Skip to main content
EPSS 2.8%top 15%

Red Hat Security Advisory: OpenShift Container Platform 4.17.57 bug fix and security update

0
High
Published: 09/03/2026 (09/03/2026, 07:53:39 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.17.57. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:60018 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/

Affected software

Affected versions
>=2.5.0 <=2.6.*=8.6.1>=4.20.0 <=4.20.10>=4.16.0 <=4.16.66Red HatRed Hat Ansible Automation PlatformRed Hat Ansible Automation Platform 2.5 for RHEL 9Red Hat OpenShift Container PlatformRed Hat OpenShift Container Platform 4.19amd64registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:0f1f30c7e4566d7c2fe5b60ec0c423c30452612f79419a80d90de3753d261535_amd64Red Hat OpenShift Container Platform 4.16arm64registry.redhat.io/openshift4/ose-pod-rhel9@sha256:9703af662852b4173a705afc3bdf52bd8da8843abb5b87c1d1ead65aaad4a13b_arm64Red Hat Enterprise LinuxRed Hat Enterprise Linux High Availability E4S (v.9.0)Red Hat Enterprise Linux ResilientStorage E4S (v.9.0)srcRed Hat JBoss Data GridRed Hat Data Grid 8.6.1Red Hat OpenShift GitOpsRed Hat OpenShift GitOps 1.18registry.redhat.io/openshift-gitops-1/argo-rollouts-rhel8@sha256:a4e3a3345862f1dbefe620bce99794e01fca58e650f3291ec4519a953398e726_amd64Red Hat OpenShift Container Platform 4.22registry.redhat.io/openshift4/ose-machine-api-provider-azure-rhel9@sha256:c3784468ebdf935dae7d9829f3ca939da75b58903c089a5b0c4ce49d066b37e7_arm64Red Hat OpenShift Container Platform 4.13registry.redhat.io/openshift4/ose-cluster-autoscaler@sha256:af81be33796b3cf9d074b10171c908846091a8073e02beb68a36c8453f367b87_amd64Red Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:b63c025b4bbfb73fdbae3c740745851ec819de710911534c516d3d9a9587637b_amd64Red Hat Openshift Data FoundationRed Hat Openshift Data Foundation 4.2registry.redhat.io/odf4/cephcsi-rhel9@sha256:dfdf81ab0ca1b4c8155b8b37db728aa37c3b708e8621995da9cbd576086954c3_amd64registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:5875ce179ab7eb09e92a3355536ba83e534712d7362c2289ff13b9fe0be0d1bf_amd64Red Hat OpenShift Container Platform 4.20registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:cde57abb7a287e9abec2b61fb0bc76931c0018ef655d7ba1b43411f6865406cf_amd64registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:6ae1dc902850b538b3c352530e1006d739479e65e06304e0e5b3d702110a70a2_amd64Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:4ae0174eec7cff35f2ae0926d28975ad4d2f303c4c3259fc5e2b9deea91699ad_amd64Red Hat Ansible Automation Platform 2.6 for RHEL 9Red Hat OpenShift Container Platform 4.17registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:7644b30ed4732df915c526f148de469c71e28ef1ad4f593cad4779d6e8eefc71_amd64Red Hat OpenShift Container Platform 4.2ppc64leregistry.redhat.io/openshift4/ose-pod-rhel9@sha256:ce699b66506a1c96f29ec17d0505438345365d05db5e97d15fcaee11e61ba9c7_ppc64leMETTLER TOLEDOSoftwareLabX Standardvers:intdot/>=21.3.22|<21.4.25LabX Standard versions 21.3.22 - 21.4.23

Weaknesses

CWE-94CWE-444CWE-770CWE-93CWE-168CWE-241CWE-338CWE-79CWE-915CWE-918CWE-776CWE-551CWE-131CWE-201CWE-212CWE-824CWE-140CWE-78CWE-1050CWE-347CWE-22CWE-88CWE-290CWE-1341CWE-1289CWE-409CWE-289CWE-1333CWE-835CWE-367CWE-764CWE-606CWE-1220CWE-295CWE-346CWE-306CWE-1286CWE-436CWE-1046CWE-681CWE-285CWE-908CWE-787CWE-416CWE-354CWE-191CWE-617CWE-59CWE-407CWE-425CWE-476CWE-319CWE-350CWE-294CWE-126CWE-125CWE-130CWE-475CWE-121CWE-190CWE-674CWE-77CWE-20CWE-122CWE-120CWE-325CWE-400CWE-601CWE-362CWE-415CWE-61

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 23:37:08 UTC

Technical Analysis

This Red Hat security advisory covers multiple vulnerabilities fixed in Red Hat OpenShift Container Platform 4.22.3 and related products including Red Hat Data Grid 8.6.1 and OpenShift Data Foundation 4.20.10. The critical CVE-2026-4800 vulnerability in lodash allows arbitrary code execution via untrusted input in template imports. Other addressed vulnerabilities include denial of service via HTTP/2 CONTINUATION frame flood (CVE-2026-33871), request smuggling in Netty (CVE-2026-33870), cross-site scripting in DOMPurify (CVE-2026-41240), authentication bypass and prototype pollution in Axios (multiple CVEs), weak pseudo-random number generation in Spring Boot (CVE-2026-40975), and several Apache Log4j issues causing denial of service and log injection. The advisory provides updated container images and RPM packages to remediate these issues. The vendor has released official fixes for these vulnerabilities.

Potential Impact

The vulnerabilities fixed in this advisory can lead to arbitrary code execution, denial of service, authentication bypass, cross-site scripting, request smuggling, and information disclosure in affected Red Hat products. Exploitation of CVE-2026-4800 could allow attackers to execute arbitrary code via untrusted input in lodash templates. Other vulnerabilities may allow denial of service attacks, bypass of authentication mechanisms, or injection attacks that compromise system integrity and confidentiality. The severity is rated critical for some issues, indicating a high risk to affected systems if unpatched.

Mitigation Recommendations

Red Hat has released official fixes for these vulnerabilities in updated container images and RPM packages for Red Hat OpenShift Container Platform 4.22.3, Red Hat Data Grid 8.6.1, and OpenShift Data Foundation 4.20.10. Users should apply these updates promptly. Before applying the updates, ensure all previously released errata relevant to your system have been applied. Follow Red Hat's official guidance for applying these updates as documented in their advisories and release notes. No additional mitigations are indicated beyond applying the official patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:11454
Cve Count
2
Additional Cves
["CVE-2026-31958"]

Threat ID: 6a160974e29bf47b5063e36f

Added to database: 05/26/2026, 20:58:28 UTC

Last enriched: 08/14/2026, 23:37:08 UTC

Last updated: 09/14/2026, 22:01:35 UTC

Views: 108

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:22619https://access.redhat.com/security/updates/classification/#importanthttps://docs.redhat.com/en/documentation/red_hat_data_grid/8.6245245324524562453496245732124573232457328246114724616072461626246162924616302463331Canonical URLhttps://access.redhat.com/errata/RHSA-2026:12277https://access.redhat.com/security/cve/CVE-2026-27942https://access.redhat.com/security/cve/CVE-2026-33036https://access.redhat.com/security/cve/CVE-2026-33186https://access.redhat.com/security/cve/CVE-2026-34986https://access.redhat.com/security/cve/CVE-2026-4800https://access.redhat.com/security/updates/classification/https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:40795https://access.redhat.com/security/cve/CVE-2026-44487https://access.redhat.com/security/cve/CVE-2026-44488https://access.redhat.com/security/cve/CVE-2026-44494https://access.redhat.com/security/cve/CVE-2026-44495Canonical URLhttps://access.redhat.com/errata/RHSA-2026:44235https://access.redhat.com/security/cve/CVE-2026-40895https://access.redhat.com/security/cve/CVE-2026-42154https://access.redhat.com/security/cve/CVE-2026-45736Canonical URLhttps://access.redhat.com/errata/RHSA-2026:29795https://access.redhat.com/security/cve/CVE-2026-35469https://access.redhat.com/security/cve/CVE-2026-44293https://access.redhat.com/security/cve/CVE-2026-6322https://access.redhat.com/security/cve/CVE-2026-9277Canonical URLhttps://access.redhat.com/errata/RHSA-2026:20946https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/cve/CVE-2026-33487https://docs.redhat.com/en/documentation/red_hat_openshift_gitops/1.18/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:42078https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/release_notes/patch_releaseshttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading245633324609272461624246658224666842467822247715424807562480757248076124853792487937248793824879422487943https://access.redhat.com/errata/RHSA-2026:24762https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updateshttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6#Upgrade24485532451867245245024561792456336245633824563392456735245743224588562464121Canonical URLhttps://access.redhat.com/errata/RHSA-2026:36621https://access.redhat.com/security/cve/CVE-2026-12151https://access.redhat.com/security/cve/CVE-2026-26996https://access.redhat.com/security/cve/CVE-2026-29063https://access.redhat.com/security/cve/CVE-2026-9697Canonical URLhttps://access.redhat.com/errata/RHSA-2026:114542446765Canonical URLhttps://access.redhat.com/errata/RHSA-2026:37186https://access.redhat.com/security/cve/CVE-2026-13676https://access.redhat.com/security/cve/CVE-2026-9595Canonical URLhttps://access.redhat.com/errata/RHSA-2026:48699https://access.redhat.com/security/cve/CVE-2026-16242Canonical URLhttps://access.redhat.com/errata/RHSA-2026:54188https://access.redhat.com/security/cve/CVE-2026-44486https://access.redhat.com/security/cve/CVE-2026-44492https://access.redhat.com/security/cve/CVE-2026-49332https://access.redhat.com/security/cve/CVE-2026-50237Canonical URLhttps://access.redhat.com/errata/RHSA-2026:60023https://access.redhat.com/security/cve/CVE-2026-25681https://access.redhat.com/security/cve/CVE-2026-33814https://access.redhat.com/security/cve/CVE-2026-39820https://access.redhat.com/security/cve/CVE-2026-42499https://access.redhat.com/security/cve/CVE-2026-42504https://access.redhat.com/security/cve/CVE-2026-46597https://access.redhat.com/security/cve/CVE-2026-50236Canonical URLProduct security website of METTLER TOLEDOCERT@VDE Security Advisories for METTLER TOLEDOVDE-2026-088: METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4 - HTMLVDE-2026-088: METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4 - CSAFSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses