Skip to main content
EPSS 2.8%top 15%

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.20.10 security, enhancement & bug fix update

0
Critical
Published: 04/30/2026 (04/30/2026, 11:25:14 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Data Foundation 4.20.10 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-6171: RHODF 4.20.10 release DFBUGS-6016: Backport to odf-4.20.z [GSS] No public access to buckets after ODF upgrade to 4.20 DFBUGS-5941: Backport to odf-4.20.z [External Mode]: noobaa-default-backing-store is in creating state due to "CheckExternalConnection Status=UNKNOWN_FAILURE Error=SELF_SIGNED_CERT_IN_CHAIN" DFBUGS-5818: [Backport to odf-4.20.z] [IBM_Support][Fusion HCI]"storageclient-xxxxx-status-reporter job" doesn't inherits the tolerations defined in "ocs-client-operator-controller-manager" deployment DFBUGS-5801: [Backport to odf-4.20.z] must-gather causes default RGW pools to be created and PGs to be stuck at 1 DFBUGS-5115: [csi] Handle race conditions during relocate/failover of RBD based workloads DFBUGS-4747: Unable to select NAD from dropdown list when creating storage cluster when using Multus CVEs: ========== CVE-2026-4800 CVE-2026-34986 CVE-2026-33186 CVE-2026-33036 CVE-2026-27942

Affected software

Affected versions
=8.6.1=4.21.24=6.18Red HatRed Hat SatelliteRed Hat Satellite 6.18amd64registry.redhat.io/satellite/iop-remediations-rhel9@sha256:94bfbcac75fca25a6babc06844a05703c5e745939c62288131f56e039877601c_amd64Red Hat OpenShift Container PlatformRed Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:b63c025b4bbfb73fdbae3c740745851ec819de710911534c516d3d9a9587637b_amd64Red Hat Ansible Automation PlatformRed Hat Ansible Automation Platform 2.6 for RHEL 9Red Hat JBoss Data GridRed Hat Data Grid 8.6.1Red Hat OpenShift Container Platform 4.22arm64registry.redhat.io/openshift4/ose-machine-api-provider-azure-rhel9@sha256:c3784468ebdf935dae7d9829f3ca939da75b58903c089a5b0c4ce49d066b37e7_arm64Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:5875ce179ab7eb09e92a3355536ba83e534712d7362c2289ff13b9fe0be0d1bf_amd64registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:6ae1dc902850b538b3c352530e1006d739479e65e06304e0e5b3d702110a70a2_amd64Red Hat OpenShift Container Platform 4.2registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:cde57abb7a287e9abec2b61fb0bc76931c0018ef655d7ba1b43411f6865406cf_amd64Red Hat Ansible Automation Platform 2.5 for RHEL 9Red Hat OpenShift Container Platform 4.13registry.redhat.io/openshift4/ose-cluster-autoscaler@sha256:af81be33796b3cf9d074b10171c908846091a8073e02beb68a36c8453f367b87_amd64Red Hat Openshift Data FoundationRed Hat Openshift Data Foundation 4.2registry.redhat.io/odf4/cephcsi-rhel9@sha256:dfdf81ab0ca1b4c8155b8b37db728aa37c3b708e8621995da9cbd576086954c3_amd64Red Hat OpenShift GitOpsRed Hat OpenShift GitOps 1.18registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:a4e3a3345862f1dbefe620bce99794e01fca58e650f3291ec4519a953398e726_amd64Red Hat OpenShift Container Platform 4.20Red Hat OpenShift Container Platform 4.19registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:0f1f30c7e4566d7c2fe5b60ec0c423c30452612f79419a80d90de3753d261535_amd64Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:4ae0174eec7cff35f2ae0926d28975ad4d2f303c4c3259fc5e2b9deea91699ad_amd64Red Hat OpenShift Container Platform 4.17registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:7644b30ed4732df915c526f148de469c71e28ef1ad4f593cad4779d6e8eefc71_amd64ppc64leregistry.redhat.io/openshift4/ose-pod-rhel9@sha256:ce699b66506a1c96f29ec17d0505438345365d05db5e97d15fcaee11e61ba9c7_ppc64le

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 20:10:51 UTC

Technical Analysis

Red Hat has issued security advisories for several products including Red Hat Data Grid 8.6.1 and OpenShift Container Platform 4.21.24. The advisories address multiple vulnerabilities such as CVE-2026-4800 (lodash arbitrary code execution via untrusted input in template imports), CVE-2026-33870 and CVE-2026-33871 (Netty request smuggling and denial of service), several Axios prototype pollution and denial of service issues, DOMPurify cross-site scripting (CVE-2026-41240), Apache Log4j denial of service and log injection vulnerabilities, and a Spring Boot weak pseudo-random number generation issue leading to information disclosure. The advisories provide updated container images and packages to remediate these vulnerabilities. The updates have been rated with an important security impact by Red Hat Product Security.

Potential Impact

The vulnerabilities collectively allow for arbitrary code execution, denial of service attacks, request smuggling, authentication bypass, cross-site scripting, and potential information disclosure. These issues can affect system availability, confidentiality, and integrity if exploited. The impact severity is rated as important/high by Red Hat, indicating significant security risks that could be leveraged by attackers if unpatched.

Mitigation Recommendations

Red Hat has released official security updates and patches for the affected products and versions. Users should apply all relevant errata and updates as described in the vendor advisories (RHSA-2026:22619 for Red Hat Data Grid 8.6.1 and RHSA-2026:37186 for OpenShift Container Platform 4.21.24). Detailed upgrade instructions are available in the Red Hat documentation. No additional mitigation steps beyond applying these official fixes are indicated by the vendor.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:8498
Cve Count
2
Additional Cves
["CVE-2026-30951"]

Threat ID: 6a160973e29bf47b5063cc8c

Added to database: 05/26/2026, 20:58:27 UTC

Last enriched: 08/10/2026, 20:10:51 UTC

Last updated: 09/13/2026, 10:01:31 UTC

Views: 144

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:22619https://access.redhat.com/security/updates/classification/#importanthttps://docs.redhat.com/en/documentation/red_hat_data_grid/8.6245245324524562453496245732124573232457328246114724616072461626246162924616302463331Canonical URLhttps://access.redhat.com/errata/RHSA-2026:37186https://access.redhat.com/security/cve/CVE-2026-13676https://access.redhat.com/security/cve/CVE-2026-44293https://access.redhat.com/security/cve/CVE-2026-4800https://access.redhat.com/security/cve/CVE-2026-6322https://access.redhat.com/security/cve/CVE-2026-9595https://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:8498https://access.redhat.com/documentation/en-us/red_hat_satellite/6.18/html/updating_red_hat_satellite/indexhttps://access.redhat.com/security/cve/CVE-2026-30951https://catalog.redhat.com/software/containers/searchhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.18/html/installing_satellite_server_in_a_connected_network_environment/performing-additional-configuration-on-server_satellite#installing-and-configuring-red-hat-lightspeed-in-satellitehttps://docs.redhat.com/en/documentation/red_hat_satellite/6.18/html/installing_satellite_server_in_a_disconnected_network_environment/performing-additional-configuration#installing-and-configuring-red-hat-lightspeed-in-satelliteCanonical URLhttps://access.redhat.com/errata/RHSA-2026:24762https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updateshttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade24485532451867245245024561792456336245633824563392456735245743224588562464121Canonical URLhttps://access.redhat.com/errata/RHSA-2026:29795https://access.redhat.com/security/cve/CVE-2026-35469https://access.redhat.com/security/cve/CVE-2026-9277Canonical URLhttps://access.redhat.com/errata/RHSA-2026:12277https://access.redhat.com/security/cve/CVE-2026-27942https://access.redhat.com/security/cve/CVE-2026-33036https://access.redhat.com/security/cve/CVE-2026-33186https://access.redhat.com/security/cve/CVE-2026-34986https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:42078https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/release_notes/patch_releaseshttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading245633324609272461624246658224666842467822247715424807562480757248076124853792487937248793824879422487943https://access.redhat.com/errata/RHSA-2026:20946https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/cve/CVE-2026-33487https://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.18/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:36621https://access.redhat.com/security/cve/CVE-2026-12151https://access.redhat.com/security/cve/CVE-2026-26996https://access.redhat.com/security/cve/CVE-2026-29063https://access.redhat.com/security/cve/CVE-2026-9697Canonical URLhttps://access.redhat.com/errata/RHSA-2026:48699https://access.redhat.com/security/cve/CVE-2026-16242https://access.redhat.com/security/cve/CVE-2026-40895https://access.redhat.com/security/cve/CVE-2026-42154Canonical URLhttps://access.redhat.com/errata/RHSA-2026:40795https://access.redhat.com/security/cve/CVE-2026-44487https://access.redhat.com/security/cve/CVE-2026-44488https://access.redhat.com/security/cve/CVE-2026-44494https://access.redhat.com/security/cve/CVE-2026-44495Canonical URLhttps://access.redhat.com/errata/RHSA-2026:44235https://access.redhat.com/security/cve/CVE-2026-45736Canonical URLhttps://access.redhat.com/errata/RHSA-2026:54188https://access.redhat.com/security/cve/CVE-2026-44486https://access.redhat.com/security/cve/CVE-2026-44492https://access.redhat.com/security/cve/CVE-2026-49332https://access.redhat.com/security/cve/CVE-2026-50237Canonical URLhttps://access.redhat.com/errata/RHSA-2026:60023https://access.redhat.com/security/cve/CVE-2026-25681https://access.redhat.com/security/cve/CVE-2026-33814https://access.redhat.com/security/cve/CVE-2026-39820https://access.redhat.com/security/cve/CVE-2026-42499https://access.redhat.com/security/cve/CVE-2026-42504https://access.redhat.com/security/cve/CVE-2026-46597https://access.redhat.com/security/cve/CVE-2026-50236Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses