Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.20.10 security, enhancement & bug fix update
Red Hat OpenShift Data Foundation 4.20.10 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-6171: RHODF 4.20.10 release DFBUGS-6016: Backport to odf-4.20.z [GSS] No public access to buckets after ODF upgrade to 4.20 DFBUGS-5941: Backport to odf-4.20.z [External Mode]: noobaa-default-backing-store is in creating state due to "CheckExternalConnection Status=UNKNOWN_FAILURE Error=SELF_SIGNED_CERT_IN_CHAIN" DFBUGS-5818: [Backport to odf-4.20.z] [IBM_Support][Fusion HCI]"storageclient-xxxxx-status-reporter job" doesn't inherits the tolerations defined in "ocs-client-operator-controller-manager" deployment DFBUGS-5801: [Backport to odf-4.20.z] must-gather causes default RGW pools to be created and PGs to be stuck at 1 DFBUGS-5115: [csi] Handle race conditions during relocate/failover of RBD based workloads DFBUGS-4747: Unable to select NAD from dropdown list when creating storage cluster when using Multus CVEs: ========== CVE-2026-4800 CVE-2026-34986 CVE-2026-33186 CVE-2026-33036 CVE-2026-27942
AI Analysis
Technical Summary
Red Hat has issued security advisories for several products including Red Hat Data Grid 8.6.1 and OpenShift Container Platform 4.21.24. The advisories address multiple vulnerabilities such as CVE-2026-4800 (lodash arbitrary code execution via untrusted input in template imports), CVE-2026-33870 and CVE-2026-33871 (Netty request smuggling and denial of service), several Axios prototype pollution and denial of service issues, DOMPurify cross-site scripting (CVE-2026-41240), Apache Log4j denial of service and log injection vulnerabilities, and a Spring Boot weak pseudo-random number generation issue leading to information disclosure. The advisories provide updated container images and packages to remediate these vulnerabilities. The updates have been rated with an important security impact by Red Hat Product Security.
Potential Impact
The vulnerabilities collectively allow for arbitrary code execution, denial of service attacks, request smuggling, authentication bypass, cross-site scripting, and potential information disclosure. These issues can affect system availability, confidentiality, and integrity if exploited. The impact severity is rated as important/high by Red Hat, indicating significant security risks that could be leveraged by attackers if unpatched.
Mitigation Recommendations
Red Hat has released official security updates and patches for the affected products and versions. Users should apply all relevant errata and updates as described in the vendor advisories (RHSA-2026:22619 for Red Hat Data Grid 8.6.1 and RHSA-2026:37186 for OpenShift Container Platform 4.21.24). Detailed upgrade instructions are available in the Red Hat documentation. No additional mitigation steps beyond applying these official fixes are indicated by the vendor.
Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.20.10 security, enhancement & bug fix update
Description
Red Hat OpenShift Data Foundation 4.20.10 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-6171: RHODF 4.20.10 release DFBUGS-6016: Backport to odf-4.20.z [GSS] No public access to buckets after ODF upgrade to 4.20 DFBUGS-5941: Backport to odf-4.20.z [External Mode]: noobaa-default-backing-store is in creating state due to "CheckExternalConnection Status=UNKNOWN_FAILURE Error=SELF_SIGNED_CERT_IN_CHAIN" DFBUGS-5818: [Backport to odf-4.20.z] [IBM_Support][Fusion HCI]"storageclient-xxxxx-status-reporter job" doesn't inherits the tolerations defined in "ocs-client-operator-controller-manager" deployment DFBUGS-5801: [Backport to odf-4.20.z] must-gather causes default RGW pools to be created and PGs to be stuck at 1 DFBUGS-5115: [csi] Handle race conditions during relocate/failover of RBD based workloads DFBUGS-4747: Unable to select NAD from dropdown list when creating storage cluster when using Multus CVEs: ========== CVE-2026-4800 CVE-2026-34986 CVE-2026-33186 CVE-2026-33036 CVE-2026-27942
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Red Hat has issued security advisories for several products including Red Hat Data Grid 8.6.1 and OpenShift Container Platform 4.21.24. The advisories address multiple vulnerabilities such as CVE-2026-4800 (lodash arbitrary code execution via untrusted input in template imports), CVE-2026-33870 and CVE-2026-33871 (Netty request smuggling and denial of service), several Axios prototype pollution and denial of service issues, DOMPurify cross-site scripting (CVE-2026-41240), Apache Log4j denial of service and log injection vulnerabilities, and a Spring Boot weak pseudo-random number generation issue leading to information disclosure. The advisories provide updated container images and packages to remediate these vulnerabilities. The updates have been rated with an important security impact by Red Hat Product Security.
Potential Impact
The vulnerabilities collectively allow for arbitrary code execution, denial of service attacks, request smuggling, authentication bypass, cross-site scripting, and potential information disclosure. These issues can affect system availability, confidentiality, and integrity if exploited. The impact severity is rated as important/high by Red Hat, indicating significant security risks that could be leveraged by attackers if unpatched.
Mitigation Recommendations
Red Hat has released official security updates and patches for the affected products and versions. Users should apply all relevant errata and updates as described in the vendor advisories (RHSA-2026:22619 for Red Hat Data Grid 8.6.1 and RHSA-2026:37186 for OpenShift Container Platform 4.21.24). Detailed upgrade instructions are available in the Red Hat documentation. No additional mitigation steps beyond applying these official fixes are indicated by the vendor.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:8498
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-30951"]
Threat ID: 6a160973e29bf47b5063cc8c
Added to database: 05/26/2026, 20:58:27 UTC
Last enriched: 08/10/2026, 20:10:51 UTC
Last updated: 09/13/2026, 10:01:31 UTC
Views: 144
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.