Red Hat Security Advisory: RHACS 4.11.2 security and bug fix update
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-39822 — golang: Go os.Root: Symlink following vulnerability allows directory traversal CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-49978 — dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
🎯 Affected products48
- Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel9@sha256:1d373af6ff6d0304d519bdf48fa985d72b1052381dec1baaa87cd6420ebb93b4_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel9@sha256:5685a71649cd8d5c572a346976b68a92bef7bbf58d5f38912eb40abaf24f0739_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel9@sha256:579d53ced5dd623da09da66fa073af9ce61cf7f077e395172d97dddff5ead1a0_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel9@sha256:ad568db39287a055021705502052f97c655c3a1f0a1fb495f62fc083f7e769e4_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel9@sha256:07378851bfdfab080408d29168cbd9ae71ca59daa77193e40b98c4bffea20c5c_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel9@sha256:3312a3f15c8417733c5d7eafdd90183bcd9fb04244a1918081f3b2a911875953_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel9@sha256:4689503392ae616b2ff49acd932921b36224355a5c2aba381ec487f58316f1da_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel9@sha256:561fc0df6908af302050d45d43c7e93fbff3a4185be5124b12fc5fc2640182c2_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-fact-rhel9@sha256:8110a60431013e5e8b714a2f135c1625d7f2dec483223a6c79ec23c39cd1229f_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-fact-rhel9@sha256:f4a5b11fe3db09e4eff51f04538862e7f32976509781de2197caa79fdb4465bd_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-main-rhel9@sha256:11f030dff5b5865966d159d8d60d759c9fb7b44227a83600c9350e4c769b9278_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-main-rhel9@sha256:75ad887f42a73e4a96e9ff71d4cad3d17a23921a637051f0eb80e2bdd278b89b_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-main-rhel9@sha256:90fadbe8122211a31df7ed708236e1cee61cb8da2d08926f2012d7370e6e2622_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-main-rhel9@sha256:cb0d755742c975b2cc2757764d7c3a29977601cbce7b29e2b1f9f5c215eded25_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-operator-bundle@sha256:a54d7087a3af9b61a1cbddda89b5d4b952e4d5e7341ab9c61495ef9c33305636_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-rhel9-operator@sha256:4b18b1c625609954f9e6074bc1a36299dcb5b280d1fd42ea92fa4077ec8bfffa_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-rhel9-operator@sha256:55e02f87b35f5a131ff1892692fc66339d142085175f69390aec1d171646fc57_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-rhel9-operator@sha256:5dbe2daed4f0ba6a6c43d3ed154ac4b738c29ac4f2c5be1550bf30f1e3be9347_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-rhel9-operator@sha256:fdd42cda6726ea86d75c82a691d026bb1000aea3f1bc1cff9c6c0a541f525ea6_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel9@sha256:1e7ba0f698480c49662c6bd29b8e27bee8ea903b2bac207b4302787ed54e1e49_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel9@sha256:4fbf9e7f3eabfc008497d3d75081e688f019759904516171f01a21e93541e7d0_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel9@sha256:6744519ca6a8679c5f47db2e048f5c9757944eb901234a95f740edf011e5b2af_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel9@sha256:ee7e48afc6473ffaf45cde59c98cd4290427f293329051ef1a4bfc26559e8d12_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel9@sha256:629cfc63003d93804f6938b968ffbf723fc380e4db71df9d76c5ac4d6ef4bfcb_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel9@sha256:79630c5fc9293984a658cef24ca2c6b8e36ce907296ee23e777bfa06ad4d4a29_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel9@sha256:c26cc5fdc89a7c75090c4c11f4abd0a2046872a1271a69a4a0af54b0a6eb0038_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel9@sha256:c51aa966ebc260b6920c10dca7cbf80a304c367ef0189c5aefbe9db36e045c02_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel9@sha256:0106d6ecefd6f4c87570de249c2d49491e01d05ff39f7c6cb39ce9322c8b6d20_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel9@sha256:0870dfa372f0029ba90bba9d270afe3b730262180ad970906991a8450789ccd6_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
- +18 more not shown
✅ Remediation
If you are using an earlier version of RHACS, you are advised to upgrade to the version of RHACS mentioned in the synopsis and release notes in order to take advantage of the enhancements, bug fixes, and/or security patches in the release. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: There is no mitigation for this issue other than updating the Go toolchain to Go 1.25.12 or Go 1.26.5. Programs compiled with Go >= 1.24 that do not use the os.Root API are not affected by this vulnerability. The os.Root API was introduced in Go 1.24. Go versions prior to 1.24 are not affected. This issue is fixed in Go 1.25.12 and Go 1.26.5. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:48891
- externalhttps://access.redhat.com/security/cve/CVE-2026-13149
- externalhttps://access.redhat.com/security/cve/CVE-2026-39822
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-49978
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.11/html-single/release_notes/index#about-this-release-4112_release-notes-411
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_48891.json