RHSA-2026:57194HighCVSS 8.8

Red Hat Security Advisory: multicluster engine for Kubernetes v2.11.5 security update

Published
August 19, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (44)

📋 Description

CVE-2024-45336 — golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect CVE-2025-22866 — crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization CVE-2026-25680 — golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-27141 — golang.org/x/net/http2: golang.org/x/net/http2: Denial of Service due to malformed HTTP/2 frames CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39817 — cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction CVE-2026-39819 — cmd/go: golang: Go 'go bug' command: Arbitrary file overwrite via symlink attack CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39823 — html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content CVE-2026-39825 — net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls CVE-2026-39826 — html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping CVE-2026-39827 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via repeated rejected channel openings CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-39833 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation CVE-2026-39834 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service due to integer overflow in SSH channel write CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-39836 — net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-42506 — golang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing CVE-2026-42507 — net/textproto: golang: Golang net/textproto: Misleading error messages via input injection CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-46598 — golang.org/x/crypto/ssh/agent: golang: golang.org/x/crypto/ssh/agent: Denial of Service via malformed input CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-66804 — console: console: authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure CVE-2026-66805 — console: console: stored DOM XSS via unescaped pod logs in document.write CVE-2026-66808 — hypershift-addon-operator: hypershift-addon-operator: unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection) CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow

🎯 Affected products129

  • multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:0451628c58cb6738977a1a5499f204b07e8ab02b41e949b27b263fea3ea61f88_amd64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:3e9e3ef83f3da8d29471e8cc5cc0315f7b02dd44cfaafbd0b27f049d2efcc4a5_ppc64le as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:5acf929f44e14e1a1d229e0a4d0e0d68c592654435d0a7ea234c23d88e7da686_s390x as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:ba6c4a20a6ee685c319df030bd2774e9ff9747c0bea02df16c169f85b20e4ca0_arm64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:0f5af66d650b218e30c57aad3bd4d6c9d978a5fee42f5a8e4c3d6b792282cd9b_arm64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:49774c069cd6a4f2b3850039ae338fa0ff1da3f29a42990a863b6c93dfa30a42_ppc64le as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:de79fc015730adf4dce460ea07cdabc89b31537a36831bd85a3ed3cc0683307c_s390x as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:f480a9edc21d0cf6d2358a6847796ad8438bdb05151c1a263cbd61373b18908d_amd64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:27a860976c6e2d3839bd7748d55d3803fd3bd25363d54ee6c50f5fe56ef343d4_arm64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:5df15f8fe0f01ad4400f505bcbbeb38ac4389a2f7efce2852c94e088c742bc6e_ppc64le as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:77241ec4ce514b53eea74ecc7f7c53e59f9f992e8f9383e854ee8e78c7b0ef67_amd64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:ded50b49b8d04d0ffb844216115f7bee6ba3a10a6c03ece119335f644b2b0f54_s390x as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:374732a24d27236906d8de2d39932909aa662c770ede2d0adcffe580c105cda6_amd64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:6f3fb64d8b881cfbd847af85d193ea4f516925c6249f91ec55084905f4dd3c6a_ppc64le as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:a2f084702f5a1c31f27c7716aedcd617c96fbf1f5f93bebd6ca1d452b91757e7_arm64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:da3299e3a8199a200cfbb2eeb0e15f8911573836d2dbde73a55492d5053ae96d_s390x as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:126a79bee08f4df0f9dc8327e479768c1066fddad4359416935414933a190556_s390x as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:8853c67109f5d998bdb6670599856f61322004cd3f46df2522e7b56b9fe333f9_amd64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:92614c9b2d1df37df37b52ccaac562318d0dd8330c5c650c5bf09f11b228d680_arm64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:d7e6b3a44df34cb814f6490aa71e6ab0845ca9b51eab226e5f94c17b25f27a0f_ppc64le as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:71cec7e3da1978e7431c50ab9e2095b57915431f4f66267cc7ac3160ac788d74_amd64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:9f4bc02787f5e7046ebbaf5ea2c9b747b9f7a2b868c1832099460ef55604b6d5_arm64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:b1dc86fb39953b8099ea5a637eac97a4bd1b2f92d097a52cae77f61dda0dbb1f_s390x as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:ef5799ee0dbb30b3e5371d34253bf5f8159968d056b09566b746af8bf4473514_ppc64le as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:3288bd73ed35f786de12f386ed341721cbf14ba81854f3907897a787362cc091_amd64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:59c06be711e3f5926f46a1e9e29c9f6ed14594a1385d4d9b37d803e19acc3cb6_ppc64le as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:a3518bedb826eabb81c40a547549dd83e81dee958c9c00a256716c5463f6b131_s390x as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:e5faa2640041002b8acbc6e9be67485a13c2f62ba4ad6c42793e1c485b49169e_arm64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-azure-rhel9@sha256:0de237fbabb09982be974ac1cf3d88e28c6f6a2fe1293dd0e7bd84bdf01186a4_arm64 as a component of multicluster engine for Kubernetes 2.11
  • +99 more not shown

✅ Remediation

For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/clusters/cluster_mce_overview#mce-install-intro Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Update affected Go applications to use golang.org/x/net version 0.55.0 or later. As a workaround, do not use golang.org/x/net/html to parse untrusted HTML content, or enforce timeouts on HTML parsing operations. Applications that do not parse arbitrary HTML are not affected. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: Ensure that user-supplied URLs are validated and sanitized before being passed to Go's `html/template` package for rendering in HTML meta tag content attributes. Avoid rendering untrusted URL data directly in meta tag content attributes. Workaround: Increase the maximum number of query parameters allowed by setting the GODEBUG environment variable `urlmaxqueryparams` to a higher value (e.g., `GODEBUG=urlmaxqueryparams=20000`), or validate and enforce security controls on query parameters at the backend service rather than relying solely on the ReverseProxy's Rewrite or Director function for security filtering. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: Update affected Go applications to use golang.org/x/crypto version 0.52.0 or later, which rejects unsupported ConfirmBeforeUse keys instead of silently ignoring the constraint. As a workaround, do not add keys with ConfirmBeforeUse to the in-memory keyring from golang.org/x/crypto/ssh/agent, or use an SSH agent implementation that correctly enforces confirm-before-use. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: Update affected Go applications to use golang.org/x/net version 0.55.0 or later. As a workaround, do not use golang.org/x/net/html to parse and re-render untrusted HTML content. Applications that do not parse arbitrary HTML are not affected. Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: To mitigate this issue, restrict the exposure of the SSH agent to untrusted sources. Avoid enabling SSH agent forwarding when connecting to untrusted hosts or environments. Ensure that applications interacting with `golang.org/x/crypto/ssh/agent` validate all inputs to prevent malformed data from being processed. Reloading or restarting SSH services may be required for changes to take effect. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: To reduce the risk of exploitation, ensure strict access controls are enforced on managed clusters, limiting the ability of untrusted users to deploy or modify pods and thus inject malicious content into container logs. Additionally, users should exercise caution when viewing "Raw" logs from potentially untrusted sources within the hub console. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely.

🔗 References (47)