RHSA-2026:40768HighCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 4.22.6 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-40895 — follow-redirects: follow-redirects: Information disclosure via cross-domain redirects
CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API
CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows
CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits
CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability
CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:40768
- externalhttps://access.redhat.com/security/cve/CVE-2026-40895
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/cve/CVE-2026-44487
- externalhttps://access.redhat.com/security/cve/CVE-2026-44488
- externalhttps://access.redhat.com/security/cve/CVE-2026-44495
- externalhttps://access.redhat.com/security/cve/CVE-2026-45736
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_40768.json