OpenShift Jenkins 4.22 security update also changes its default Java runtime
Red Hat’s Important update covers 28 CVEs, makes OpenJDK 21 the default, offers OpenJDK 25 and removes OpenJDK 17.
Red Hat has issued an Important security update for OpenShift Jenkins 4.22, pairing a broad container-image refresh with a Java runtime change that existing deployments need to account for.
What changed
RHSA-2026:60256, issued August 26, lists 28 CVEs and publishes updated jenkins-rhel9 and jenkins-agent-base-rhel9 image digests for amd64, arm64, ppc64le and s390x.
The advisory also changes the supported JDK mix in the image: OpenJDK 21 is now the default, OpenJDK 25 is available in the RHEL 9 images, and OpenJDK 17 has been removed.
Who it affects
The update applies to users of Red Hat OpenShift Developer Tools — OpenShift Jenkins 4.22. Teams that pin image digests or depend on Java 17 behavior in controller or agent customizations should treat the image replacement and runtime change as one upgrade event, not as a security-only rebuild.
What to do
Red Hat recommends that existing OpenShift Jenkins 4.22 users upgrade to the latest images. Before rollout, verify custom plugins, agent images and pipeline tooling against OpenJDK 21, then replace pinned digests with the updated architecture-specific images listed in the advisory.
sources
- RHSA-2026:60256 — OpenShift Jenkins 4.22 security updateaccess.redhat.com
comments · 0