RHSA-2026:41030HighCVSS 8.8

Red Hat Security Advisory: Multicluster Global Hub 1.4.7 security update

Published
July 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-41567 — docker: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-43870 — apache-thrift: Apache Thrift: Denial of Service via multiple vulnerabilities CVE-2026-46384 — github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: Integer Overflow in Avro Decoder CVE-2026-46385 — github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: CPU Exhaustion in Avro Decoder via Unbounded Block-Count Iteration CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin CVE-2026-53492 — github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration.

🎯 Affected products22

  • Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:5e37720cef2fa6b617ee4f13dd20b52ffd6ea1f40d344fbed5a9ee13062100db_arm64 as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:7430c54c9069fb79c4868fd138d9b32aca5c5b7bdc664b8c4867c88f368794b1_s390x as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:b236a391dc18a1318246f2f2dafd51046e9775e27da59062285160182c433b37_ppc64le as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:c083ca3a199fb2526f8c5bd289360c564190d03bb62442b9b8ee1bbaf50b5ddb_amd64 as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:46d3139333312711d3a5182fa39faa17f55ad958705d5cac251d4368c19ea10c_ppc64le as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:7ea29573411a624258921e47724e74d5990e08961d439b570fa7e514ca1e089e_arm64 as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:8f60851c9d3e9cb1acd491f76b9e69ed960a0aa2aef05150db679e77041c6db0_amd64 as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:dcf3c795131a0ad5d23d84cf75624bc6a218b92fc7f77d315f09abd13043af99_s390x as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:171f3dd702df169e177e19a280f7a3ac7ec39b7314803bd79e75899458537f45_ppc64le as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:725f309bda18524c827f0c7f62f54b0deccd6ea913f09f18ca425b8a629fc079_arm64 as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:aec321001dc697520c69f4a895cf4e7f586588dc9ff4bdafee7174ec845bf981_amd64 as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:dfcfdb1ecacd9bb6f5c869f738a72f59b29374dedfbc70a2a110b9c3ed2030d5_s390x as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:dbf88c1d7dcc954af16930554e98740784793d4147ffb249d06b79f2a7402d47_amd64 as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:060d3bfc8a2c8a26e2900198c08ad7a6c7483ef97ffbae7d76d557be77aa5e1b_arm64 as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:36cf715173a544f464ab1eab439d75bda3d3b02fc4d54038243edfce5b177d4a_s390x as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:5207c10c701c09e2497976ba70543a66e1ec8141603cb970dfd7ec26414eab65_amd64 as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:9f621dbba78c2f72b74a16a23f29f0630d0527737abbf7a2cf62ffdd1bab236b_ppc64le as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:4a57e975be3e638d774e9f0e9d2608f528636185b2fbac6c08d058be74211d9f_amd64 as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:5eb9f34c615982831061c9d24e978cd54e4fd40f34224dcad3f447003f63dfaa_arm64 as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:a04a325cde0fc3eeccbdcf6e942df306865ca7ccfb734160ea06dc204d5dbc02_ppc64le as a component of Multicluster Global Hub 1.4.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:dcef91d3059252532c053a368a234c137851a89f348d37f61c85cc12ff58250b_s390x as a component of Multicluster Global Hub 1.4.5

✅ Remediation

For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this issue, Red Hat recommends only running containers from trusted images. Additionally, users should avoid piping compressed archives into containers created from untrusted images. For environments utilizing authorization plugins, restricting access to the `PUT /containers/{id}/archive` endpoint can further reduce exposure. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available. Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path.

🔗 References (16)