RHSA-2026:44622HighCVSS 8.8

Red Hat Security Advisory: Multicluster Global Hub 1.6.4 security update

Published
July 23, 2026
Last Modified
September 15, 2026

🔗 CVE IDs covered (16)

📋 Description

CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-33376 — grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default CVE-2026-33377 — grafana: Grafana: Privilege escalation via dashboard overwrite CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-41567 — docker: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-43870 — apache-thrift: Apache Thrift: Denial of Service via multiple vulnerabilities CVE-2026-46384 — github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: Integer Overflow in Avro Decoder CVE-2026-46385 — github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: CPU Exhaustion in Avro Decoder via Unbounded Block-Count Iteration CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin CVE-2026-53492 — github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration. CVE-2026-55677 — github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy

🎯 Affected products22

  • Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:180cae1153b4147f4bde808fa626ce8d1970b11714bcffceed4beab911133ae2_s390x as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:3386cafd13a0483523176f34c1a0ff5b1d3bc3f99f16504eaf4f250ec25aab1f_arm64 as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:6c4c5ba04f69becfcdfa348fd79ec31e350bc9b3d6a49a5bc2db372852b25c33_ppc64le as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:ba8baef02a1434c484823b4a913daab81dcc2a590aedad6296e790848522a733_amd64 as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:195e3f89eee8e33fadedb701918846da6ab1c9e0edf23718e0bf024995f09977_ppc64le as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:21ea61d1524280f483fe2b55f17d4d5510c21e207c6403fa4e5e248f39f70b5c_s390x as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:e7aaef898bce215f645dc0b8e28414509bf5dd5805720c6380548f1ab32907cd_arm64 as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:f7c4bbfa958c00f1f43e8d4470c4b11ee7c5558e1f2df707ca45e179370c3103_amd64 as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:ae7687a09a81bcf3e2ebe5e3eb08eeddcd600fee1c029a65d99f856084496e1a_ppc64le as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:bbb16ee5a4823ff1d28b7e8696c0dfef512b56421c71bfb3d62a61c1279bf6c0_s390x as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:e9b6deffc1ea8be6e26d391f2d11be1391151884fff5c41be3b6cd65d07b7fd0_amd64 as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:f4184cf8175d4f48ef1ad3fed2a8c337a713a01115ae00d27af199246b920dd6_arm64 as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:2e53eabb0d89de4dc25f6575124918826b066da62f149b71cde4ebb6e806375c_amd64 as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:199581add540c329289b169a80c95ffd3fa56bb0e504ca2c2723ef7297b7910f_s390x as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:2bf5a1d79ec3b811cd70156ad6476b3c5519d17358f24c0d0fbf5118793bb116_arm64 as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:3450dc352b5b27412c5069896f5fdb2f3d1a0085a3947fd21e30deef90c09392_ppc64le as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:eefe132d48f531b38e721a246daeded5f0b7d4616d8f9ad0c16cb128b4812b86_amd64 as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:3641c6586eb7c7c808dd2a90a51b0659112136189fe71a392fc1a786df647da9_s390x as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:40c094dbef73513e773ac085242e20cc395591790ed103937a178197ffafab50_arm64 as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:43a86eefdd0fdc6fc7e2958138e27979d64443f564d1c32bd92804de96546c6c_ppc64le as a component of Multicluster Global Hub 1.6.5
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:f356b6ca990f7fb11fd1ada512bbd01f17fa48690b801214c2785dea430d9d7d_amd64 as a component of Multicluster Global Hub 1.6.5

✅ Remediation

For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.15/html/multicluster_global_hub/index Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate this issue, explicitly specify the intended IPv6 address mask—typically /128 for a single host—within the Grafana Auth Proxy allow-list configuration. This overrides the incorrect default /32 mask, ensuring that network access restrictions are applied strictly as intended. For RHEL: Update the whitelist directive under the [auth.proxy] section in /etc/grafana/grafana.ini. For example, if ::1 is the desired address, configure it explicitly as ::1/128. A restart of the Grafana service (systemctl restart grafana-server) is required for the changes to take effect. Workaround: Audit dashboard-level permissions to ensure that write access is granted only to users who should be able to modify each specific dashboard. Revoke per-dashboard write permissions from Editor users who do not strictly require them. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this issue, Red Hat recommends only running containers from trusted images. Additionally, users should avoid piping compressed archives into containers created from untrusted images. For environments utilizing authorization plugins, restricting access to the `PUT /containers/{id}/archive` endpoint can further reduce exposure. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available. Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path.

🔗 References (19)