Skip to main content
EPSS 0.2%top 88%

Red Hat Security Advisory: OpenShift Container Platform 4.20.39 bug fix and security update

0
High
Published: 09/22/2026 (09/22/2026, 09:49:41 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.20.39. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2026:68535 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/

Affected software

Affected versions
>=10.0.0=1.5.2-r1=1.26.0-r0>=10.0.0 <10.2.0Red HatRed Hat OpenShift GitOpsRed Hat OpenShift GitOps 1.2amd64registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel9@sha256:e13198a63c267ab7e4447218a5b071a4d64d7828e3c19825642b690fdd924a12_amd64Logging for Red Hat OpenShiftLogging for Red Hat OpenShift 6.4registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:20a457aef3fe79d1504b3635b44194de337345bccdaea7faed59d2b9d773a78d_amd64Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 10)srcopentelemetry-collector-0:0.152.1-1.el10_2.srcRed Hat Enterprise Linux AppStream (v. 9)x86_64podman-6:5.8.2-4.el9_8.x86_64opentelemetry-collector-0:0.152.1-1.el9_8.srcgrafana-0:10.2.6-27.el10_2.x86_64grafana-0:10.2.6-23.el9_8.srcRed Hat Trusted Artifact SignerRed Hat Trusted Artifact Signer 1.4registry.redhat.io/rhtas/rhtas-operator-bundle@sha256:195df73746aaab5f31babde709336f74c9bda535cd064585afac38a53b919195_amd64Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)Logging Subsystem for Red Hat OpenShiftLogging Subsystem for Red Hat OpenShift 6.2registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:9e5f624ea6566612b579400be7648bf2fab8eebcfe4dff301b8cb4da096960e8_amd64Cert Manager support for Red Hat OpenShift releaseCert Manager support for Red Hat OpenShift release 1.19registry.redhat.io/cert-manager/jetstack-cert-manager-rhel9@sha256:82461a011b7698c367b21a0866ac8c73a44fb3d5f21527cb34ed1495383207c2_amd64registry.redhat.io/rhtas/policy-controller-operator-bundle@sha256:b5c08c17bd9c60a295f9e557371da76d5bad9e87071c478e4caef82fefc375fd_amd64registry.redhat.io/cert-manager/cert-manager-istio-csr-rhel9@sha256:6468289d06d9d44dccfd3928b7ae6fc7faa5748572357367d04a20d6403df8fa_amd64Red Hat Enterprise Linux AppStream E4S (v.9.4)opentelemetry-collector-0:0.152.1-1.el9_4.srcRed Hat OpenShift Container PlatformRed Hat OpenShift Container Platform 4.20registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:cf29a2290183ee5db28c01199fa5e07e8e3d38907f0bb2f6e45aa1f981b78cee_amd64Red Hat SatelliteRed Hat Satellite 6.18registry.redhat.io/satellite/iop-vmaas-rhel9@sha256:1fdcc43ad509f20876adc6e985a1246950649ee3c3cd1dbd48cef577e0c650a9_amd64Red Hat Enterprise Linux AppStream EUS (v. 10.0)opentelemetry-collector-0:0.152.1-1.el10_0.srcLogging Subsystem for Red Hat OpenShift 6.4Logging for Red Hat OpenShift 6.2Red Hat multicluster global hubRed Hat multicluster global hub 1.4.2registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:8f60851c9d3e9cb1acd491f76b9e69ed960a0aa2aef05150db679e77041c6db0_amd64OpenShift API for Data ProtectionOpenShift API for Data Protection 1.4registry.redhat.io/oadp/oadp-cli-binaries-rhel9@sha256:611ec141ca5f61fc4fe6c7f74a6aca2013f89efd26f58663759285baae8cbcec_amd64Multicluster Global HubMulticluster Global Hub 1.5.6registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:f58b750ede7e9dbce58f763c6cdf74901499619a15fe8f57590ea647f08267ad_amd64Red Hat multicluster global hub 1.6.0registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:f7c4bbfa958c00f1f43e8d4470c4b11ee7c5558e1f2df707ca45e179370c3103_amd64Logging for Red Hat OpenShift 6.0registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:0a3cbe776357421fe89b45e9f5da54259fb91825925660e9efd2e2058b82672e_amd64Red Hat Enterprise Linux AppStream EUS (v.9.6)grafana-0:10.2.6-22.el9_6.srcLogging Subsystem for Red Hat OpenShift 6.5registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:d9bc0d110bbc7b7ec8a2401f34cde12e470980086bb04fc532a9885917c06b7f_amd64Red Hat OpenShift Workload AvailabilityRed Hat OpenShift Workload Availability 0.8registry.redhat.io/workload-availability/fence-agents-remediation-operator-bundle@sha256:f722fd012aa6bad3c185baa5644bb8087745e04d37a34b925a38575941cff096_amd64opentelemetry-collector-0:0.152.1-1.el9_6.srcRed Hat OpenShift Workload Availability 5.7registry.redhat.io/workload-availability/node-maintenance-operator-bundle@sha256:5d9fa0808c900246ef05e51d6de29c48c201c6e8b2e9cdec0f895ecb6ad26c03_amd64<1.8.0-r2Red Hat OpenShift Workload Availability 0.13registry.redhat.io/workload-availability/self-node-remediation-operator-bundle@sha256:b6ff2ce15359c7ccda7f9fdfa5500d7f01ce240ae9701de5625c31899872ca99_amd64Red Hat OpenShift GitOps 1.20Red Hat Lightspeed (formerly Insights) for RuntimesRed Hat Lightspeed (formerly Insights) for Runtimes 1.0registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:1764d020e1189c01f154dcf82c554f6bd7f95ba4377c2a47976053c46dc7e1e9_amd64Red Hat OpenShift Workload Availability 0.7registry.redhat.io/workload-availability/machine-deletion-remediation-operator-bundle@sha256:d3ef7d11ec2b62962e8d582587d19dc3295f8265d9bf0b0975742c5d6d810e3d_amd64Logging Subsystem for Red Hat OpenShift 6.0osbuild-composer-0:132.2-11.el9_6.srcRed Hat OpenShift Workload Availability 0.3registry.redhat.io/workload-availability/storage-based-remediation-agent-rhel9@sha256:cf75a72c8b4ec1972529dd273879f989e40e12a05cdf6b04c23997c0940531c4_amd64Multicluster Global Hub 1.4.5Red Hat multicluster global hub 1.5.1Red Hat multicluster global hub 1.5.3Multicluster Global Hub 1.6.5Red Hat OpenShift Workload Availability 0.12registry.redhat.io/workload-availability/node-healthcheck-operator-bundle@sha256:4214978132ffd6f9d840e2be8df4e9b85cf13d2740ba4f82fbe72f3d93d6dee5_amd64Logging for Red Hat OpenShift 6osbuild-composer-0:101.3-4.el9_4.5.srcgrafana-debuginfo-0:10.2.6-22.el9_6.x86_64osbuild-composer-0:134.1-10.el10_0.srcosbuild-composer-0:165.1-5.el10_2.x86_64image-builder-0:52.1-2.el10_2.srcRed Hat Edge ManagerRHEM 1.1 for RHEL 10RHEM 1.1 for RHEL 9osbuild-composer-0:165.1-5.el9_8.x86_64registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:7e9a363a70f5eebc7fb1be1b3b5fe0a2d1b2899669cdbc5d35b0747bd6b87117_amd64multicluster engine for Kubernetesmulticluster engine for Kubernetes 2.10registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:20cd7ea4dc9d96ba6f4002b75d798ec4f8aa511e4075d8c29232fc721d845f3d_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 16:30:37 UTC

Technical Analysis

This advisory covers security fixes for Red Hat Enterprise Linux 10 and related products, specifically for the OpenTelemetry Collector and its dependencies. The key vulnerability CVE-2026-25681 involves arbitrary code execution through Cross-Site Scripting in the golang.org/x/net/html package. Additional vulnerabilities addressed include privilege escalation via incorrect Punycode label processing (CVE-2026-39821), denial of service via long CNAME responses (CVE-2026-33811), information disclosure of Azure OAuth client secrets (CVE-2026-42151), and denial of service via uncontrolled memory allocation in Prometheus (CVE-2026-42154). The vendor advisory confirms patches are available and provides detailed update instructions. The affected products include multiple architectures and variants of Red Hat Enterprise Linux 10 and related container images.

Potential Impact

The vulnerabilities fixed in this update can lead to arbitrary code execution, privilege escalation, denial of service, and information disclosure in affected Red Hat Enterprise Linux 10 systems and components. Successful exploitation could compromise system integrity and confidentiality. The issues affect core components used in telemetry and monitoring stacks, potentially impacting observability infrastructure.

Mitigation Recommendations

Red Hat has released official patches for the affected packages in Red Hat Enterprise Linux 10 and related products. Users should apply these updates promptly following Red Hat's published guidance at https://access.redhat.com/articles/11258. No additional mitigation steps are indicated beyond applying the official fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:34364
Cve Count
10
Additional Cves
["CVE-2026-32285","CVE-2026-33186","CVE-2026-33811","CVE-2026-33813","CVE-2026-34986","CVE-2026-39820","CVE-2026-39821","CVE-2026-42154","CVE-2026-42499"]
State
PUBLISHED

Threat ID: 6a45998227e9c797194186fa

Added to database: 07/01/2026, 22:49:38 UTC

Last enriched: 08/16/2026, 16:30:37 UTC

Last updated: 09/30/2026, 07:27:43 UTC

Views: 207

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:34357https://access.redhat.com/security/updates/classification/#important246650524665072467822248075624807612484207Canonical URLhttps://access.redhat.com/errata/RHSA-2026:41030https://access.redhat.com/security/cve/CVE-2026-25681https://access.redhat.com/security/cve/CVE-2026-27136https://access.redhat.com/security/cve/CVE-2026-27145https://access.redhat.com/security/cve/CVE-2026-33811https://access.redhat.com/security/cve/CVE-2026-39821https://access.redhat.com/security/cve/CVE-2026-41567https://access.redhat.com/security/cve/CVE-2026-42151https://access.redhat.com/security/cve/CVE-2026-42154https://access.redhat.com/security/cve/CVE-2026-43870https://access.redhat.com/security/cve/CVE-2026-46384https://access.redhat.com/security/cve/CVE-2026-46385https://access.redhat.com/security/cve/CVE-2026-53488https://access.redhat.com/security/cve/CVE-2026-53492https://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:47952https://access.redhat.com/security/cve/CVE-2026-32280https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/cve/CVE-2026-32282https://access.redhat.com/security/cve/CVE-2026-33186https://access.redhat.com/security/cve/CVE-2026-33810https://access.redhat.com/security/cve/CVE-2026-34986https://access.redhat.com/security/cve/CVE-2026-39820https://access.redhat.com/security/cve/CVE-2026-42499https://access.redhat.com/security/cve/CVE-2026-42504Canonical URLhttps://access.redhat.com/errata/RHSA-2026:34359Canonical URLhttps://access.redhat.com/errata/RHSA-2026:35827Canonical URLhttps://access.redhat.com/errata/RHSA-2026:35828Canonical URLhttps://access.redhat.com/errata/RHSA-2026:34364https://access.redhat.com/security/cve/CVE-2026-32285https://access.redhat.com/security/cve/CVE-2026-33813Canonical URLhttps://access.redhat.com/errata/RHSA-2026:42852https://access.redhat.com/security/cve/CVE-2026-33376https://access.redhat.com/security/cve/CVE-2026-33377Canonical URLhttps://access.redhat.com/errata/RHSA-2026:370722480680248068124806842480685248068824807572493620Canonical URLhttps://access.redhat.com/errata/RHSA-2026:44622https://access.redhat.com/security/cve/CVE-2026-55677Canonical URLhttps://access.redhat.com/errata/RHSA-2026:37123Canonical URLhttps://access.redhat.com/errata/RHSA-2026:50843Canonical URLhttps://access.redhat.com/errata/RHSA-2026:50894https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4/html-single/release_notes/indexCanonical URLhttps://access.redhat.com/errata/RHSA-2026:51084Canonical URLhttps://access.redhat.com/errata/RHSA-2026:51341https://access.redhat.com/documentation/en-us/red_hat_satellite/6.18/html/updating_red_hat_satellite/indexhttps://access.redhat.com/security/cve/CVE-2026-42502https://catalog.redhat.com/software/containers/searchhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.18/html/installing_satellite_server_in_a_connected_network_environment/performing-additional-configuration-on-server_satellite#installing-and-configuring-red-hat-lightspeed-in-satellitehttps://docs.redhat.com/en/documentation/red_hat_satellite/6.18/html/installing_satellite_server_in_a_disconnected_network_environment/performing-additional-configuration#installing-and-configuring-red-hat-lightspeed-in-satelliteCanonical URLhttps://access.redhat.com/errata/RHSA-2026:51112Canonical URLhttps://access.redhat.com/errata/RHSA-2026:534152466671Canonical URLhttps://access.redhat.com/errata/RHSA-2026:53412Canonical URLhttps://access.redhat.com/errata/RHSA-2026:54283https://access.redhat.com/security/cve/CVE-2026-33814Canonical URLhttps://access.redhat.com/errata/RHSA-2026:52910https://access.redhat.com/security/cve/CVE-2026-39828https://access.redhat.com/security/cve/CVE-2026-39829https://access.redhat.com/security/cve/CVE-2026-39830https://access.redhat.com/security/cve/CVE-2026-39831https://access.redhat.com/security/cve/CVE-2026-39832https://access.redhat.com/security/cve/CVE-2026-39835https://access.redhat.com/security/cve/CVE-2026-42508https://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.20/Canonical URLReference 100Reference 101https://access.redhat.com/errata/RHSA-2026:53413Canonical URLhttps://access.redhat.com/errata/RHSA-2026:54284Canonical URLhttps://access.redhat.com/errata/RHSA-2026:54285Canonical URLhttps://access.redhat.com/errata/RHSA-2026:54441Canonical URLhttps://access.redhat.com/errata/RHSA-2026:54274https://access.redhat.com/security/cve/CVE-2026-39883Canonical URLhttps://access.redhat.com/errata/RHSA-2026:54286Canonical URLhttps://access.redhat.com/errata/RHSA-2026:54287Canonical URLhttps://access.redhat.com/errata/RHSA-2026:54583https://access.redhat.com/security/cve/CVE-2026-42965https://access.redhat.com/security/cve/CVE-2026-44918https://access.redhat.com/security/cve/CVE-2026-50236https://access.redhat.com/security/cve/CVE-2026-50237Canonical URLhttps://access.redhat.com/errata/RHSA-2026:54527https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.htmlCanonical URLhttps://access.redhat.com/errata/RHSA-2026:54531https://access.redhat.com/security/cve/CVE-2026-46595https://access.redhat.com/security/cve/CVE-2026-46597Canonical URLhttps://access.redhat.com/errata/RHSA-2026:56340https://access.redhat.com/security/cve/CVE-2026-56852Canonical URLhttps://access.redhat.com/errata/RHSA-2026:59467https://access.redhat.com/security/cve/CVE-2026-42306https://access.redhat.com/security/cve/CVE-2026-44740https://access.redhat.com/security/cve/CVE-2026-71235https://access.redhat.com/errata/RHSA-2026:595602480762Canonical URLhttps://access.redhat.com/errata/RHSA-2026:59562Canonical URLReference 142https://access.redhat.com/errata/RHSA-2026:615852493622Canonical URLhttps://access.redhat.com/errata/RHSA-2026:63134Canonical URLhttps://access.redhat.com/errata/RHSA-2026:664322484830Canonical URLhttps://access.redhat.com/errata/RHSA-2026:67139Canonical URLhttps://access.redhat.com/errata/RHSA-2026:6833424563352467809246782024806752480678248389424842042488484250423325107192512562251581525158202515827https://access.redhat.com/errata/RHSA-2026:69293Canonical URLhttps://access.redhat.com/errata/RHSA-2026:68541https://access.redhat.com/security/cve/CVE-2026-55204Canonical URLhttps://access.redhat.com/errata/RHSA-2026:72853https://access.redhat.com/security/cve/CVE-2026-33818https://access.redhat.com/security/cve/CVE-2026-41178https://access.redhat.com/security/cve/CVE-2026-46600https://access.redhat.com/security/cve/CVE-2026-56858https://access.redhat.com/security/cve/CVE-2026-56859https://access.redhat.com/security/cve/CVE-2026-56860https://access.redhat.com/security/cve/CVE-2026-56862https://access.redhat.com/security/cve/CVE-2026-73500https://access.redhat.com/security/cve/CVE-2026-84445Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses