Red Hat Security Advisory: multicluster engine for Kubernetes v2.10.2 security update
🔗 CVE IDs covered (10)
📋 Description
CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-4740 — rhacm: Open Cluster Management (OCM): Cross-cluster privilege escalation via improper Kubernetes client certificate renewal validation CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation
🎯 Affected products125
- multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:6010f1e00ada07c0100468bde8ab20c176610f9d8e7498fc26d46960d63c9984_amd64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:9530059a49869e8f1909a7ab06036c7fd36018a14ae2e6f22c5c0c1868eaaf49_arm64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:b1eb4a408936b8cd0863c04fb7fe3a72e875c06d9f5c33dca4c82dd4a05a027f_s390x as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:ea9dda951ced7f3641ba5afd651191a75321cb0db5e251f66a510bc6d6f0f090_ppc64le as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:1a9bf49ede874a64c5acbe426e62324b564458e5575db9dd95230a15933e9adc_s390x as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:a464a9d46467012d73772656bd5eb81713bcc2d27b461e1083ba5c00548156a8_amd64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:b3cb1d388c9d992b4721a1087e142255583868d0c855f5603d37b67d2c0ed64c_arm64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:d66e556ff0b55bf9a54b45dc26e5175a662be785440db589efe01efa9da30d0e_ppc64le as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:2b20ddec4825b4224839823ce56183cd163491142b9d613f51f5e15859c0bf2f_amd64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:5cf7bb103490cb1b5423c7d02d5b412f9059dca5455770fb0ecae8e1331493d7_s390x as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:c9456c7efa795d600500ab1c05e30ac7ce8f83fd571c5d8cfc0d382fcf575d9f_ppc64le as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:d1773b6567bd5ebd6b33e5ff24bafdd17e1d1f4dceb2a93fd4355bad0995b7a9_arm64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:4c30c0f1e5ba711350357dbfb9f5048129a90be5c28011f85116a2fb365c6f4c_ppc64le as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:88c09914c96a5eeea856d8ec05f7c4d7afff9537990a3508073a98de2977e983_amd64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:a2bbd28144d23264473715038172a92b199f6fb0a1b1f3f1cad2c56a3454fe00_s390x as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:b1619f86a599f1c386e8b487a1855b6f99a3538a619b55479debce224f541544_arm64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:09ddc268aff8a2e20a6678fe200843c4fc98e9e1d305074c5bbef73760ec15a9_arm64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:3d1a892c3842daea43ff64fa6bfb2276504003de0c8822412bb403e90c783d1b_s390x as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:5606d9e6154e3eb20a6c7b94346881ddedb155f54473f0713d67fe4fa0586ac3_amd64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:9e783056352c39529e7315855af6d05cde5b39c009d2e67b9d88fb0210d30ed0_ppc64le as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:140b3b9a9526130a50040e355eb02609e0c38bf9ec0a8d5bcefb31862e2024f7_arm64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:64efc33fe97ef9bcae490ff0ca61717dd48e6b0b0aab417e8ff252250baed576_s390x as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:994412dd0b9619d215a17d5ac684b11864f12030a399437247dbfa9f26061e31_ppc64le as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:f6a4ce6ceab1271e0afab9e60f4ef27745c584341ba944fd10e0b4209c8e4650_amd64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:13ef7c6b65ffe6a1b434091830aa08fe539d9befd8e55f3177e486e59fdfc9b5_amd64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:67bbdc696225283b4baa550a402fb03d9999ccd471a62622df1bbf0917ac8f52_ppc64le as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:8b16aa9760ba4402dfef3eac989432a794af7c1c71f3e1127f6077d54cdf244d_arm64 as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:dad83ae3c921ff7444f8317fbdc165a43f9177b5d0554b08a960d9752ed1dbf8_s390x as a component of multicluster engine for Kubernetes 2.10
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:57538de1fa62ef85ff3bcf844e90d44d79bb35bae50b21b2029d5fdcb909520c_s390x as a component of multicluster engine for Kubernetes 2.10
- +95 more not shown
✅ Remediation
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.15/html/clusters/cluster_mce_overview#mce-install-intro Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:13542
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-58183
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2026-22029
- externalhttps://access.redhat.com/security/cve/CVE-2026-25639
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/cve/CVE-2026-40175
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_13542.json