RHSA-2026:47451HighCVSS 8.8

Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.15.4 security update

Published
July 28, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (16)

📋 Description

CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents

🎯 Affected products185

  • Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:14d93f00cfda9b2da624e5e85e484d0633ec4917a5309d5e90de1425d97fcd3d_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:6b6748d7a7b9bc239800249498572ade8ac30c8b6062f86bcd8b9a84854afe7a_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:7d96c87c3165fa78f212b49b7bc521d65174311899387472ada2de2e24e8f3ca_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:a76b2b069599a4510ebbf8905d1699ad8043db5aff2c9eef1451b2b813549a24_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:bb6786b1d2465f9db06589c445711323810674383207d3399b33b31f05c7eb75_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:caaefc0079169980c63dcd64a15fec26ad627e8538cea66413e132204b34ae79_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:ce8a41c2d46340a023c85ce17402cc261e03726e71db999bda1298cf85d17816_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:e5e2bd6d92393f65abd658a7a7c59f6473b209add1d782931e0d1adfd777d803_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:338b935f6089a54edab864a2bb2f7cbc9f05f3354c51f3e12267220cd7397e02_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:45eca79638a0071ca47ee12a70d34c0cfca7fb7054ff678e74a1ff401d94f1e1_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:5fc9b6f7c21821a09c80071538a7fe346e9e2a913f23532b937b2b762dad5ca4_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:681b742308cee62001f4549a883620a560c8a8812d7967889898be3edfe24a56_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:0da3dee0804cda73ce4eb1b6306393d73058f32aadc5f276d265aa5dc1531ff2_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:1e6fd27e8e03f38d71699f98f57035fe53e654b8dab124ead8ce7b6ab64bd7a4_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:794b1b780b6e2a3246b48d3e96c1245dbaf5ae3f9a58205df7154ee76cd5426a_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:b9136f99755f852e7dbf7ffe3afe4235beaef4977556ff47bbec019aba7163cb_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:2f4084bd82319855c6442399b0bf4ff61f8dd791d09d9d2cb93677fc5cfbd290_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:33714154f69fd17002cfa4af68b55c8b6293d546f4141b5c4b1c867675f28de3_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:446987f028d5dcf61ad4fe86c415148433caf3d79cc3386a2ae23e449a00c0fc_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:48b8b893c0c31fb931680dd0479a4c8fed52cf99e96ade0444b968e1b3642cd3_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:b20a94f0cf8d61b869115f6c89e18d205c92ae7bb003737cf52ad0fe0c59c263_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:b2dacf942a49172fcd3e9587a973048fcf4284b9064380b0a2e17eaf139dc4aa_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:b6066ba9828a79d40f2b1809d51af011c0ec32cf2ad50c62852188e734fd1965_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:c7b5d0ae3005c5bf205451f44ef97261c888afbf800c7155d847b16236ac5dae_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:9794cd7dbbaa9e478b45de8b98cf113b5c32d0ee4e7772ca3992b45e05972195_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:a0de8c0e1f7bc3128791fd1e5c64cc8c34e2b1e20e80d796823a6cd602e92aa0_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:b1ee83cb5f10eb29d58a8924e372040d85149b08cc4a3e41d83c341c6403a5c5_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:e5be9b894b7886245b48564484eba36e9c8d3006758a1f4d946567782c9e2dc7_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:9dab3732b7e17c1dba1c5cb37262a9f9b1a35d9e996e782562c09f360e5c862d_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • +155 more not shown

✅ Remediation

Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.

🔗 References (20)