Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.11.10 security update
🔗 CVE IDs covered (16)
📋 Description
CVE-2025-9288 — sha.js: Missing type checks leading to hash rewind and passing on crafted data
CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions
CVE-2026-21721 — grafana/grafana/pkg/services/dashboards: Grafana Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation
CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects
CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig
CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects
CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows
CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits
CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability
CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass
CVE-2026-46384 — github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: Integer Overflow in Avro Decoder
CVE-2026-46385 — github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: CPU Exhaustion in Avro Decoder via Unbounded Block-Count Iteration
🎯 Affected products165
- Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:2fbc77c6b49895fa6ca4d1ccea4017178621870d1895a101b599c4d363767cb7_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:5a6dee35195432bb81f4136aa9f1f10b7a8fdb55d2feecec1edd18a5b0beeccc_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:6dee87bba9612731e98ac81dccc39996626d83bc1ea8ec37b224d8ccbe74c273_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:efc061c2b9751fa2e4794ddbd9ac9a067b4724c27aea42258b95c894daecc6a8_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:0214b8d816592b8d0e5effaf3a97eddbdfd32b4c3056fe52d869134e760a1999_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:2f7afab1d50e4b63467fa53a459da1caca9674d5d10caa5381e73d52d0bba48f_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:3aae30a486770ede46e8096a217c6726a0c28e7aa9a0c41d01b512159090278a_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:edc0de9ec9ce648b3062fed475a01f5ba2c705af7d7f68697702ccff4b01b240_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:9f2e011a88af74a47713534dd66a8af603b09abceffefb78a948675f29593135_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:a09f8e102ea566c31f755ac01f616dd2b8decc3e67a54db9559c8a21a06c1cd4_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:cf03d8aee9d3cda92ca2f5ead22a72ee4c09b8b86ab48b8c4b13acffda6a74a8_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:ff471db4a5b2a195f8f4ba00c4c965d20b7d5a05e00802ec3a3327bdb292147e_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:2fee1170f06bb48ea8e44dd8f55134c53fc06440787722cac5efd4eafd931ba0_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:3987a6dc7f58658e99009a96b6efa7ae1de121b3e2b5f96c85b6270ce652e4c8_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:ca17f3d069b1f706c78c1a9e9d4a5e93c6ef3b3efe06857fd2b0df22fbf698fa_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:ffae150c4999c220b0d554f6a4308962a64c1b8b40127071d49d5b06024f427e_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:1131f70e58adc57a1abea1d3ff0c05ba5550b076d85c03c3603da385569c66a4_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:b8f73833900bd2ca598dde4820ee987ccdbce79ed40c73dd95541ba85b3391c9_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:c9ead678f4a890bb12e4ee3c86b838cd36cabd6173068b55de831799c53ea6db_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:ef181694b56303e79a0ba6048c71bfb7c09fbe016a18c7b35cdbc2d6b96aa54f_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:49c86d311aa7114dde4f5aba376cd4bf8e31befeab636b76e6f72cbc6604631a_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:58984d269811dff0f957d1220052dcfd83213da1b20dcc83d5dc8bdc789f31f6_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:71b62b8827a7c450c0e2b03e53e02a107c6eb1f46ecd69264bcf9355672b4111_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:f2f4afb3763dcc2b455db4ffa82bb49ea8eadbf6201ca463d59e1092835184ac_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:15f5eba0eee8a4e2b2a85cf91a91c80da6d6afe20ea5f6bb0388e641d2b3948b_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:56c682ad9d05710d8607492438bbc40876b71cbe4edfd30ea990f03a8f5b353f_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:731f0a59e2ef4dd6ad6dff6667afddbb41e5abe22a9dad158175d038ce522bcc_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:ea5476f88f2e0ba0810ee594f5c344023928f65ebd21b7a3f0a16c91ecd73c1c_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-search-indexer-rhel9@sha256:6d91b1e05908851c158aed4813921fc86cd1609c723fcb057aa1085be86aac56_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- +135 more not shown
✅ Remediation
Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2026:41064
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-9288
- externalhttps://access.redhat.com/security/cve/CVE-2026-21721
- externalhttps://access.redhat.com/security/cve/CVE-2026-22029
- externalhttps://access.redhat.com/security/cve/CVE-2026-25639
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/cve/CVE-2026-44486
- externalhttps://access.redhat.com/security/cve/CVE-2026-44487
- externalhttps://access.redhat.com/security/cve/CVE-2026-44488
- externalhttps://access.redhat.com/security/cve/CVE-2026-44492
- externalhttps://access.redhat.com/security/cve/CVE-2026-44494
- externalhttps://access.redhat.com/security/cve/CVE-2026-44495
- externalhttps://access.redhat.com/security/cve/CVE-2026-44496
- externalhttps://access.redhat.com/security/cve/CVE-2026-44990
- externalhttps://access.redhat.com/security/cve/CVE-2026-46384
- externalhttps://access.redhat.com/security/cve/CVE-2026-46385
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_41064.json