RHSA-2026:24503HighCVSS 8.4

Red Hat Security Advisory: Multicluster Global Hub 1.7.1 security update

Published
June 8, 2026
Last Modified
August 25, 2026

🔗 CVE IDs covered (12)

📋 Description

CVE-2025-41118 — pyroscope: sensitive COS SecretKey exposed in plaintext via configuration API due to missing type protection CVE-2026-21728 — grafana/tempo: Tempo: Denial of Service via large queries CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root CVE-2026-33813 — golang.org/x/image: golang: golang.org/x/image: Denial of Service via malformed WEBP image parsing CVE-2026-33815 — github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability CVE-2026-33816 — github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability CVE-2026-34040 — Moby: Moby: Authorization bypass vulnerability CVE-2026-40293 — OpenFGA: github.com/openfga/openfga: OpenFGA: Information disclosure of preshared API key via playground endpoint CVE-2026-40890 — github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of Service via malformed Markdown input CVE-2026-41602 — github.com/apache/thrift: Apache Thrift: Integer Overflow in TFramedTransport Go implementation CVE-2026-43869 — Apache Thrift: Apache Thrift: Security bypass due to improper certificate validation

🎯 Affected products22

  • Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:117a8c83568dc190f011469ea39c35ed1a16a7040397b092675e08c0630b3688_amd64 as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:368e38ef2cb6f7ae5a39d8802785bc1e2ea406650f0f1572425ee9e473f7dd23_ppc64le as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:58d6a46e506128186ff995a3f4cace3c4644bf6dfe6aa686aa120c1948a16241_s390x as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:f49ddb5fcea92e6361346508380cab45bc6228c151354d247e17d9700e82d58e_arm64 as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:0d6c621066cdc9c428c9286b7dd8ce0eed831de27b385c17e3761a1d411e034b_s390x as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:1f04b37cd35946131e8dd90bcec49796ae6f431d4a800b5c6de8162ab6fe0d8e_ppc64le as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:3a7f09a334a51b8f8d2da9871cc28d29de6c32cdfa12ccd38f43d101f18dcfff_arm64 as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:90153b5c4c5deeb7abadc7ac8ebb96b9ac72825ef609e8a172cb6866f3db351d_amd64 as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:056a115b19ecc05e38b2211e7adcddd4bb8e691c8403598391816db8d2f29178_amd64 as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:3b6012d3ae4ca3c074f6a9895c7c46e3cb7c55dbbd48b2118eabe228eb06fcb1_arm64 as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:54eb853bc03d77214dfc4110f6880f90b5d0b2a509941c3a0ce20e73ab978952_s390x as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:b811ad761dc45e80c61a409685f0cb18d0d87378339363185b46d56b191c7e07_ppc64le as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:6ef843cb38796a93ecd60deafbb6fb902f5d6d93a38023d2af736d5942f410f5_amd64 as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:31dc2fb94d13afd25570799ae1a1504e918eb55d79d6360a4576f3ec14ca82f6_amd64 as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:7a010c71fb5d894642c4feeb8dd841e9be0745cdadc206407be15f245895f949_arm64 as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:8d2f906d14238270d146c26c4dc54f8e219fe0b3ac2311312173fcc75af7101b_s390x as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:d509da45ed3ead45ff85dcb8d1d88883cc815a6cd2cbdba18e813448e859c490_ppc64le as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:0a3e487b8271091ee4e2f5ba71475c8986592f9c634974e2a319e05a15d566bb_s390x as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:4063ad90ef97f9e81e8f75803f64cec8a72d3dc43dfc0dd58e3f6731b4dcef8d_amd64 as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:9f50860471c0cb8176d3d9354877313976ee871922326547ecb8ee869e81ca61_ppc64le as a component of Multicluster Global Hub 1.7.0
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:dfdd95b60e0ba33c068a4b1b02442b908b383695dffefb6cefd7a6f738986d9d_arm64 as a component of Multicluster Global Hub 1.7.0

✅ Remediation

For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/multicluster_global_hub/index Workaround: To mitigate this vulnerability, limit network exposure of the Pyroscope API so it is only accessible by trusted users on the internal network. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (15)