RHSA-2026:11414HighCVSS 9.0

Red Hat Security Advisory: multicluster engine for Kubernetes v2.9.3 security update

Published
April 28, 2026
Last Modified
May 27, 2026

🔗 CVE IDs covered (6)

CVE-2026-25639CVE-2026-29063CVE-2026-40175CVE-2025-13465 · pendingCVE-2025-61726 · pendingCVE-2025-68121

📋 Description

CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation

🔗 References (10)