Skip to main content
EPSS 1.6%top 26%

Red Hat Security Advisory: OpenShift Container Platform 4.18.38 security and extras update

0
High
Published: 04/22/2026 (04/22/2026, 07:19:21 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.18.38. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:8448 Security Fix(es): * google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli.

Affected software

google.golang.org/grpc
pkg:golang/google.golang.org/grpc
Affected versions
<1.56.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 17:24:21 UTC

Technical Analysis

CVE-2026-33186 is an authorization bypass vulnerability in the gRPC-Go library caused by improper input validation of the HTTP/2 :path pseudo-header. Specifically, the vulnerability arises when the :path header omits the mandatory leading slash, allowing remote attackers to bypass defined authorization policies. This affects Red Hat OpenShift Container Platform versions prior to the fixed releases. Red Hat has issued security advisories and updated RPM packages and container images to remediate this issue. The vulnerability has a high severity rating with a CVSS v3 base score of 9.1 as rated by Red Hat, indicating high confidentiality and integrity impact but no availability impact. Mitigation includes upgrading to the patched versions or implementing infrastructure-level normalization of HTTP/2 :path headers.

Potential Impact

The vulnerability allows remote attackers to bypass authorization controls in gRPC-Go by exploiting improper HTTP/2 :path header validation. This can lead to unauthorized access to services or information disclosure within Red Hat OpenShift Container Platform deployments. The CVSS v3 base score assigned by Red Hat is 9.1 (high severity), reflecting high confidentiality and integrity impact with no impact on availability. There are no known exploits in the wild at this time.

Mitigation Recommendations

A fix is available and users should upgrade to the updated Red Hat OpenShift Container Platform packages and container images as provided in the Red Hat advisories (e.g., versions 4.19.29 and later). Additionally, infrastructure-level mitigation can be applied by configuring reverse proxies or API gateways to normalize and validate the HTTP/2 :path header, ensuring it includes the mandatory leading slash before requests reach the gRPC-Go server. Proper configuration and restarting of intermediaries is required to apply this mitigation. No contradictory vendor guidance exists; applying the official fix is recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:8449
Cve Count
1
State
PUBLISHED

Threat ID: 6a160954e29bf47b50619505

Added to database: 05/26/2026, 20:57:56 UTC

Last enriched: 08/17/2026, 17:24:21 UTC

Last updated: 09/14/2026, 03:23:23 UTC

Views: 124

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:21710https://access.redhat.com/security/cve/CVE-2026-33186https://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:44233Canonical URLhttps://access.redhat.com/errata/RHSA-2026:7245Canonical URLhttps://access.redhat.com/errata/RHSA-2026:10094Canonical URLhttps://access.redhat.com/errata/RHSA-2026:10105Canonical URLhttps://access.redhat.com/errata/RHSA-2026:10107https://access.redhat.com/security/updates/classification/#important2449833Canonical URLhttps://access.redhat.com/errata/RHSA-2026:10705Canonical URLhttps://access.redhat.com/errata/RHSA-2026:8449Canonical URLhttps://access.redhat.com/errata/RHSA-2026:10706Canonical URLhttps://access.redhat.com/errata/RHSA-2026:12119Canonical URLhttps://access.redhat.com/errata/RHSA-2026:18068OCPBUGS-76625OCPBUGS-78040Canonical URLhttps://access.redhat.com/errata/RHSA-2026:43225Canonical URLhttps://access.redhat.com/errata/RHSA-2026:12283Canonical URLhttps://access.redhat.com/errata/RHSA-2026:27893Canonical URLhttps://access.redhat.com/errata/RHSA-2026:27901Canonical URLhttps://access.redhat.com/errata/RHSA-2026:14775Canonical URLhttps://access.redhat.com/errata/RHSA-2026:15092Canonical URLhttps://access.redhat.com/errata/RHSA-2026:20035Canonical URLhttps://access.redhat.com/errata/RHSA-2026:20322Canonical URLhttps://access.redhat.com/errata/RHSA-2026:20436Canonical URLhttps://access.redhat.com/errata/RHSA-2026:22645Canonical URLhttps://access.redhat.com/errata/RHSA-2026:17459https://access.redhat.com/security/cve/CVE-2026-34986Canonical URLhttps://access.redhat.com/errata/RHSA-2026:22800Canonical URLhttps://access.redhat.com/errata/RHSA-2026:23247Canonical URLhttps://access.redhat.com/errata/RHSA-2026:24506Canonical URLhttps://access.redhat.com/errata/RHSA-2026:24535Canonical URLhttps://access.redhat.com/errata/RHSA-2026:24759Canonical URLhttps://access.redhat.com/errata/RHSA-2026:25183Canonical URLhttps://access.redhat.com/errata/RHSA-2026:25195Canonical URLhttps://access.redhat.com/errata/RHSA-2026:26412https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:53773Canonical URLhttps://access.redhat.com/errata/RHSA-2026:53804Canonical URLhttps://access.redhat.com/errata/RHSA-2026:26997Canonical URLhttps://access.redhat.com/errata/RHSA-2026:26999Canonical URLhttps://access.redhat.com/errata/RHSA-2026:25187https://access.redhat.com/security/cve/CVE-2026-35469Canonical URLhttps://access.redhat.com/errata/RHSA-2026:27892Canonical URLhttps://access.redhat.com/errata/RHSA-2026:27712Canonical URLhttps://access.redhat.com/errata/RHSA-2026:27957Canonical URLhttps://access.redhat.com/errata/RHSA-2026:29079Canonical URLhttps://access.redhat.com/errata/RHSA-2026:34795Canonical URLhttps://access.redhat.com/errata/RHSA-2026:56959Canonical URLhttps://access.redhat.com/errata/RHSA-2026:60146Canonical URLhttps://access.redhat.com/errata/RHSA-2026:278562455470Canonical URLhttps://access.redhat.com/errata/RHSA-2026:37580https://access.redhat.com/security/cve/CVE-2026-46579Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses