RHSA-2026:48872HighCVSS 8.8

Red Hat Security Advisory: RHACS 4.9.10 security and bug fix update

Published
July 30, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-41889 — github.com/jackc/pgx: golang: pgx: SQL injection via specific SQL query conditions CVE-2026-49478 — github.com/sigstore/fulcio: Fulcio: Server-Side Request Forgery and Kubernetes ServiceAccount token leakage CVE-2026-49978 — dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution CVE-2026-50163 — oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin CVE-2026-53492 — github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration. CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents

🎯 Affected products46

  • Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:0dbe34f8f684f0fa98bc40a85a2d22ac06f6c92ebf19d1d32e4544a15012011d_s390x as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:101fc7c1f78b9c024e59c89ddad49734de271c01c0c9cc74b440632bf2c3125a_arm64 as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:7a768baa1d550f4e200348b82b998e47dab787c2b9f01e77a09d8ff01a82b584_ppc64le as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:8669bcfafec38d9e49ce90a32def1eb74cfcbda54917d4eb1f8bb15d45e68c0e_amd64 as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:0072488e32544ac8727b3e29b0e60545beb895fe07a07ba3a608c19c925a71cf_s390x as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:735269356e2c466e7d6260e5f9b25da5fed4a63c03473dea9f9a98c5cd0b9d42_arm64 as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:d147656306796dd78887d039ca173543797c7c147c805f2bd5df15b3e4e8ba72_amd64 as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:df7f4cd58b44e51110370a866c9b66dbdcad7ba2d7ab2f6225e93dcb961dca0a_ppc64le as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:2361878517379a3ac144549d4240785758b46ef5b01421edbb2df9d63452c1d1_amd64 as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:349867ea5dec173408f68afaef3d57e556d09dea1b3a03923bc3a32c3d2dc96e_s390x as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:5a3c968f2c6bfb3cdfb23ac714069cfbb43222ffcb3bdf3b0d2d3d4425dbd56a_arm64 as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:9edd22028ee245414b20edb4ce65af446ff803207b883514e3991fdce67b71fd_ppc64le as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-operator-bundle@sha256:50473a07f0ee77e9ec073acb3f51ede534abeaf038f11c118223b81cc275c1f5_amd64 as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:2e2353e31fbe0379779fb67de39b06c43a0bff3a92199054d6f30e16b9ac0092_ppc64le as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:411711420af2f0f23c57818386a1bdb95440f7ff5d92cf127b21b365e3d6aca7_amd64 as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:4271a771fc35fa9c7aa1dba298e6d658337f3fab66c6a99625cdb8b20d11e4bb_arm64 as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:4b5eb6d15de1e991844f20c4a2bc3da5c62d066ba9bafcad9128ac8aa481bb59_s390x as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:1336ba26d203bf1c7d1f590fd421f5291a2d85f0effbf4710952777ae0013022_s390x as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:56e4b785fb29de9f189d64439299ed46324949dfc0803f7a6f7187bb1c611be1_amd64 as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:a1fcac216ba5635e4bc0cdb696495b88eaa9a9ebaf3cf4612bd687f54c375051_ppc64le as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:a86f0955aad8287ad7e9dcf5822acd59b81373d6626a88c825c4e1e303b90232_arm64 as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:2d20588e20a4333343ffe47e562ad49820728d8c4e578b1da438c7d67b593523_s390x as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:3d20aee1035d840db2e8cc4ea6586aeb353f7cdf0209f8aa4009027517afe618_ppc64le as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:b75fd2452538cd8d586742dd99c7171ce2c1ee4930ae29c0d241cb529a0ec350_amd64 as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:de53c9e13e684f5b26db84671093fdfc466a921d81867674196053fe82a8b97d_arm64 as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:08e0e328657fc62e89c424e82e82d85d975e2eaee80e122f2ebca770d3c8795a_s390x as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:7efc69bfb07aac91ae8e4022d667927ac1739274ffc2c4dcac0bd20bc64bb428_ppc64le as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:9761a210a1394c88a0c30dc160e81c559c8c804b1aa06e59aad3611ba48f320d_arm64 as a component of Red Hat Advanced Cluster Security 4.9
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:cb1791615523a2e53e6b424417e917d61bc988ba8146cb3767e23c0a1b588afc_amd64 as a component of Red Hat Advanced Cluster Security 4.9
  • +16 more not shown

✅ Remediation

If you are using an earlier version of RHACS, you are advised to upgrade to the version of RHACS mentioned in the synopsis and release notes in order to take advantage of the enhancements, bug fixes, and/or security patches in the release. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: Avoid using the non-default simple protocol in applications that use the pgx PostgreSQL driver for Go. The vulnerability is contingent on this non-default protocol and specific SQL query constructs. Configuring applications to use the default extended protocol prevents this issue. If the simple protocol is necessary, ensure that dollar-quoted string literals do not contain attacker-controlled placeholder values. Workaround: Upgrade to Fulcio v1.8.6 or later. No workaround is available. Workaround: Upgrade to oras-go v2.6.1 or later. Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.

🔗 References (12)