advisory: OpenShift Container Platform 4.19.46 bug fix and security update
Description
Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.19.46. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:63043 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers multiple security flaws in Kiali components used in Red Hat OpenShift Service Mesh and related products. Notable vulnerabilities include CVE-2026-12143, a CRLF injection in the form-data library that allows attackers to inject additional headers or multipart form fields by injecting carriage return, line feed, or double-quote characters into field names or filenames. This can lead to form field override and data integrity compromise, particularly in custom deployments that use untrusted input for multipart form fields. Other vulnerabilities include cross-site scripting via improper HTML escaping (CVE-2026-42338), privilege escalation due to incorrect Punycode processing (CVE-2026-39821), prototype pollution causing information disclosure and man-in-the-middle attacks (multiple CVEs), denial of service via request size limits and WebSocket memory exhaustion, and proxy bypass via IPv4-mapped IPv6 address non-normalization. Red Hat has released updated Kiali versions (e.g., 1.73.33 for OpenShift Service Mesh 2.6) that address these issues. The advisory notes that default deployments using fixed field names are not impacted by the CRLF injection vulnerability. The vulnerabilities affect multiple Red Hat products including OpenShift Service Mesh versions 2.6 through 3.3 and Red Hat Quay versions 3.1 through 3.12.
Potential Impact
The vulnerabilities collectively allow attackers to perform cross-site scripting, privilege escalation, information disclosure, denial of service, proxy bypass, and form field override via CRLF injection. The CRLF injection vulnerability (CVE-2026-12143) can compromise data integrity by allowing injection of arbitrary headers or multipart parts in HTTP requests. Prototype pollution vulnerabilities can lead to information disclosure and man-in-the-middle attacks. Denial of service vulnerabilities can exhaust memory or bypass request size limits. The impact is rated high overall, with some vulnerabilities rated moderate depending on deployment specifics. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released updated Kiali versions, such as Kiali 1.73.33 for OpenShift Service Mesh 2.6, which include fixes for these vulnerabilities. Users should upgrade to these fixed versions as documented in the Red Hat advisory. For the CRLF injection vulnerability in the form-data library, deployments that use fixed or trusted field names are not impacted. Custom integrations that forward multipart requests with attacker-controlled field names should implement strict input validation and sanitization to prevent injection of control characters (CR, LF, "). Monitoring vendor advisories and applying official patches is recommended to maintain security.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_vex
- Csaf Version
- 2.0
- Publisher
- Microsoft Security Response Center
- Advisory Id
- msrc_CVE-2026-12143
- Cve Count
- 1
Threat ID: 6a3c0d23eed863c81e23eb70
Added to database: 06/24/2026, 17:00:19 UTC
Last enriched: 08/14/2026, 23:36:17 UTC
Last updated: 09/27/2026, 05:25:16 UTC
Views: 188
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.