Skip to main content
EPSS 0.5%top 62%

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18.20 security, enhancement & bug fix update

0
High
Published: 05/14/2026 (05/14/2026, 11:46:25 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Data Foundation 4.18.20 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-6235: [4.18] [ROSA HCP][UI blocker] Broken Storage System wizard DFBUGS-6185: ocs-operator should not use image gcr.io/kubebuilder/kube-rbac-proxy DFBUGS-6172: RHODF 4.18.20 DFBUGS-5939: Backport to odf-4.18.z [External Mode]: noobaa-default-backing-store is in creating state due to "CheckExternalConnection Status=UNKNOWN_FAILURE Error=SELF_SIGNED_CERT_IN_CHAIN"

Affected software

Affected versions
>=6.16 <6.17>=4.18 <4.19Red HatRed Hat Openshift Data FoundationRed Hat Openshift Data Foundation 4.18amd64registry.redhat.io/odf4/cephcsi-rhel9@sha256:4fa3d35d6a129ff865be3cb7d0ed8a8a1d7171e447d3c7a24eb80321ebfb5c09_amd64Red Hat Satellite 6Red Hat Satellite 6.16 for RHEL 8Red Hat Web TerminalRed Hat Web Terminal 1.12registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:423baadb7daeaf78b5df584e7e5e8f2ad991e0db803a22ec7a90f7d468e55415_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 19:15:21 UTC

Technical Analysis

This Red Hat security advisory addresses several vulnerabilities in Red Hat OpenShift Data Foundation 4.18.20 and related components, notably CVE-2025-61729, a denial of service vulnerability in Go's crypto/x509 package caused by excessive resource consumption from crafted certificates. Additional fixes include denial of service issues in TLS 1.3 key update handling, authorization bypass in gRPC-Go due to improper HTTP/2 path validation, and incorrect parsing of IPv6 host literals. The advisory also includes bug fixes for UI blockers and image usage in the ocs-operator. The update is classified as important and fixes multiple CVEs affecting Red Hat Satellite and OpenShift Data Foundation products.

Potential Impact

The primary impact is denial of service caused by crafted certificates leading to excessive resource consumption in Go's crypto/x509 package, potentially affecting services relying on certificate validation. Other vulnerabilities fixed include authorization bypass and denial of service in TLS and gRPC components. These issues could disrupt availability or allow unauthorized access if exploited. No known exploits in the wild have been reported at the time of this advisory.

Mitigation Recommendations

An official security update is available for Red Hat OpenShift Data Foundation 4.18.20 and related Red Hat Satellite components that addresses these vulnerabilities. Users should apply this update after ensuring all previously released errata relevant to their systems are installed. Detailed update instructions are provided in the Red Hat documentation. No additional mitigation steps are indicated beyond applying the official patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:17547
Cve Count
4
Additional Cves
["CVE-2026-4800","CVE-2026-33036","CVE-2026-34986"]
State
PUBLISHED

Threat ID: 6a16095be29bf47b50624919

Added to database: 05/26/2026, 20:58:03 UTC

Last enriched: 08/14/2026, 19:15:21 UTC

Last updated: 09/13/2026, 10:01:28 UTC

Views: 104

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:27076https://access.redhat.com/security/updates/classification/#important24184622445356244983324563332456336245633824563392458856SAT-44720SAT-45906Canonical URLhttps://access.redhat.com/errata/RHSA-2026:17547https://access.redhat.com/security/cve/CVE-2025-61729https://access.redhat.com/security/cve/CVE-2026-33036https://access.redhat.com/security/cve/CVE-2026-34986https://access.redhat.com/security/cve/CVE-2026-4800https://access.redhat.com/security/updates/classification/https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1038https://access.redhat.com/security/cve/CVE-2025-66471https://access.redhat.com/security/cve/CVE-2026-21441https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.htmlCanonical URLhttps://access.redhat.com/errata/RHSA-2026:42047https://access.redhat.com/security/cve/CVE-2026-27145https://access.redhat.com/security/cve/CVE-2026-32280https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/cve/CVE-2026-32282https://access.redhat.com/security/cve/CVE-2026-33810https://access.redhat.com/security/cve/CVE-2026-33811https://access.redhat.com/security/cve/CVE-2026-39821https://access.redhat.com/security/cve/CVE-2026-42504https://redhat.atlassian.net/browse/WTO-359https://redhat.atlassian.net/browse/WTO-402https://redhat.atlassian.net/browse/WTO-407https://redhat.atlassian.net/browse/WTO-413https://redhat.atlassian.net/browse/WTO-418https://redhat.atlassian.net/browse/WTO-429https://redhat.atlassian.net/browse/WTO-433https://redhat.atlassian.net/browse/WTO-448https://redhat.atlassian.net/browse/WTO-450https://access.redhat.com/errata/RHSA-2026:1166Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses