Back to index
Download the installer for your operating system or run
oc adm release extract --tools quay.io/openshift-release-dev/ocp-release:4.13.72-x86_64 Qualifiers (status api ):
Tests:
Blocking jobsupgrade Succeeded periodic-ci-openshift-release-main-stable-4.y-e2e-aws-ovn-upgradeupgrade-minor Succeeded (1 retry) periodic-ci-openshift-release-main-stable-4.y-e2e-aws-ovn-upgrade Informing jobsaws-sdn-serial Succeeded periodic-ci-openshift-release-main-nightly-4.13-e2e-aws-sdn-serialaws-sdn-upgrade-4.13-micro Succeeded periodic-ci-openshift-release-main-nightly-4.13-e2e-aws-sdn-upgradeazure-ovn-upgrade-4.13-micro Succeeded (1 retry) periodic-ci-openshift-release-main-ci-4.13-e2e-azure-ovn-upgradedriver-toolkit Succeeded (1 retry) periodic-ci-openshift-release-main-nightly-4.13-e2e-aws-driver-toolkitfips-scan Succeeded periodic-ci-openshift-release-main-nightly-4.13-fips-payload-scanmetal-ipi-ovn-ipv6 Succeeded periodic-ci-openshift-release-main-nightly-4.13-e2e-metal-ipi-ovn-ipv6metal-ipi-sdn-ipv4 Succeeded periodic-ci-openshift-release-main-nightly-4.13-e2e-metal-ipi-sdn-ipv4 Upgrades from:
Untested upgrades:
4.12.19 ,
4.12.20 ,
4.12.21 ,
4.12.22 ,
4.12.23 ,
4.12.25 ,
4.12.26 ,
4.12.27 ,
4.12.28 ,
4.12.29 ,
4.12.30 ,
4.12.31 ,
4.12.32 ,
4.12.33 ,
4.12.34 ,
4.12.35 ,
4.12.36 ,
4.12.37 ,
4.12.38 ,
4.12.39 ,
4.12.40 ,
4.12.41 ,
4.12.42 ,
4.12.43 ,
4.12.44 ,
4.12.45 ,
4.12.46 ,
4.12.47 ,
4.12.48 ,
4.12.49 ,
4.12.50 ,
4.12.51 ,
4.12.52 ,
4.12.54 ,
4.12.55 ,
4.12.56 ,
4.12.57 ,
4.12.58 ,
4.12.59 ,
4.12.60 ,
4.12.61 ,
4.12.62 ,
4.12.64 ,
4.12.65 ,
4.12.66 ,
4.12.67 ,
4.12.68 ,
4.12.69 ,
4.12.70 ,
4.12.71 ,
4.12.72 ,
4.12.73 ,
4.12.74 ,
4.12.75 ,
4.12.76 ,
4.12.77 ,
4.12.78 ,
4.12.79 ,
4.12.80 ,
4.12.81 ,
4.12.82 ,
4.12.83 ,
4.12.84 ,
4.12.85 ,
4.12.86 ,
4.12.87 ,
4.12.88 ,
4.12.89 ,
4.12.90 ,
4.12.91 ,
4.12.92 ,
4.12.93 ,
4.12.94 ,
4.12.95 ,
4.12.96 ,
4.12.97 ,
4.13.10 ,
4.13.11 ,
4.13.12 ,
4.13.13 ,
4.13.14 ,
4.13.15 ,
4.13.16 ,
4.13.17 ,
4.13.18 ,
4.13.21 ,
4.13.22 ,
4.13.23 ,
4.13.24 ,
4.13.25 ,
4.13.26 ,
4.13.27 ,
4.13.28 ,
4.13.3 ,
4.13.30 ,
4.13.31 ,
4.13.32 ,
4.13.33 ,
4.13.34 ,
4.13.35 ,
4.13.36 ,
4.13.37 ,
4.13.38 ,
4.13.39 ,
4.13.4 ,
4.13.40 ,
4.13.41 ,
4.13.42 ,
4.13.43 ,
4.13.44 ,
4.13.45 ,
4.13.46 ,
4.13.47 ,
4.13.48 ,
4.13.49 ,
4.13.5 ,
4.13.51 ,
4.13.52 ,
4.13.53 ,
4.13.54 ,
4.13.55 ,
4.13.56 ,
4.13.57 ,
4.13.58 ,
4.13.59 ,
4.13.6 ,
4.13.60 ,
4.13.61 ,
4.13.62 ,
4.13.63 ,
4.13.64 ,
4.13.65 ,
4.13.66 ,
4.13.67 ,
4.13.68 ,
4.13.7 ,
4.13.8 ,
4.13.9 Upgrades to:
Loading changelog, this may take a while ...
Created: 2026-10-07 10:52:00 +0000 UTC
Image Digest: sha256:c889dfb978becf40cea36fa5517cd6540944d49cba22aa4783aa1083b93e2470
Components
Rebuilt images without code change
NO-JIRA: Allow sustaining engineering to self serve dependency updates #563
Full changelog
E2E: workload hints: compare existing profile with changes being made to avoid mcp getting stuck (#1069) #1069
OCPBUGS-33030 : [release-4.13][manual]Reduce number of reboots in offline tests (#1048) #1048
Scheduler plugin: ignore IRQs (#1027) #1027
irqbalance: set banned cpus list to 0 (#1003) #1003
OCPBUGS-24353 : rps: cherry-picks of rps fixes (#865) #865
Full changelog
NO-ISSUE: Updating ose-cluster-update-keys-container image to be consistent with ART for 4.13 #78
OCPBUGS-43886 : keys: Update Red Hat keys to use SHA256 signatures #67
Full changelog
OCPBUGS-77115 : [release-4.13] CVE-2026-26996 Bump minimatch library #16488
OCPBUGS-98418 : CVE-2026-59869 #16755
OCPBUGS-92691 : CVE-2026-46597 openshift4/ose-console: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [openshift-4.13.z] #16977
Fix for OCPBUGS-92068: CVE-2026-44990 #16722
OCPBUGS-100521 , OCPBUGS-101797 : Bump postcss to fix CVE-2026-45623, CVE-2026-69153 #17112
OCPBUGS-112511 : Fix JSON annotation parsing to prevent OperatorHub crash #17069
OCPBUGS-87988 : [release-4.13] shell-quote: Arbitrary code execution via command injection due to unescaped line terminators #16596
Fix for OCPBUGS-81594: CVE-2026-4800 #16569
OCPBUGS-88410 , OCPBUGS-88442 : CVE-2026-44486 openshift4/ose-console: Axios: Information disclosure of proxy credentials via HTTP redirects #16779
OCPBUGS-88375 , OCPBUGS-88384 , OCPBUGS-88391 , OCPBUGS-88404 , OCPBUGS-88410 , OCPBUGS-88414 , OCPBUGS-88442 : CVE-2026-44495 #16622
OCPBUGS-79432 : CVE-2026-29063 Bump immutable #16330
ART-18919 : pin fsevents to latest #16481
NO-JIRA: enable multi-architecture yarn builds #16423
CONSOLE-5011 : migrate to yarn berry #16083
NO-JIRA: Bump builder image to v29 #15989
OCPBUGS-74437 : Bump lodash to latest #15972
OCPBUGS-44160 : bump dompurify to latest #15594
OCPBUGS-57100 : Add all files to vendor regardless of gitignore #15136
OCPBUGS-54892 : Show Observe section without PROMETHEUS and MONITORING flags #14960
OCPBUGS-45292 : A value submitted in From view is wrapped with single quotation after switching to Yaml view. #14573
OCPBUGS-44356 : Application creation fail when manually entering input scaling value in local setup #14509
OCPBUGS-45197 : Edit the secret and add the Chinese in the web-console, garbled characters will be displayed #14552
OCPBUGS-44585 : Need to allow blank for Project/namespace when setting SA Subject in ‘Project access tab’ #14497
OCPBUGS-36557 : Increase login flow state paramater length/entropy #14483
OCPBUGS-42951 : The filepath including leading slash makes error during parsing devfile using Gitlab #14383
OCPBUGS-41594 : Redirects to new PipelineRun logs URL from old PipelineRun logs URL #14263
OCPBUGS-35259 : fix vCenter cluster being empty #13952
OCPBUGS-32147 : Bump graphql-go to v1.3.0 #13922
OCPBUGS-33978 : Helm Plugin’s Catalog incorrectly renders a single index entry into multiple tiles #13872
OCPBUGS-34342 : Fix PipelineRun Logs tab navigation #13890
OCPBUGS-24395 : Extra space is in the translation text(Chinese) of ‘Create rolebinding’ and ‘replicate rolebinding’ #13405
OCPBUGS-33777 : restrict Masthead logo to max-height to 60px #13860
OCPBUGS-33749 : Add visual connector between VMs and non VMs workloads #13857
OCPBUGS-33382 : Routes created by devfiles do not always use HTTPS #13827
OCPBUGS-33650 : fix issues with Edit Route form #13851
OCPBUGS-32500 : PipelineRuns in Console show wrong status or load indefinitely #13780
OCPBUGS-31077 : Pipeline Name gets changed to “new-pipeline” on the Edit Pipeline YAML/Builder #13683
OCPBUGS-31595 : Fix operands list endpoint. #13714
OCPBUGS-29063 : add additional check to determine if file is binary #13579
OCPBUGS-28788 : Copy response code from proxied plugin requests #13561
OCPBUGS-29243 : Add a new allowInsecure option to the internet proxy #13593
OCPBUGS-27406 : Add Pipeline metrics tab using plugin #13525
Full changelog
OCPBUGS-84928 : Replace google.golang.org/grpc with github.com/openshift-sustaining/grpc-go v1.64.1-sec.1 to avoid go version bump and fix CVE-2026-33186 #185
Full changelog
OCPBUGS-83661 : Bump google.golang.org/grpc to v1.79.3 #109
“OCPBUGS-29791: [release-4.13] Address CVE-2024-1725: Restrict access to infrastructure PVCs by requiring matching infraClusterLabels on tenant PVCs” #35
Full changelog
OCPBUGS-59699 : Bump github.com/golang/glog to v1.2.4 (#117) #117
[release 4.13] OCPBUGS-60541: Replace e2e test image (#132) #132
swtich golint install method (#129) #129
Correct 4.16 owners file (#130) #130
Full changelog
: OCPBUGS-27594,OCPBUGS-27679: Update go-git to v5.11.0 #75
And 1 elided commits (e.g. from squash or rebase merges)
Full changelog
OCPBUGS-102413 : CVE-2026-33814 openshift4/ose-openshift-state-metrics-rhel8: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame [openshift-4.13.z] #137
Full changelog
Source code for this page located on github