RHSA-2026:54427HighCVSS 8.1

Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.15.5 security update

Published
August 12, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2026-14362 — github.com/hashicorp/memberlist: HashiCorp memberlist: Denial of Service via push/pull state handling CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input CVE-2026-66805 — console: console: stored DOM XSS via unescaped pod logs in document.write

🎯 Affected products185

  • Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:081e80d92fb4abca986fe555fecb5a1089c2ed884a8b06c673c2d9a0cba28a7d_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:4b59a91b0f4f0ee348074558411ac5a06b6daf80f281d82de78fefeb4cd64c2f_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:726d3185e3ec8b19448a515529b784c0fd115fd97f53598703b4e9efcab42c72_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:8c3a0c275df66554cc7580127847f8a25e1a93a37b2bc959c6c873fd56036127_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:6b4b56de6aa091ac87ce8a8c3beb2d82a5a019f2e1f6ff9f0ce220050d19d447_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:ae6aaeae3e16c625db66c742f86f8743324cfd83469fd7460f42843f558cc596_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:b5fe209b755e3b97a968bf0dec2b22288c6a28f342ccca5afb9927dbbb5a8488_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:ea647473a29becdead38ce07c20a3836dce6b9c4355b8ec749fa6c8fa01656ff_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:009192d26ff0422301cf1161cd7df863be8a69430a3ab02ce90711f56bd06739_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:2c5d51fc1a581737e92a337bb534f7e5a84ee51ab66c6db04fc5fe07a50bcd3d_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:52ae03ffbd554c183c46d7c06feb3e7f64d11a3316beb3a180b9bf2c796b054b_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:9a3735b27a0b1e87f1008d20a5d26ceaad4aed91fb2d0387dd304f9e9230abf1_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:222033b1c86d40c7ca2eec6a1668b097923a7fd03154380fbde31d7495a81464_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:76c04f4014f8b72600be2927ab294ef92528cc5ca68b75f0c3fe476b320e5e9d_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:d7a7af28b169f38e7dbff61c6a4fe8651e034810865ebc1a617d7d9a1df1b84d_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:f39e9bc78ba578522003b66f44c227b3cf3ca49f41e3d53c40a7eacd5b04ed3c_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:1983c2581c6f46370a18e04b822a987a9326f3b80983ca5a659a17aa034b7ce6_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:3829e6b7eb9c10742356d68e0cf2b6761697808976af08bd6bd635da9ba521ad_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:6cb786a7b9b60606fc87c2cdac198740248e822250f7522015665d7389dfa077_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:784c610aa01dc829d1352d04585a759013ecb573c6645d19f9167c76f40b6413_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:2ce6bc821b132a01d05d6d9bd3c1f8030dcaf25307fb48ae53ddcf126c57b034_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:7a240591bd0cef0773f1cbe2fddc412817194d3f33ebeac34ecb3ee1977ad65d_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:a766d7433ea19b74e4584f038883546cd9e0365902924ea8e81955cd1f620f8a_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:e983adf2ffdcaad13f4aefb295df3f0c32008b1c98de05a42a36473f10b1eac9_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:0f7807cfa4efec2e3cbda82ab8200d0059c6e6308fde7707bac0c6b39df206e2_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:65c19f431c6f3c7d0dd91e2d8a5ee8621be54b0ce63233382473d023fb2ad71f_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:e2c1d1e4857fa8669dc6055295acb6fbfd9255d0002f74f462c5647291b98d37_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:e439078f9f17194417623ca25787d1a6b55d65083298b419b692c02a579413db_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:67dda827430141da9260addae0484b63d0526d2d4a69177e9c90850627a6792a_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • +155 more not shown

✅ Remediation

Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Upgrade github.com/hashicorp/memberlist to version 0.6.0 or later, which fixes the push/pull state handling issue. As a temporary mitigation, restrict network access to the gossip port (UDP/TCP, commonly 7946 or 9094) to trusted cluster members only, e.g. via network policy, firewall rules, or security groups, since the flaw requires network access to the gossip listener to trigger memory exhaustion. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: To reduce the risk of exploitation, ensure strict access controls are enforced on managed clusters, limiting the ability of untrusted users to deploy or modify pods and thus inject malicious content into container logs. Additionally, users should exercise caution when viewing "Raw" logs from potentially untrusted sources within the hub console.

🔗 References (12)