Red Hat Security Advisory: multicluster engine for Kubernetes v2.8.9 security update
🔗 CVE IDs covered (17)
📋 Description
CVE-2026-16242 — hypershift: Konnectivity proxy-server accepts agent connections without validating client certificates
CVE-2026-17107 — cluster-proxy: cluster-proxy: Impersonation header injection in service-proxy grants cluster-admin on every managed cluster
CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries
CVE-2026-29181 — github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Denial of Service via crafted multi-value baggage headers
CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey
CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation
CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass
CVE-2026-45447 — openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
🎯 Affected products109
- multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:5a0702c3c3d088bb774c5b0e9cc2e48d92581d33a10446a05f18c72f6df837b9_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:67d425c91a8e56db535778086bff18efe33d90ee10ceb4e4c2a3dc713123e7f1_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:9a403df05958e9063415fe0e84d7a7ac9d9facb026472ab33f56fa59308c692a_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:c6aecc60f95e292897ac5c337ac8cde89828d7d0148b1b9f05bb75ae3d9d47f3_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:4a6e8639ee3e5069f2aad866acbf03994fc3a9d668ff10e9bc7997b56ceb1609_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:5d0bc8f34248f3ebb74910b9b7f2d3a9627f44c7b436fd1b5c195c40e2dbf6db_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:9d35d186e2f8744c7f160fdd95448f8d74e29a705fe0d59809611388a6a2f2a9_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:f5eecd0d2aae93c09dc7a9d9c9c21be6bb1b9414b532787c851d0074dece3af1_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:0949c13d5ebfe48cf1c9883e545dfd80a9f1d2b065aa71b0eca2699028208187_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:304eeab66005c5712deb46cc48de5f0f19f79b21629364f72340351edb8768e0_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:d9b878dbf396a18cf7cfc29ce96fb0f55225fada969c14d4503944f2af6066df_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:debf14c25cc30f66440e329131fba3d2ac2e9cdc71b8fa293cdcec7ada7ef386_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:45f0787d5edd242ba4ef205975a085bc405d9e2a791ff2eb9f85fe7040646595_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:512d5d7f218a81bcb9469cf187ffc4731a6da970a525376e201ac5263d5af331_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:7dd351693ab329a2f34cd3b081f6232aee512034bbdb8dc4c46b6cf3e2293d53_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:c7e0ada1136dcc9dd8e2d5a5b65b9faccbf4c594d9131d3a6e32e1c5f8fdeec0_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:1b511bf48e2d14e6512bacd2f25e3446e617eff32cc4fdc0d0f0934ebd2274f6_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:1f42aea03c5fa6dc65d4ab39bfc4fd02b302f2432f14dc24af76e53d22441a06_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:3cb716d71347eb7c6bfb462b2186a8052c99df5a6676e47602b998e1990ce960_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:bcc7da879cd2b6b13b76ad1ea8fe8720582b609121bd3a45d3c60d97a6d3403f_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:72510993f9a641fb4757820784cdef1f1686e3d13a53f3582d8effce6152e0a2_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:d882a6916930992429f816cfca119f46076403c61bb436550be70c05b7ada8e9_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:ef0e88f2715e347a15c0bb9e0f66ac28eb315c69a8016ddfa117193c3e79155b_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:f9ff88db707a5dd40514f7fcaabf2113dd1821049c62b921b4d1b0478ef25880_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:2c197ed8c197d27d7b57364130c9a15b9c60e7b13163909e3ebf00db8f321ffe_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:6e59fb4a06394dac0a0b30568c80380a1e0dc2bb0f1af3cbfdc9666814c77a55_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:72f91b33bcbdfa76f08c9291f79a964bba6685df0680bed4f5b3a5b74e35fc2f_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:bf94211e48693b7e233b75f05f7e3d2370da317fd2b6a46ff7e96c752c61935b_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-proxy-rhel9@sha256:43b0023994c97622c4777d1a41ed26b2d8e5136c80d58cbb73d9405f37c8c9f7_amd64 as a component of multicluster engine for Kubernetes 2.8
- +79 more not shown
✅ Remediation
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/clusters/cluster_mce_overview#mce-install-intro Workaround: Until an update that configures Konnectivity agent authentication is applied, restrict network access to the Konnectivity cluster (agent) endpoint so that only trusted worker networks can reach it. For NodePort or LoadBalancer publishing, limit ingress to port 8091 to worker node subnet ranges. For Route-based publishing, restrict access to the Konnectivity route to trusted networks where possible. These controls reduce the chance that an unauthenticated attacker can reach the agent listener; they do not replace proper agent client-certificate (or token) authentication. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2026:47735
- externalhttps://access.redhat.com/security/cve/CVE-2026-16242
- externalhttps://access.redhat.com/security/cve/CVE-2026-17107
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-29181
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-39828
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39830
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-42508
- externalhttps://access.redhat.com/security/cve/CVE-2026-44740
- externalhttps://access.redhat.com/security/cve/CVE-2026-44990
- externalhttps://access.redhat.com/security/cve/CVE-2026-45447
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_47735.json