Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.14.3 security update
🔗 CVE IDs covered (40)
📋 Description
CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions
CVE-2025-47907 — database/sql: Postgres Scan Race Condition
CVE-2025-48431 — Apache Thrift: c_glib: Apache Thrift c_glib: Denial of Service via specially crafted requests
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url
CVE-2025-61728 — golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip
CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate
CVE-2025-62718 — axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization
CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects
CVE-2026-22610 — angular: Angular: Cross-site scripting vulnerability in Template Compiler
CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig
CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution
CVE-2026-32285 — github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input
CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
CVE-2026-33487 — github.com/russellhaering/goxmldsig: goxmlsig: Integrity bypass due to incorrect XML Digital Signature validation via loop variable capture issue
CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation
CVE-2026-40293 — OpenFGA: github.com/openfga/openfga: OpenFGA: Information disclosure of preshared API key via playground endpoint
CVE-2026-40895 — follow-redirects: follow-redirects: Information disclosure via cross-domain redirects
CVE-2026-41602 — github.com/apache/thrift: Apache Thrift: Integer Overflow in TFramedTransport Go implementation
CVE-2026-41603 — Apache Thrift: apache.com/apache/thrift: Apache Thrift: Security Bypass via Improper Certificate Hostname Validation
CVE-2026-41604 — Apache Thrift: apache.com/apache/thrift: Apache Thrift: Out-of-bounds Read vulnerability
CVE-2026-41605 — Apache Thrift: Apache Thrift: Integer Overflow or Wraparound Vulnerability
CVE-2026-41606 — Apache Thrift: Apache Thrift: Denial of Service via uncontrolled recursion
CVE-2026-41607 — Apache Thrift: apache.com/apache/thrift: Apache Thrift: Out-of-bounds Read vulnerability
CVE-2026-42033 — axios: Axios: HTTP Transport Hijacking via Prototype Pollution
CVE-2026-42035 — axios: Axios: Arbitrary HTTP header injection via prototype pollution
CVE-2026-42039 — axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data
CVE-2026-42041 — axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling
CVE-2026-42043 — axios: Axios: NO_PROXY bypass via crafted URL
CVE-2026-42044 — axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget
CVE-2026-43869 — Apache Thrift: Apache Thrift: Security bypass due to improper certificate validation
CVE-2026-43870 — apache-thrift: Apache Thrift: Denial of Service via multiple vulnerabilities
CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects
CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows
CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits
CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability
CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass
🎯 Affected products177
- Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:66da00ebe2d4fa0bda9685eb8bb89833317eb324769254d731150c22d5b506fd_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:772bb712bae46bea06dec3d397128bb011f9521f98a8645785fbe91b26570c2b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:a05a01a8fda681ada52c9d70a0317bc663caf87e57b316b5175883d3a1475e12_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:d32b838ffcd0bdffba3a470ad2dde22885e43eb88363a09147179ce1d515984f_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:34b5cd6c5a4839f58e05ef23d90170a998e0c30d1c0659a65b3f8e3dc2c279ce_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:3b307df3c50e8047e79830027f6ce895d7586316a8e26c44bd09d604645feb95_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:bf9a5ec228dd4d0cfb72da1e1ea1e3bdae9eace9bf309735bf4be11da1c7f7e6_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:faf2c3490f8febcf1a41eff248843ce3fae7c2e919109144a1276b53a06bdda9_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:4291fed3e746f01fcc1c6edf5e5b8ae229b04bdc728c7f52fff6e0399b2d04c5_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:89c73fbfed46178e3424c37aa6018b31530e99bb5e7d28f716e170ff0431f25f_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:d5555839272a48ab8d880d72ec36c561cd267e45637947736a37b724713fbae3_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:df472fcbb2c39b1f3aad252c272744d250b077b75b1c3c62d7b0f3d8322f9521_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:323671ca65f1b27d7eac33ce82bafe434cfd1b5b31960cfb7c3ed2c7a012d949_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:3feb86eb593f38c5efe3dc46ca4a0ddb32c973c01e5e341562f024888a459cb6_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:9b93cd7401711741cd201a4e7e313da1c79c18ce924300eb988690833c19e8eb_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:a6d33b6c93ccf7ecef655f66f2703bdc5da1f1b94ef73b097930a1e8fbb8c2f7_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:2a6b24698fc9507613d57ba8cf0053dc29fe2c0cb6ab7c2eddd2efaf5e8b6a81_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:559bf1a421c22038236d883cfc0629a45f76b1552a85c95c2a6d1fcf2112dc8c_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:a4ca7e559443c13e2427567959cdc305bfc7839bfe3e222b43f9a5024f350468_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:c498d18de777b04f5849a688951372fae72701cd4309b343ede04b6983ce35b1_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:21407e5dd4852c8b2d7fb0c6447f6017b023845a6c66337a0c17bcebd0930dad_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:3d651c5687e9bf298351c4ce7f1040e37436332b7acc32d4d670be153cd7500e_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:af7be61f02a19106d1920503b189285c908a904913c8331eee30a76e0c8bdad2_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:b5467cff145fafebf8b6b50e225625f864069e337d486067772be42f6eed654c_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:6df9cf919cce766d694e5764d10b67a1853c6298a0d77839feee135015941673_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:8558ffae80998e7cb196efefada06a9a7f610e38adf35bd03536d19ec8abf227_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:cbd358457729f023c501cbd4f6de8feca53fdecc5d92b42ca03befebc528ea16_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:dc2c0655013c5b238d5480e74d308ba26f5f6d26a6447e06ea1f253808eb1a3c_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:25d3ace0d94163da6e4612cad811b434941c64cecce701aa636752bdbac5b4bb_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- +147 more not shown
✅ Remediation
Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this vulnerability, implement a timeout in your archive/zip processing logic to abort the operation if it exceeds a few seconds, preventing the application from consuming an excessive amount of resources. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: This issue can be mitigating by avoiding the usage of dynamic bindings, this can be achieved by not using the Angular template binding `[attr.href]` when handling SVG `<script>` elements. If there's a need of using dynamic bindings, users are advised to validate the input against a strict list of trusted URLs on the server side before serving the values to the template. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (44)
- selfhttps://access.redhat.com/errata/RHSA-2026:36882
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-47907
- externalhttps://access.redhat.com/security/cve/CVE-2025-48431
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61728
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2025-62718
- externalhttps://access.redhat.com/security/cve/CVE-2026-22029
- externalhttps://access.redhat.com/security/cve/CVE-2026-22610
- externalhttps://access.redhat.com/security/cve/CVE-2026-25639
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/cve/CVE-2026-32285
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-33487
- externalhttps://access.redhat.com/security/cve/CVE-2026-40175
- externalhttps://access.redhat.com/security/cve/CVE-2026-40293
- externalhttps://access.redhat.com/security/cve/CVE-2026-40895
- externalhttps://access.redhat.com/security/cve/CVE-2026-41602
- externalhttps://access.redhat.com/security/cve/CVE-2026-41603
- externalhttps://access.redhat.com/security/cve/CVE-2026-41604
- externalhttps://access.redhat.com/security/cve/CVE-2026-41605
- externalhttps://access.redhat.com/security/cve/CVE-2026-41606
- externalhttps://access.redhat.com/security/cve/CVE-2026-41607
- externalhttps://access.redhat.com/security/cve/CVE-2026-42033
- externalhttps://access.redhat.com/security/cve/CVE-2026-42035
- externalhttps://access.redhat.com/security/cve/CVE-2026-42039
- externalhttps://access.redhat.com/security/cve/CVE-2026-42041
- externalhttps://access.redhat.com/security/cve/CVE-2026-42043
- externalhttps://access.redhat.com/security/cve/CVE-2026-42044
- externalhttps://access.redhat.com/security/cve/CVE-2026-43869
- externalhttps://access.redhat.com/security/cve/CVE-2026-43870
- externalhttps://access.redhat.com/security/cve/CVE-2026-44486
- externalhttps://access.redhat.com/security/cve/CVE-2026-44487
- externalhttps://access.redhat.com/security/cve/CVE-2026-44488
- externalhttps://access.redhat.com/security/cve/CVE-2026-44492
- externalhttps://access.redhat.com/security/cve/CVE-2026-44494
- externalhttps://access.redhat.com/security/cve/CVE-2026-44495
- externalhttps://access.redhat.com/security/cve/CVE-2026-44496
- externalhttps://access.redhat.com/security/cve/CVE-2026-44990
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_36882.json