Red Hat Security Advisory: multicluster engine for Kubernetes v2.11.6 security update
🔗 CVE IDs covered (14)
📋 Description
CVE-2024-45336 — golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect CVE-2025-22866 — crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec CVE-2026-10059 — cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via ClusterCurator ServiceAccount token CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-19130 — provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedFrom labels bypasses authorization CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-39825 — net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls CVE-2026-42507 — net/textproto: golang: Golang net/textproto: Misleading error messages via input injection CVE-2026-66794 — cluster-proxy-addon: cluster-proxy-addon: unauthenticated SSRF to arbitrary managed-cluster services via public Route CVE-2026-66795 — managedcluster-import-controller: CSR auto-approver does not validate certificate Subject or signerName (spoke→hub cluster-admin) CVE-2026-73266 — clusterclaims-controller: Confused deputy: tenant-controlled ClusterClaim labels propagated to ManagedCluster, enabling cross-tenant ManagedClusterSet join CVE-2026-73267 — clusterclaims-controller: ManagedCluster deletion keyed solely on ClusterClaim.Spec.Namespace with no local ownership check CVE-2026-73268 — cluster-curator-controller: cluster-curator-controller: spec.install.overrideJob allows arbitrary Job spec injection CVE-2026-73269 — cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA
🎯 Affected products129
- multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:0451628c58cb6738977a1a5499f204b07e8ab02b41e949b27b263fea3ea61f88_amd64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:3e9e3ef83f3da8d29471e8cc5cc0315f7b02dd44cfaafbd0b27f049d2efcc4a5_ppc64le as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:5acf929f44e14e1a1d229e0a4d0e0d68c592654435d0a7ea234c23d88e7da686_s390x as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:ba6c4a20a6ee685c319df030bd2774e9ff9747c0bea02df16c169f85b20e4ca0_arm64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:404dcf5023d8ff7a271516665c7e45cfa1402d61c1fabbfde2e109a644b228df_ppc64le as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:43b37c9163cd7336ef811263d8326c56c4df8f534106c8a4e7fd2ba99d7d3cd6_arm64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:8ae3b76219dc0aa9ecaf8ae7aa554db2eef47bfcca8a30f249fa58c848e07fb7_amd64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:a9e5ed5f8168f16e376542c66e9a32427585dd308c1bed430a23f11429ae33ab_s390x as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:0225d9860665b2f594ee080a52c359cd0e7f80259512f8335efb1b5aa2a4fa13_arm64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:7645582f77914160ce55fb649e88e69bbdac7401be2f23ff07b876d7b9f2af78_ppc64le as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:98c3890f6aa831d8a8414b7d6eed8341cb622f411de8b40c246a44fc9418d408_amd64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:ee57333d602b4d5d9940ecf475857d8a195083244b7e1d6ac3935d2579069791_s390x as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:36ec9ddd267a79d04ea91d3867d57d7f11ddf7ab09e06ec36477bf8c921dfcc1_amd64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:a7358415fd9d8529f817e121ea275b9bcee8eaf4549989e38be7d2a199fdeb6f_s390x as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:eca55ab82d4c2a589b432312915721ac7ba3bcd989aa4fe9c87600d7c573327b_ppc64le as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:fd3a8c00893e74eb82f4a4a9c026525d0fe88768a2bb6a70922448c4460a1328_arm64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:073ebe38b89107a2883e7557ad359244f83c663141181f113851bd737b4117af_ppc64le as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:0cb8604d4e30774a567456b816e41fab2dd9356fe8cc6f607e80f8d885e507be_s390x as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:32293c26199bf6d9f20523e8d210b2dd77f27f825f073b17df3e5e3525997f76_arm64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:90153bc36951f2be3330a0e1c73525dac72ba9dd7a34727d0e2b3214043d7573_amd64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:71cec7e3da1978e7431c50ab9e2095b57915431f4f66267cc7ac3160ac788d74_amd64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:9f4bc02787f5e7046ebbaf5ea2c9b747b9f7a2b868c1832099460ef55604b6d5_arm64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:b1dc86fb39953b8099ea5a637eac97a4bd1b2f92d097a52cae77f61dda0dbb1f_s390x as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:ef5799ee0dbb30b3e5371d34253bf5f8159968d056b09566b746af8bf4473514_ppc64le as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:3288bd73ed35f786de12f386ed341721cbf14ba81854f3907897a787362cc091_amd64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:59c06be711e3f5926f46a1e9e29c9f6ed14594a1385d4d9b37d803e19acc3cb6_ppc64le as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:a3518bedb826eabb81c40a547549dd83e81dee958c9c00a256716c5463f6b131_s390x as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:e5faa2640041002b8acbc6e9be67485a13c2f62ba4ad6c42793e1c485b49169e_arm64 as a component of multicluster engine for Kubernetes 2.11
- registry.redhat.io/multicluster-engine/cluster-api-provider-azure-rhel9@sha256:450cceb8f690a3e5ea6bb6df2daddb06f1dd9e95c09220e423becc78d3743981_s390x as a component of multicluster engine for Kubernetes 2.11
- +99 more not shown
✅ Remediation
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/clusters/cluster_mce_overview#mce-install-intro Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: Increase the maximum number of query parameters allowed by setting the GODEBUG environment variable `urlmaxqueryparams` to a higher value (e.g., `GODEBUG=urlmaxqueryparams=20000`), or validate and enforce security controls on query parameters at the backend service rather than relying solely on the ReverseProxy's Rewrite or Director function for security filtering. Workaround: To mitigate this issue, restrict network access to the user-facing Route of the `cluster-proxy-addon` to trusted networks only. Implement firewall rules to limit inbound connections to the Route's exposed port, ensuring only authorized sources can reach it. This reduces the attack surface by preventing unauthenticated external access to the vulnerable proxy. Workaround: To mitigate this issue, implement strict Role-Based Access Control (RBAC) policies to limit create and update permissions on `clustercurators.cluster.open-cluster-management.io` resources to trusted administrators only. This restricts the ability of less privileged tenants to exploit the vulnerability and escalate privileges within the Kubernetes environment. Workaround: To mitigate this issue, restrict the ability of tenants to create `ClusterCurator` resources. Implement Kubernetes Role-Based Access Control (RBAC) policies to limit `create` permissions for `clustercurators.cluster.open-cluster-management.io` resources to only trusted administrators or service accounts. Alternatively, deploy an admission controller to enforce that `metadata.name` and `metadata.namespace` fields are identical when `ClusterCurator` resources are created, preventing the vulnerable condition.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2026:59556
- externalhttps://access.redhat.com/security/cve/CVE-2024-45336
- externalhttps://access.redhat.com/security/cve/CVE-2025-22866
- externalhttps://access.redhat.com/security/cve/CVE-2026-10059
- externalhttps://access.redhat.com/security/cve/CVE-2026-12143
- externalhttps://access.redhat.com/security/cve/CVE-2026-19130
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-39825
- externalhttps://access.redhat.com/security/cve/CVE-2026-42507
- externalhttps://access.redhat.com/security/cve/CVE-2026-66794
- externalhttps://access.redhat.com/security/cve/CVE-2026-66795
- externalhttps://access.redhat.com/security/cve/CVE-2026-73266
- externalhttps://access.redhat.com/security/cve/CVE-2026-73267
- externalhttps://access.redhat.com/security/cve/CVE-2026-73268
- externalhttps://access.redhat.com/security/cve/CVE-2026-73269
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_59556.json