RHSA-2026:11414HighCVSS 9.0
Red Hat Security Advisory: multicluster engine for Kubernetes v2.9.3 security update
🔗 CVE IDs covered (6)
CVE-2026-25639 →CVE-2026-29063 →CVE-2026-40175 →CVE-2025-13465 · pendingCVE-2025-61726 · pendingCVE-2025-68121 →
📋 Description
CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:11414
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2026-25639
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/cve/CVE-2026-40175
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#low
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_11414.json