Skip to main content
EPSS 0.2%top 93%

Red Hat Security Advisory: OpenShift Container Platform 4.17.58 packages and security update

0
High
Published: 10/01/2026 (10/01/2026, 13:08:20 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Container Platform versions including 4.12.98, 4.14, 4.15, 4.16 through 4.17, 4.18 through 4.19, 4.19 through 4.20, 4.20 through 4.21, 4.21 through 4.22, and up to 4.22.11 contain multiple security vulnerabilities. These include a bypass vulnerability in cri-o allowing /etc/passwd injection via the HOME environment variable (CVE-2026-15809), several denial of service issues in Go language packages, a privilege escalation via incorrect Punycode processing, and cross-site scripting in Go's html/template package. Red Hat has released updated RPM packages and container images to address these issues. Users are advised to upgrade to the fixed versions using the OpenShift CLI or web console.

Affected software

Affected versions
>=4.19 <4.20>=4.20 <4.21>=4.21 <4.22>=4.22 <4.22.11>=4.16 <4.17>=4.18 <4.19=4.12.98=4.14=4.15=4.21

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/09/2026, 23:01:04 UTC

Technical Analysis

This advisory covers multiple security fixes in Red Hat OpenShift Container Platform 4.17.58 and later releases, addressing vulnerabilities such as CVE-2026-15809, a bypass in cri-o allowing /etc/passwd injection via the HOME environment variable. Other fixed issues include denial of service vulnerabilities in Go encoding/asn1, JSON Web Encryption processing, XML decoding, URL path resolution, and TLS KeyUpdate handling. Additionally, a privilege escalation vulnerability due to incorrect Punycode label processing and a cross-site scripting vulnerability in Go's html/template package are addressed. The vendor advisory confirms these fixes are included in updated RPM packages and container images, with instructions for upgrading clusters provided by Red Hat.

Potential Impact

The vulnerabilities fixed in these OpenShift Container Platform releases include potential bypass of security controls allowing injection into /etc/passwd, denial of service conditions caused by crafted inputs leading to excessive recursion or resource exhaustion, privilege escalation through improper Punycode handling, and cross-site scripting via malformed input. These issues could impact the confidentiality, integrity, and availability of affected OpenShift deployments if exploited. However, there are no known exploits in the wild at this time.

Mitigation Recommendations

Red Hat has released updated RPM packages and container images for OpenShift Container Platform versions including 4.22.11 and earlier affected versions. Users should upgrade their OpenShift clusters to these updated versions using the OpenShift CLI (oc) or web console as soon as the updates are available in their release channels. Detailed upgrade instructions are available in the Red Hat documentation. Patch status is confirmed by the vendor advisory, and applying these updates fully mitigates the described vulnerabilities.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:57361
Cve Count
3
Additional Cves
["CVE-2026-39822","CVE-2026-42504"]
State
PUBLISHED

Threat ID: 6a8d9ad7acd9273b493e1478

Added to database: 08/25/2026, 13:38:31 UTC

Last enriched: 10/09/2026, 23:01:04 UTC

Last updated: 10/09/2026, 23:01:04 UTC

Views: 85

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses