RHSA-2026:46885CriticalCVSS 9.4

Red Hat Security Advisory: multicluster engine for Kubernetes v2.10.4 security update

Published
July 27, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (22)

📋 Description

CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2026-16242 — hypershift: Konnectivity proxy-server accepts agent connections without validating client certificates CVE-2026-17107 — cluster-proxy: cluster-proxy: Impersonation header injection in service-proxy grants cluster-admin on every managed cluster CVE-2026-33747 — BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend CVE-2026-33748 — github.com/moby/buildkit: BuildKit: Unauthorized file access via Git URL fragment subdir components CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents

🎯 Affected products125

  • multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:136c6a753e310e7e6809ced784d2d5226947b97bc98e07e6792d2a7ce972660b_s390x as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:278c42f76c9470e4c7533c059c362a5038e9b05494c9b58921eab0f61b4183bc_amd64 as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:4586d6c013397c1df40c2891772e6ef6f4e062778665512eb9834f2a421709b6_ppc64le as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:8bf2e603771b91e76df3be8485acae6a502ec9269e0c40006cd5376c98cea909_arm64 as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:3ae1bdf41b805f83117d9b25de06a6839813372a09ef50aab1efd1ff21b7226d_amd64 as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:9c379542f01419ad790e638e173ede790714f89e3a84c5cfbed915c0d34cad69_s390x as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:e4b9c600b35147042a02789e2bbf4f89733e8fd06051696fc4283fa33080cb88_ppc64le as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:e55a2019b89df55b01dd091d2e237d9f76062d0db4e488ddb326956e4d2d4d99_arm64 as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:4caf5364db9009959ef955ef9d7214b050bc687f4000681ca1bdca86d55f789d_amd64 as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:6ba3b38b6abe5faa27d4a7142db92a73bbae3e0ae3c547e741e6b254c589deb6_ppc64le as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:78c38d89c9cdc0bb52077fffd74bfc06157b9da1bed85918f03951b5d02ff57e_arm64 as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:dd602844017c8c6273a64bbe0a855dac4b323ca93c7446cbc30dc60e19c1d4d1_s390x as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:0d2fb45f17f175bd73a95efaa693e2c7aae46d404036c10a0f4e05ba3bfe0a18_amd64 as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:0eead9eb76feadd64ac02d8c91cdadabc62c42e9ec7d207981800acbd998d7cb_arm64 as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:742a5253021aabf72b9f79a4bb808e53d5528fa013fc8c4b7c3a17987acb8bac_s390x as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:d9b11eb494abdcc303afce6c7af677970cd7aac128502331bd4d0915992499e3_ppc64le as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:18941248820aeb151a8aa2057dd307cd1afecc88aee07a08e40868943342df3f_ppc64le as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:73a5a073ae7697113a15a6233094170720b342e7314426b4c441aea0243f78c9_arm64 as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:a749a8574f96973399020db76bae72b264daa4abbef8e26fecc0bd742f31f1f3_s390x as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:df8c54f538d078ae8ee2a093a8d549d4c3b9cd4f1e9e5682106546ac920d49ba_amd64 as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:1d39d1daf3a30f31bffd2fb7f3b2864ec2b3ccbb77d59166c3582591dc7e4716_amd64 as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:65855fde9a1b726d0a2d9c4c7c9684df3b6683f76c0e9ba11fc46297d99ef20d_arm64 as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:7fe95e8be415d1a0fbdf0874d27f5e1b233624c1fbb6dd9d992af3f52300ee2d_s390x as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:867a2ad4cbead1fd6033c4f5951699bbe9b9b50c050379c96cbcbcef679ab553_ppc64le as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:00c71f4d0611013a0457cbc15312f0670038d8aa91e02913f063850c7cc5472e_s390x as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:4096a2f3e82f4d8ea07bd0560d1da4a8b631867465ecd4d1efe4027eb49794e3_arm64 as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:82d8a63ecad453c6a46bd1f8a64d263a5c8d77e5abb25a35008e8c2ee4e385f0_amd64 as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:c0344283fe0d1db8232d0cc868d4ae8df482069239fb9b1a7940958fe3fc4440_ppc64le as a component of multicluster engine for Kubernetes 2.10
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:0accf3514a20e1c55f87940482239940e24d0890a90710a55d4eca1cc8a52236_amd64 as a component of multicluster engine for Kubernetes 2.10
  • +95 more not shown

✅ Remediation

For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.15/html/clusters/cluster_mce_overview#mce-install-intro Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Until an update that configures Konnectivity agent authentication is applied, restrict network access to the Konnectivity cluster (agent) endpoint so that only trusted worker networks can reach it. For NodePort or LoadBalancer publishing, limit ingress to port 8091 to worker node subnet ranges. For Route-based publishing, restrict access to the Konnectivity route to trusted networks where possible. These controls reduce the chance that an unauthenticated attacker can reach the agent listener; they do not replace proper agent client-certificate (or token) authentication. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this vulnerability, avoid using untrusted BuildKit frontends. Restrict the use of custom BuildKit frontends to only those from verified and trusted sources. Do not specify untrusted frontends via `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.

🔗 References (25)