Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.15.2 security update
🔗 CVE IDs covered (11)
📋 Description
CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2026-4645 — github.com/antchfx/xpath: xpath: Denial of Service via crafted Boolean XPath expressions CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution CVE-2026-32285 — github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33487 — github.com/russellhaering/goxmldsig: goxmlsig: Integrity bypass due to incorrect XML Digital Signature validation via loop variable capture issue CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation
🎯 Affected products185
- Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:60065dbc53bb557903a9b64b6d125ec9b1cc079219820ef3e130a6de1c31a344_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:c5e28c2806be10fb75b30adf2a97c43544dcb51435cf00807a116d7d99720d17_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:f20db2439e0a790e6b1c78770ffb6dcfc0104713d2e8201f6b5b9de1295781cc_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:fa7e83bb54b4933cd659946cd4229667c691cac019d9997d5f828eb0c6fcfabc_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:6664a9064f3da9d60819ad3ada04c9b4ceb4ea2d5d7f74627083e782163c05ac_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:a6b2af53c56da44480240dcca6a72c3a650a540149ff0bc0325532fcdd13ca13_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:ab4c94b227afa4d17c00714b606e540a969c6fe85406dedfa24163586218da27_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:ea837be842753d52b5a2df7f45372f1ede0497ea477e4109b77589afab4d6b08_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:2c595aed572b9a851314ad8b7bcbfed30296f90f86cd5e973642d1625d14a007_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:5a0a4f6eaa4ab83bb6eab21ace418d5479fea3264dacdf775c8460eb71437a0c_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:6902779011f15e1dc9a2cfcd5506ca90144d6db7eaecf25c30734ed28399548d_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:b5f297ec8554c1a9436ac8a00382d51d6b5b97e8afa3c4572cc8c6b0230d6a82_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:90438caf8bfd26f515d860aecf57a8c0e8df09552a0261920a15809caf51e8ed_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:9b7f6a66aaf4da4f35eb903eed24fffd24a4e3a755903056391c38c4cca910c2_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:d4084698590388f90218d2f0ed5461f89ef92b15d6a24a14c405eec019988339_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:d6588c327c81ff582c94c04f5778545ad6a33f6565f4c92f0b370da0e88c8c07_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:08670904b912776ccbe1b62d7e9e0bbbf376e54c33b34763f2b78f88e395ad5d_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:256d30d727563fd38b23bf8559df0acf66668b261bb77881a5480453d4f119a8_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:3bae58887e2e06420a85586b71ad13eeba2bfd1f42a5eb744c22762528b346b1_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:a97937bfce590d78b46b3b3e7ac1cc23c34847b462dc84bdec376a6f525addd0_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:139b9d6a3d694fc65c3e3bc657b51d4415991074dbb1a996a157ae0b166c1794_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:7022651f3c75f56614d6d6672d6913e4544b9ec8515ce6cc48584ec976904d2f_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:7844ddb3d5dbdcc3007e0f925f82cfe5559901b022cff780755b76243212408f_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:f31430730d261174629bcc858733392f61e850641b570e13e97a955512113e4e_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:19ecedec85f74f07230653f5a353742b382618b28fb182154b41e8f95db40611_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:71334d9c7559dc933e9e0dc1677c7d8ebbfa3f541378230dcfebe6a8835ed0b4_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:717cae9be4c4d30321db1c6724c349a609975bfc30176235bd3f675ad249e866_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:b6e18a4ff1bb1312466d4cef97537874506b42de08ba44dbf088e3745bf5a779_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:29df4aae19c1ab73ff0b31095f1970f0d5b704555ecedfbf9e8a499f6bed8bcf_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- +155 more not shown
✅ Remediation
Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this issue, restrict the processing of untrusted or unvalidated XPath expressions by applications which utilize the `github.com/antchfx/xpath` component. Implement input validation and sanitization for all XPath expressions originating from external or untrusted sources. If possible, configure applications to only process XPath expressions from trusted sources or disable features that allow arbitrary XPath expression evaluation. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2026:13548
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-58183
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2026-22029
- externalhttps://access.redhat.com/security/cve/CVE-2026-25639
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/cve/CVE-2026-32285
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-33487
- externalhttps://access.redhat.com/security/cve/CVE-2026-40175
- externalhttps://access.redhat.com/security/cve/CVE-2026-4645
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_13548.json