RHSA-2026:48913HighCVSS 8.2

Red Hat Security Advisory: RHACS 4.10.6 security and bug fix update

Published
July 30, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-41889 — github.com/jackc/pgx: golang: pgx: SQL injection via specific SQL query conditions CVE-2026-49478 — github.com/sigstore/fulcio: Fulcio: Server-Side Request Forgery and Kubernetes ServiceAccount token leakage CVE-2026-49978 — dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution CVE-2026-50163 — oras-go: Oras-go: Information disclosure and arbitrary file access via crafted tarball hardlinks CVE-2026-53492 — github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration. CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents

🎯 Affected products48

  • Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:ae9a852c7b15e5ad0bb493cf9b808be18847ce07502a5c663d087a80bd47f3c2_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:b1757ef2d73e04c7675b32149802cdf1b3a89f7953d64456436b8549cc794296_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:c19b4e2ae18ebcf75eed8adf8d70269b9013bd79b652a36aa7ddc5267f8cf8d1_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:f8938440faec7bcea67d6434dfc77e20b96f76530f31d86eed62d92de17eb176_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:78cc429e1e2f1ebff70d4fb2e703423c7237a41d2a83bca8807af57f07d91967_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:bdfa798d7de5921e1fa635029fc9a8013bc7e431e2c217096cbff4415822d1df_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:d249a36632ade0b88a3eaf8e4489d26835104ee46f451880d0178db74e66105a_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:d595dda762a290dcc82f2fd1ed0f332b84f8a279ba98a12082bd49841507da97_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-fact-rhel8@sha256:d4802a880ece2d2af9b67e047690cee05e4d9bf2819f8eeea115bbf0f695d487_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-fact-rhel8@sha256:e1eaa504db4f91a5daa9308be177e72f1871ee4ca0ad97026fa2cfdfe0e916de_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:2cd067c86c7d3297a4f9324b31950e844e699ab2375ffcf1547a814e5831b3ee_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:6285a6535f012775f552442253463881d510e933ee575b5c7fda649e8df3c536_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:75be60f007da174e37b146a46f0b34c8fbee80573a916539147cc435ac48e77c_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:896b1a826f67e9216b7d46f35def353293c8afbe1a124cdd8ec8aab0f1c0797f_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-operator-bundle@sha256:96c59bb24164e747ad5e83d9f118b2da8c485f6a3dd4f7533a45aea91e9fb163_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:17087208e550bbf1a580a72752f20f7b41ae1103313cc1485678936dbf3b7beb_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:98aadb3874793b6e9af3c198e6e36f98489e3c28812592975c9923a3a7e3f5ec_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:b8614627ab29a2364c61a551c1268526886adfcb9e26aa13aed212b88960fd1a_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:fb741a4e3f0fff301230aaa29cc4bf4dc3980243df1940ad094538e6596fcb7a_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:7c03d8a0fa0997be48acb3f0e4ab72161b3b106f8907f2c55baf5784d78118f4_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:a15bc27b2559d36723fccd0146920a31d9d9fb04a99d07bca2aaf82644d1182c_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:c49fcf244af24ab354e7485561cf498072011d473575992c49516ee52b919841_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:e0de840202049bfcf9158c119bac7c683157ff6fde30ffc36972f83074d40ccb_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:06673c36a28c208d24b95ba61e41c807d4dd61de335a669acc3a6c94b57d2f4c_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:4b4dd652cf5539dc053d1f07f36dc7b7e795c3d1459bf45fc73bb1c928eb222d_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:aba89f741dcd67cfbf6718476aa18d3921fd023792f6542c14e4f4e59e72eb0a_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:cdc3ecb02a0f07a2573d6c20ace878fa58d53b6547d082b461033f66a0616b33_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:260215e4068708476b494bab6c69f63718c9d40c248205497beee709c0a37203_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:67ae19613df612b61395c5288fcf5fb4abc625db2067079ee1d68e691917f568_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
  • +18 more not shown

✅ Remediation

If you are using an earlier version of RHACS, you are advised to upgrade to the version of RHACS mentioned in the synopsis and release notes in order to take advantage of the enhancements, bug fixes, and/or security patches in the release. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: Avoid using the non-default simple protocol in applications that use the pgx PostgreSQL driver for Go. The vulnerability is contingent on this non-default protocol and specific SQL query constructs. Configuring applications to use the default extended protocol prevents this issue. If the simple protocol is necessary, ensure that dollar-quoted string literals do not contain attacker-controlled placeholder values. Workaround: Upgrade to Fulcio v1.8.6 or later. No workaround is available. Workaround: Upgrade to oras-go v2.6.1 or later. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations.

🔗 References (11)