RHSA-2026:25273HighCVSS 8.3

Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.16.2 security update

Published
June 11, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2025-48431 — Apache Thrift: c_glib: Apache Thrift c_glib: Denial of Service via specially crafted requests CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-33815 — github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability CVE-2026-33816 — github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability CVE-2026-40895 — follow-redirects: follow-redirects: Information disclosure via cross-domain redirects CVE-2026-41602 — github.com/apache/thrift: Apache Thrift: Integer Overflow in TFramedTransport Go implementation CVE-2026-42033 — axios: Axios: HTTP Transport Hijacking via Prototype Pollution CVE-2026-42035 — axios: Axios: Arbitrary HTTP header injection via prototype pollution CVE-2026-42039 — axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data CVE-2026-42041 — axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling CVE-2026-42043 — axios: Axios: NO_PROXY bypass via crafted URL CVE-2026-42044 — axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget CVE-2026-43869 — Apache Thrift: Apache Thrift: Security bypass due to improper certificate validation

🎯 Affected products189

  • Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:03f75036c7674a6b565158b5b61b0cb546cb0b54ecf68555c200e1fe42e8b31c_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:897c7b3e333e267183cd9b70d8249ac2ef8d3153d490124b485b48e14c958f34_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:cce9961ca00d8a06e4c1fbcead30bb8733577b14e51bec3a07e9afd4106b90bf_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:f16e488712d7d6a203192b2bc094e05d4bffa779aa796ba39d907cf6ad6cf147_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:0102aec0b620f9e278033e6085b9b7a5713a92ff66716f596daccf29c125f18b_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:44c5cbf818f2fb1d7e771cd519f5278004fb2c7877d342e617710effcfb4453e_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:4e696212f0c369f627460f69eb5027e25c3a58a2bbdd66dcf2a449c68e268f31_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:7972b1082ace8562b459bac5427f939a174d73a7e38ed90b0faf8948c10ac6a2_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:641e84ed8ff440b1172160ea0018a965c80c2b21b1630087bd537f1e71356462_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:7a9da04c13054cb07f9b7b0b8a8b46eb4dbb1da4b423396e1a9f63e983665af7_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:c0714ab2d5f3ac81682cd67a71cbb6fafb91aac8a00ad8d005335f6afaaea76f_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:f29fe1873d34780919512ddf33fb866bd4f291ee6a4b1911bff1126409aee909_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:220c90b7f7cca86bbf0f819052ba5203d2f5ebe829144ecc294f41dcee783f2f_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:404d9e42d24ec726250b6216342a2798991c347467070357fe23d677576bc443_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:461b0575b8b515f97c98bbbba2351b81a1d8cdba663ed041ca289d2c0f8fa5d7_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:76502efd68aee64769fec9d26190dd703ce73590de58b3156ed188695024c38b_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:017cbc09964b873dd073e6f9533571cab735c1207eb3ca4eaefe2d175f0fcea5_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:1b727e894dc9a0f39f1d4abc848760136ffcd987d5b263c0746eb22b4064cab2_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:8ef26648d1e499032ce6a650994b1ac118f1a50ac6aea668116433bf4e79d395_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:b0802e748328f09b2f4213aa36acd4d1956a465093058637bb09b643a3b830be_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:2839b631104101396ee90d7260c54a33718d2f05efae74d5835328669171d92a_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:3983ad22bcdd423c25ae15847c731e53252b9ab2f872562ba5e176975ecb3020_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:4c27be62da4013add02df51047989be3b4eb1d4adfed5088d498b577e3a0abcd_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:dac92bae7fdedab855500513f5c38ec4cc9006de8cfa39b10e027fa7d0abdc49_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:48e88da6dfd84f5f893c8ad35434dd6e7eb7b2e77c7ecfb349a6a9dcb6e93cf3_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:51310127d2f1a523aea5a43218fba7f21c99a8e7dd1694ed4cf3495cd80d0cc7_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:86417edce819a2a74d5067441f21d1785216a71a7edb3fc1ff249be3b59bc7a7_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:af4644ac53ee2237273937c516f5fde27fa9bcd2bdd9e0341bc0eff4d3a5754e_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:3b3cdbbbdead1b32f52652da1637bc6249ab6513dfa2713b8f4bd666484ac345_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • +159 more not shown

✅ Remediation

Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (17)