Red Hat Security Advisory: multicluster engine for Kubernetes v2.9.3 security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-4740 — rhacm: Open Cluster Management (OCM): Cross-cluster privilege escalation via improper Kubernetes client certificate renewal validation CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation
🎯 Affected products121
- multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:05c68daf75ebb0aa8353778272d29c3dde67a4988806c5e8ea19a707b0453bf4_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:6a274b91afb43bc23b4c378ba760bae2d104641f3fbec75284fe0db6c9333a41_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:7100c3b705273d0eabf8e79720363e2a9a9e936de2e4a9d065c473f0ba84ec82_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:f27864c6b8e7d909bf543b2c7fe14916b25617e87dee53cd2e4137747f26e60d_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:0d311a96d10861ed390004216ef1ab7af16069752f93672a60a213d8a2352062_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:6a1f8385d4e46f414d78902d7aaabbfe534dcb8fdaa1e2f1d19895e6c063be22_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:a99c70594615f9a5c3a3d4923d3734f5e2e48fa18e8a13bed71877d942077918_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:bb436501d9ba7564b17d17af5c64d829ded6a097c251176aa7ba05848443e0de_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:0059c4e84378c4573af64fd2b7f77674887eb112fa91c2a9aab6d991b04669ec_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:255d63bfe77a84a4728f03e05281bc052edbe24d3f5197e85d24ddbb1e1b83c1_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:89824177b9b9bd2e6dac5aa16536d4e4e84b996cc8874fc270428d858710d081_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:a04e572c55cde29b16e42a1383acb6bae299f7d002790e8353d4dabea2f2def6_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:14aa8aca2295a7b53bcb953b0af416922e6052613805d7a798626c01356e39ee_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:33923924370f61939f5b4f9dbe4f6c5d32b2dd1c8f26cf99a3aff0781c01be76_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:5f393871b9628d8f73c272f42aca32d79168e1aae72360d46767db92555571a0_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:8e91dabc89b2b2f09898197df3dbdc10f8ba6fe1fc98633c3f5cd03154f40b6b_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:3450172045122d4c042cf5fe8b854438e6d12c3be040c658389868cf7c783855_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:40c40d46fbc1025eda0f9d8f318bc3e29db9dd69c9a58c0053a66c88e7ebf896_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:bc68255f57080c7e318086d28895792242264ec83a898a352c7ef7376acc179d_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:f5a133e83045e227dcf88bf6f824d7e70199d4b72c1c75d8528ded51cb09bb6b_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:11c80aa37603b5b8b77ac607fa177d24c9787b7c99ca111d3c25b20713fa7c1a_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:796972164eeaf4e3848ff48ac5d5712d09b176349a0b722d7a1942b1eaeedf79_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:9fde338283a4f276b5700240b3b8c2106b8d11f3631d1cb054393b4824620b08_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:eea3a084a03c92edcc5dd6f88ab45a083ee51d43334aa29fba83198498b61a5c_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:0482f136aea57d0c58833fbf0c9b98a78e12750cc12a4f76c6da35b2578bcb66_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:34a6431cc565c806a1ac50337459ee5c19aaad9dd70fbd1a05afdc86bdbb564a_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:bf37bccbbb3b5219d24753a92926b3cafd5ea52978887ba463caad985c52001b_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:dc5cee7aecbdf340ac6bfa804066d1275478a7825c4310395f93434e4bdff66e_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:7834cfc402e38728e46782d63cce3298167e3627c2c6023a490cf54a9561552b_amd64 as a component of multicluster engine for Kubernetes 2.9
- +91 more not shown
✅ Remediation
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.14/html/clusters/cluster_mce_overview#mce-install-intro Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:11414
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2026-4740
- externalhttps://access.redhat.com/security/cve/CVE-2026-25639
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/cve/CVE-2026-40175
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#low
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_11414.json