Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.15.3 security update
🔗 CVE IDs covered (20)
📋 Description
CVE-2025-48431 — Apache Thrift: c_glib: Apache Thrift c_glib: Denial of Service via specially crafted requests CVE-2026-33815 — github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability CVE-2026-33816 — github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability CVE-2026-40293 — OpenFGA: github.com/openfga/openfga: OpenFGA: Information disclosure of preshared API key via playground endpoint CVE-2026-40890 — github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of Service via malformed Markdown input CVE-2026-40895 — follow-redirects: follow-redirects: Information disclosure via cross-domain redirects CVE-2026-41602 — github.com/apache/thrift: Apache Thrift: Integer Overflow in TFramedTransport Go implementation CVE-2026-41603 — Apache Thrift: apache.com/apache/thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation CVE-2026-41604 — Apache Thrift: apache.com/apache/thrift: Apache Thrift: Out-of-bounds Read vulnerability CVE-2026-41605 — Apache Thrift: Apache Thrift: Integer Overflow or Wraparound Vulnerability CVE-2026-41606 — Apache Thrift: Apache Thrift: Denial of Service via uncontrolled recursion CVE-2026-41607 — Apache Thrift: apache.com/apache/thrift: Apache Thrift: Out-of-bounds Read vulnerability CVE-2026-41636 — apache.com/apache/thrift: Apache Thrift: Node.js skip() recursion CVE-2026-42033 — axios: Axios: HTTP Transport Hijacking via Prototype Pollution CVE-2026-42035 — axios: Axios: Arbitrary HTTP header injection via prototype pollution CVE-2026-42039 — axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data CVE-2026-42041 — axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling CVE-2026-42043 — axios: Axios: NO_PROXY bypass via crafted URL CVE-2026-42044 — axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget CVE-2026-43869 — Apache Thrift: Apache Thrift: Security bypass due to improper certificate validation
🎯 Affected products185
- Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:135a39cd83ff285a1aa11cff10afc0b296ac7e02b8e36b709c0bca158f57632b_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:504b27bcace40e21bf5be1ec132f2e55496a67f2ab4193d246d617b66986f943_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:a0874e5519e050c5ea7b6314c691bfe409ecc028b097c31bbd945ded74500544_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:f506e2a31bbad877c7e679cb176a1b254df38a5576014bbe8b7e920a870a6005_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:656e84829439b903286623b80566ba2ba399eb67381881b372b2cf95c7b0f146_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:9067f888796876691463b4533630153c75033639b57e9ee9dc226488cf90bf8d_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:d86fdba4dceb045db1df4bb31f8ed6024c05cb25b68b2d515b30b67158aa048f_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:ee8e07f92b860276174b6b70ffb7de6ffb01e90b0ab8d834efb96a80e02a2372_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:0e7f75763aaa1a7483477354d73b9caa181eed458e7aa3accbbac54fd382bbc8_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:1ea38f304e338f464a6db844de9ea5c29fefebb9bd4bcc1b52d0f1fe5d00557c_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:3689d26f867bdcb48af3bd70df75afb3af0dad076e8757f0c3a7b20a865555dd_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:4feb177e6a22c190b556f07fe21ebb4a866637914a3e222ef00db31bd50e7c7d_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:29fb6bf45c50f761ceebdca0e9186c5d8b9eaf291cb4f521b50d89fe744eaa70_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:49eee8060fb6e6f04ae62e623fd43b0c8080be74cffa4bfc9f23f4743e8d29d9_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:a3b5778a8a7a0c51dad6a2ab83d836319eb43dec9ecc748e4e0dd15767b9c459_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:c69d489f44c83b541fee0e00e75dfa219469643559e5757d641f8d4a1cbbafc8_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:847feb43a65e505fe51ca5ef85dea599506b4eba9aa26a35f1a1eb8f1f5f2f64_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:cbad6b72aaaef2bd2b9435a8f5a9a4d24981ca7881f9a46988d174cad655d761_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:e79d88319b73bc8e4454df08094cce3e98adf87da507068d42a0c0273ade9ea2_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:f157a7dfa46c8b1f295c9842c2d1bbae8b5a6a78dbc0d7e4d7b4de1211d6850b_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:5f9b6f0aff5091b4ed312a6402d2eec09c883eb77b5fca3141731c5c414bad00_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:7870bde1c9daf376a528d2320927e631ffba109696b8191177ea4a09e19c517e_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:b4b5a6f032c18ca6e1dd85db61475ff7913764941e8601cb9e18d2fd38a5a7c5_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:de06f2f0d25f9a285869dea7b82528141a74dc93a16c28243a721fdd408aeb1e_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:77f0a0a44f10d77e2e962e199295f50c8301d66c0b856d62e3c5126babc7364e_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:a31e278dc4f07dfefe6295b26ac350536f90ea740a1a92720eeb89df45b210d6_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:a93310fadf8597c46a66ffe2ff32c5dbcd75250fb35aabc01ee5bea2cb86e1c1_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:eafaeb90d195f89f579cd1c5a586db9d5d19947b63ecbf7c24785b23ab2c4026_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:35871087288d35952ff8e11eb793444cc58cb505958cdc173f0e8d77581a4b6c_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- +155 more not shown
✅ Remediation
Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (24)
- selfhttps://access.redhat.com/errata/RHSA-2026:24539
- externalhttps://access.redhat.com/security/cve/CVE-2025-48431
- externalhttps://access.redhat.com/security/cve/CVE-2026-33815
- externalhttps://access.redhat.com/security/cve/CVE-2026-33816
- externalhttps://access.redhat.com/security/cve/CVE-2026-40293
- externalhttps://access.redhat.com/security/cve/CVE-2026-40890
- externalhttps://access.redhat.com/security/cve/CVE-2026-40895
- externalhttps://access.redhat.com/security/cve/CVE-2026-41602
- externalhttps://access.redhat.com/security/cve/CVE-2026-41603
- externalhttps://access.redhat.com/security/cve/CVE-2026-41604
- externalhttps://access.redhat.com/security/cve/CVE-2026-41605
- externalhttps://access.redhat.com/security/cve/CVE-2026-41606
- externalhttps://access.redhat.com/security/cve/CVE-2026-41607
- externalhttps://access.redhat.com/security/cve/CVE-2026-41636
- externalhttps://access.redhat.com/security/cve/CVE-2026-42033
- externalhttps://access.redhat.com/security/cve/CVE-2026-42035
- externalhttps://access.redhat.com/security/cve/CVE-2026-42039
- externalhttps://access.redhat.com/security/cve/CVE-2026-42041
- externalhttps://access.redhat.com/security/cve/CVE-2026-42043
- externalhttps://access.redhat.com/security/cve/CVE-2026-42044
- externalhttps://access.redhat.com/security/cve/CVE-2026-43869
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_24539.json