Red Hat Security Advisory: RHACS 4.10.7 security and bug fix update
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-39822 — golang: Go os.Root: Symlink following vulnerability allows directory traversal CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
🎯 Affected products48
- Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:6a980a762347317fe2eb5a8a0da9c7dc9f8809f1346e10b224862f33fea9456e_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:b5026e4fc9203f367c78250713883b2620bab241bbe03bf9544dd8cf38f91e18_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:e4de2a94294c323bd029c693d539ffc9e11e0401a947dc49b512428852b23b47_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:f7e33828faddd5bf7030179865108cd8aebe3792bbcda38e8834144f2599e635_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:42fce168d48c2323e4e8cb012e3fcb529a8beb871ce7366565c99ddf33687775_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:5fa5284bdacb67d49f9dfb41dc89584b78fecf523c115fb40081111337f891ae_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:a8a5be037b33510e023b9eca6f593f3ee3a8fcbf970ebf42649a9eac289022a8_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:ecda43bf64854b5db93f7bf255c72f1449ba9e953af91dae8bd3bdbc03e23aef_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-fact-rhel8@sha256:0e2614305f385222818ba5bb446aa30db2ad6e2b0c88542e653406db13fc9b92_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-fact-rhel8@sha256:10bd90633dfd295f087dce6712c43abd761c6e6cbaa9249e0f29eb3ceaf607e9_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:4cfac3dc0c224c1f49f4eab49d186aec22e4b5313402c875118887cd28409201_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:9ed3000c0fbf674bc35b46ae4631d06ae1589ee7a65c77df34803c2814f3054c_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:b825928aa70c4fcd660f849af991fda6677a952688e01820dbfa5369ecda9584_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:e17343e3255259a858ce2be6e96b909eaed2ed08ea32b4c548b8421ded736885_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-operator-bundle@sha256:18618fd708fc639eee0a60e61a662bb39aa2b8ee7caed5b3d7d89b3ff206a40d_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:2caf58917f349f5ad35e0a59fd82d2f3dfbdefa8e958392859289d2742a402a2_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:4110c57e7e4e1e535678bf0e3cd4e541d0169e98d977c2f21c0c119537cd28be_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:586af1b1fd4f1f4e5ad98d51b361bf83af3866d2c80f2bea3aa276511f016e12_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:a337e275001b59a637a531f1997d07e7a45e8fde0dec5c72f7e2d5c295f02f87_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:4c286dbd7a19ba23ea7fd49eb8954f0877fca60c9e32b3c1dfc9bbf29c24c846_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:7a66579b020b01d2f023ed320ba1962a6e2269a5e8bf921604f4ed520aaf9082_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:bb8aa0658db73803f89608fd47b4c070e61606a222279328ad1a1120fa6a1d16_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:feee253916fa10ae8ede30bc4bbe6b965e2e2cdb473b6525dfa3bb1e70f290a8_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:070b56aee8895f4c1777432111475a376f2a9f0c3dbf869d9361a8232298bb05_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:239f63b068896ae3cb7346d37122378a2d3a20f70141e2a9f5e8857ab0692d7d_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:b48e0084c6a330ea811a5d7a2b193922ba763d1c3954d964acec286d1e20cae6_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:ba9c445ce5d8e0412092f513dacab7f393d4b35d1059cf580e677a3247795ee9_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:0c43d51803f117913eb780aa01033a5003b5831e1382b14117bc56b181289699_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:488bab21b123467a2f283ee6a740eb05144b683804eb6fa9c06e381f49f5b4f4_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- +18 more not shown
✅ Remediation
If you are using an earlier version of RHACS, you are advised to upgrade to the version of RHACS mentioned in the synopsis and release notes in order to take advantage of the enhancements, bug fixes, and/or security patches in the release. Workaround: There is no mitigation for this issue other than updating the Go toolchain to Go 1.25.12 or Go 1.26.5. Programs compiled with Go >= 1.24 that do not use the os.Root API are not affected by this vulnerability. The os.Root API was introduced in Go 1.24. Go versions prior to 1.24 are not affected. This issue is fixed in Go 1.25.12 and Go 1.26.5. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:59203
- externalhttps://access.redhat.com/security/cve/CVE-2026-39822
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-69152
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.10/html-single/release_notes/index#about-this-release-4107_release-notes-410
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_59203.json