RHSA-2026:47949CriticalCVSS 9.4

Red Hat Security Advisory: multicluster engine for Kubernetes v2.6.13 security update

Published
July 29, 2026
Last Modified
August 30, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-16242 — hypershift: Konnectivity proxy-server accepts agent connections without validating client certificates CVE-2026-17107 — cluster-proxy: cluster-proxy: Impersonation header injection in service-proxy grants cluster-admin on every managed cluster CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents

🎯 Affected products109

  • multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:0285559d1ba4a1006c38fd757489e78c0edacb5bc42f1037f59cce2dd6ef9e9c_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:1692f5d5ec43b8c908243ac6f8628d17341933f25e1e5a53f5c279a2d93e97d6_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:c1d92a020bae5c00e04604f0ca6bb3f7d327410799c1332e9fae7786bdf1fb29_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:e0abbf7070dc25c3e7ea111d3672bb2575db543c39809eb30516a5dad9ef4777_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:2a277106c9b2acfaf89bbd84c8a974f5efe818812193f07656058063028ec5c6_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:30cf9f892c01a468397be3ce802866eab7bd11337a14e9cd709e57174a5f0148_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:40950d8c795d570bb80eb2ae5d3f7cccb1d5c3e9f6f74836635a843cf4243141_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:d46c2c311aa26edd0d18ff71cc199c28408f9fc9286c96c59d6800ddc6e7ec03_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:48ab4b1d5decfa1b2dfd24632d6e175c090372469ad31db1eeecbd96532005ac_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:631dcfe7186760eb5120d7e45e5ff0835d3b42af5d16aaec1314aa5e35682cfe_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:c4a63170383e42285bdc7a6018714c30553887897af4cbfb8ba9894a0da0e04c_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:c6f49643d6e7d962af0a57505daa1b7e2be10c7dad88ff133f46852e1649b206_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:09f85eb57abbfa147d7ade8d3372e0af7ff76496959334728f45efadfb100902_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:3bb4350f81f0512ed3554b3f3bd8113ff3172469148240d4694016da0fc570be_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:48509a26cad00ecaa7c2daffc16946c03dc99e8f61a911498d5012ee1a7e07b7_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:72277f2871056a0446b952a5887669e259a6392d0745aa93c75afda775008c4a_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:18bff3da8026ed552530a8aa200cb6d063f60c46bded9cefeee1c893fb49293e_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:8fa5951d6f07742baf0085074e4b31a5f56984650e692141fd7671daa7accce4_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:a087e9ea9267bd76bb3c9d2b91f778053dd2e021d4ea4c6e6b7a7561e7a7c1d5_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:b1c0531d53968af44c9ff208a5ce409f053c1332b32d265268e692d472de4566_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:427e80920a50b0e7ce023f8cc9809c72c8313a318cbca92528ba1d16285387ec_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:74285c8dd92c4b921b1a57ab0d7f2dabf6cd279ae422154c098f28f53629d448_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:bf71a24ce4cd38386173aad504b6a86d0d29c665684c48f64194e2babcd001e3_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:dbda382a9df7482cbcd844793b3a023388e94ea4a292da230e068400bb0e7fea_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:446557ca88e5b1223f224af8b77437e5396c1946acc30e55034b531bb841246d_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:817e64eda0391d0b6283a899a2365e91c6aea030de50e648d8de6e43f383b6cf_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:a61cd975697698d8610da6cfccb2f8e73d04358a0d5ad8498421c1eafc54edd6_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:f0cc0d43f4367d1f3852065cca7940f75f37a0e12748dcd1dd06e24ea558c9fd_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-proxy-rhel9@sha256:7255ba328e0588c7bee888a5c4d0bc5bcd8685a909f20ddf7aaae9439661513e_arm64 as a component of multicluster engine for Kubernetes 2.6
  • +79 more not shown

✅ Remediation

For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/clusters/cluster_mce_overview#mce-install-intro Workaround: Until an update that configures Konnectivity agent authentication is applied, restrict network access to the Konnectivity cluster (agent) endpoint so that only trusted worker networks can reach it. For NodePort or LoadBalancer publishing, limit ingress to port 8091 to worker node subnet ranges. For Route-based publishing, restrict access to the Konnectivity route to trusted networks where possible. These controls reduce the chance that an unauthenticated attacker can reach the agent listener; they do not replace proper agent client-certificate (or token) authentication. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.

🔗 References (9)