RHSA-2026:42852HighCVSS 8.8

Red Hat Security Advisory: Multicluster Global Hub 1.5.6 security update

Published
July 21, 2026
Last Modified
September 15, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33376 — grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default CVE-2026-33377 — grafana: Grafana: Privilege escalation via dashboard overwrite CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-41567 — docker: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-43870 — apache-thrift: Apache Thrift: Denial of Service via multiple vulnerabilities CVE-2026-46384 — github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: Integer Overflow in Avro Decoder CVE-2026-46385 — github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: CPU Exhaustion in Avro Decoder via Unbounded Block-Count Iteration CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin CVE-2026-53492 — github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration.

🎯 Affected products22

  • Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:2e071c3bb6f1fec229b53557556feffaa8f3137fbf50444ddbf50eb99eacb571_arm64 as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:65b21ad0d3524d3646d256224376d5cdc6e168ca4a888211a6544448c3d1ba5b_ppc64le as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:802fab4ed4895751fae71a3f1ca7402e73a95a8cbf31bc83d3935ed2b27886f2_amd64 as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:8f43a432db2cd48fa4af89f053fbfec80cbe295f4682ae6a67ce51971fa96d3e_s390x as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:534f21b4fa204a463f8bef0ed54eee2bf66e549e92ede32dad3ae67a32779b3c_s390x as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:8a0d6dd45f38bf49e18944c3dd487035b4866e36453bd2a322918ce03f2262db_arm64 as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:ecae6850a68896cf10e7c2c2b9d23987ee2b9108618a33b98d8a372d3649dd6a_ppc64le as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:f58b750ede7e9dbce58f763c6cdf74901499619a15fe8f57590ea647f08267ad_amd64 as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:371474d8fe061de9129e2f8f65058c179aa1f9f19c6d1acb671235b22551e8af_amd64 as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:dbabc66991a633163cc07ee1e104bd2bf1ae52eb85ac2efd9d9d1c400b1be30c_arm64 as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:ddfcd7a87576306c460973e055aa4cc592c8240387e8e391b5cfe79810f42d82_ppc64le as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:ff3090c12380fbd77d9e6932395658624332c0ef37498a608332f89dcd82a630_s390x as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:8938c8e6627cc3065ad04d5dc3eb29114de2c1fc7a13b49204f0103bbb0411c8_amd64 as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:085bed6a41ccdfcc6a12f1156171c9c53c9f3c7c25b660b8f5cf482f5a3f76b4_amd64 as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:7ebd83b265ed7bafc8461909844f8d7cdde691a3c69a5dd6646adb26b281ca8e_s390x as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:b22867f265404f708b8c920f351b5c0e0afe02ab4aa99dc28ed7232ad70a5981_ppc64le as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:c6b8fdbc7880fbf5473375970fa34430ab5607d8d0a3da27e61bcfdc7fabed54_arm64 as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:749ad711d2e6d877684eff67674dafccac43d15ea372fcd5898d2eb53a1767e4_arm64 as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:7cddde99d5db412a174f95bc15f568d4a2f7ecf3c00736ae777414ebd28d7efc_amd64 as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:c00c88c6bb1adfc7b06c930e30121cdc9ec783ca88582789d7844f399f1a5730_ppc64le as a component of Red Hat multicluster global hub 1.5.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:edd270e4b896aa26e6d7f5b4a8a8cc0143bca3e8fb64c232dc09b238a877e8c0_s390x as a component of Red Hat multicluster global hub 1.5.3

✅ Remediation

For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.14/html/multicluster_global_hub/index Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, explicitly specify the intended IPv6 address mask—typically /128 for a single host—within the Grafana Auth Proxy allow-list configuration. This overrides the incorrect default /32 mask, ensuring that network access restrictions are applied strictly as intended. For RHEL: Update the whitelist directive under the [auth.proxy] section in /etc/grafana/grafana.ini. For example, if ::1 is the desired address, configure it explicitly as ::1/128. A restart of the Grafana service (systemctl restart grafana-server) is required for the changes to take effect. Workaround: Audit dashboard-level permissions to ensure that write access is granted only to users who should be able to modify each specific dashboard. Revoke per-dashboard write permissions from Editor users who do not strictly require them. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this issue, Red Hat recommends only running containers from trusted images. Additionally, users should avoid piping compressed archives into containers created from untrusted images. For environments utilizing authorization plugins, restricting access to the `PUT /containers/{id}/archive` endpoint can further reduce exposure. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available. Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path.

🔗 References (17)