RHSA-2026:59557HighCVSS 9.9

Red Hat Security Advisory: multicluster engine for Kubernetes v2.10.6 security update

Published
August 25, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2024-45336 — golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect CVE-2025-22866 — crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec CVE-2026-10059 — cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via ClusterCurator ServiceAccount token CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-19130 — provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedFrom labels bypasses authorization CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-66794 — cluster-proxy-addon: cluster-proxy-addon: unauthenticated SSRF to arbitrary managed-cluster services via public Route CVE-2026-66795 — managedcluster-import-controller: CSR auto-approver does not validate certificate Subject or signerName (spoke→hub cluster-admin) CVE-2026-66804 — console: Authenticated SSRF via user-controlled towerHost in /ansibletower handler CVE-2026-73266 — clusterclaims-controller: Confused deputy: tenant-controlled ClusterClaim labels propagated to ManagedCluster, enabling cross-tenant ManagedClusterSet join CVE-2026-73267 — clusterclaims-controller: ManagedCluster deletion keyed solely on ClusterClaim.Spec.Namespace with no local ownership check CVE-2026-73268 — cluster-curator-controller: cluster-curator-controller: spec.install.overrideJob allows arbitrary Job spec injection CVE-2026-73269 — cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA

🎯 Affected products125

  • multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:120becd4f1b2a36f48a43d2933b7a1be1595cc2cb626d44a053033d010e6aac7_ppc64le as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:610df72fa91b7ff983c5698c08462a2c77ec60d2940e8c0048054d14fd0a3e31_s390x as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:675af2b54df773d590a2543225c7c5cce1e9a6b0f3651a8e454c02dde506a580_arm64 as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:b69db5c2aac4decf99a4c97c09e9c7055b642c4849f7e78d74f78877702428e8_amd64 as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:17b907f3bc67fe68c91f72a5fac1a2320ef0ceb642a7ff7359781ef627f660c2_arm64 as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:1c7f83bf0ff1d3231bc3d2c8559708671e58229e4ddcbd1db8607559d0564fed_amd64 as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:67fe0a996cbb7af417edf2b4b7b7cac1c1d638e0cfe8d0e684c8d4314814de49_ppc64le as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:864cfbceb2af949ad1f7d0db61bb0a93346db74188314c3fe03892a2daf156ad_s390x as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:019c1264ffad487a41578bf33209d997303a491194491d0d4332b15602086ac7_ppc64le as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:4ef3304a33a387668f0b5fa1b6998e64062cd61e19aa3b49b444400d4ba5b229_s390x as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:b8606468aabd58cc015ee48aadbe7d69bf2ceedf25466c201303fdeb01aeedb0_arm64 as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:e45ef752eeafd85f33f0b87e955055b701522a99c01b5b1662997015cda0e236_amd64 as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:07502045ec816b13a5aab5f5bcdf8c50242a2b8acbd15e3fa2dbb2faa25d2ed3_arm64 as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:104cfeb03d0b29b7e76516aa3ac8072366efeef5c136b68f7c3e8e0ad5ce1b96_amd64 as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:e3445247fb19830ca4840fc26918d1154d53e1ae735d139473fe470db09a3efe_s390x as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:fa831832da15a85b49d52812220f3e6de82793461016cc659577113c0a5a0a4c_ppc64le as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:22d2a996d18d00f5985f381e395b33186c2af759fba010bec0cc9f3120be3d3a_amd64 as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:51b926dc40fa8abe32f1a31f419d6e38d2ac322dc5973650bf0326afd841edd7_ppc64le as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:c86653f45ed8c480589f2d3cde84e1de45e23dbdeb7dcc398d5f0121ebc9215f_arm64 as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:dbe55cb7c87224ae10d5b157ef5e66a4ffe4788bfb134a3db47d2c1bceab4eec_s390x as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:0815b6568f3c2df6d86aa70458a3037d0251f58a673244f13defcfa9053d4019_amd64 as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:2fc1ac0ac7950482cc4ee05aea133af511ebfcfbe45e0fa3d13f33c983a1a75a_s390x as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:48d38b946e601b8bfebe7fac00d538f01b6e565f01f76681059af7001d1a42a6_arm64 as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:81b31ada806558c18afb7bfcdaf1bc74ae92245e2f42aade9d80c59be2fa9a4c_ppc64le as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:3b69bad711b3358fa22546c193d0b7d15c96c1b0c445b36da1d426695516634d_ppc64le as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:72514aafb15a0988ec5d65cd01a90bd0c58010cce32af69c3d42b4d3a051a892_amd64 as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:aa964bc0245cd01f2077b2f28567048ccb638cb899eefa66383dbcc2d53bcf3d_s390x as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:affbb00a938b6306fc357de5f5b5b48c1bc493a280b9db94cc0a5d545337934f_arm64 as a component of multicluster engine for Kubernetes 2.1
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:18c24d419df62a0eea1661c1ee045d90c0af6b9b1b026db79ecb194eb90da729_arm64 as a component of multicluster engine for Kubernetes 2.1
  • +95 more not shown

✅ Remediation

For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.15/html/clusters/cluster_mce_overview#mce-install-intro Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended. Workaround: To mitigate this issue, restrict network access to the user-facing Route of the `cluster-proxy-addon` to trusted networks only. Implement firewall rules to limit inbound connections to the Route's exposed port, ensuring only authorized sources can reach it. This reduces the attack surface by preventing unauthenticated external access to the vulnerable proxy. Workaround: To mitigate this issue, implement strict Role-Based Access Control (RBAC) policies to limit create and update permissions on `clustercurators.cluster.open-cluster-management.io` resources to trusted administrators only. This restricts the ability of less privileged tenants to exploit the vulnerability and escalate privileges within the Kubernetes environment. Workaround: To mitigate this issue, restrict the ability of tenants to create `ClusterCurator` resources. Implement Kubernetes Role-Based Access Control (RBAC) policies to limit `create` permissions for `clustercurators.cluster.open-cluster-management.io` resources to only trusted administrators or service accounts. Alternatively, deploy an admission controller to enforce that `metadata.name` and `metadata.namespace` fields are identical when `ClusterCurator` resources are created, preventing the vulnerable condition.

🔗 References (17)