Red Hat Security Advisory: multicluster engine for Kubernetes v2.8.10 security update
🔗 CVE IDs covered (30)
📋 Description
CVE-2024-45336 — golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect CVE-2025-22866 — crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing CVE-2026-10059 — cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via ClusterCurator ServiceAccount token CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-19130 — provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedFrom labels bypasses authorization CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-47219 — find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server CVE-2026-54272 — ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification CVE-2026-66794 — cluster-proxy-addon: cluster-proxy-addon: unauthenticated SSRF to arbitrary managed-cluster services via public Route CVE-2026-66795 — managedcluster-import-controller: managedcluster-import-controller: CSR auto-approver does not validate certificate Subject, signerName, or requester identity CVE-2026-66804 — console: console: authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure CVE-2026-66805 — console: console: stored DOM XSS via unescaped pod logs in document.write CVE-2026-66808 — hypershift-addon-operator: hypershift-addon-operator: unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection) CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation CVE-2026-67214 — nanoid: nanoid: Denial of Service via negative size input in non-secure module functions CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-73266 — clusterclaims-controller: clusterclaims-controller: tenant-controlled ClusterClaim labels propagated to ManagedCluster enabling cross-tenant ManagedClusterSet join CVE-2026-73267 — clusterclaims-controller: clusterclaims-controller: ManagedCluster deletion keyed solely on ClusterClaim.Spec.Namespace with no ownership check CVE-2026-73268 — cluster-curator-controller: cluster-curator-controller: spec.install.overrideJob allows arbitrary Job spec injection CVE-2026-73269 — cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA
🎯 Affected products109
- multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:39107a76cb734e1ac067b0e92edfa3b3ee815eceb88679d4694ac8ddbc132996_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:ba8e2a155495f12baa4a3a908c125307168f9b4ce3cf50dec6ec7d6f5b78dfea_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:d1d588dada5b4df6834112599ded1d58803440dbb469bcef41f45edc588eeab5_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:f4a5ebfd1ccd9330f8dd9fe29716934c87ac252f978be0579aa897ff07db23ca_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:2ec34db505644df5b118f80548f20aa9b5aab5774f5caea0aa2016119f1b8a2a_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:329177de16ae423bcf4322258097e3055ffe3e77d2e067e7ecf364e50c8120c0_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:631d71ab051143fbd095b70014c0a4c422d7190a7f5ff9286efb04e125cbdce0_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:9551ff2958489c920a4da96696c1a09f282afd882e19dd95b8b1ac1260726dc7_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:2e177368c12f666b4a5862b81eea57559b3885231f6a745e98cc01309cea9a57_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:4ba8f8ff0b3ca51a496506e3e19a0aa308e1406e1703c198ac37eb4f558bc6b7_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:9716e9b89f4c00ca1c49a172c19cd3b4df780fedee35c5ca78691c8576febb6f_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:e8f78bee117c1c93aa04cf20db05a47d9e0d43f3fd50ef558e4d9240064d89af_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:21057d30b379b8db8e0a4120ba30e308fb3e4be5fc92d422aac0be05766b02c9_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:7c87c8082d0b184bc8a3aff9359fd4f0b7e87290a2425e6a8ef61737b8d93d79_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:87f0a7d78ce0954bdb7f7a988e8914228303503fd2ecfd4b9c23bb6d67b37fdd_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:c819d844f28c34d28c31da0010b3d5d2b0a6f0f8dca8b5a0007a308583e1e2a3_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:01a94e2860bf5871f9b3fea049a291b487ac319b6521241a52cc08d0b23162da_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:6d312615def25d135953ff42f49acff39ebe4876e1e1ceb3854416530a0c1523_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:8b24eece2c66427808627fd4ca91eba779c2958d32896ccb6cc7585af7b8528d_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:97a4040d296bceb72425636faf1542845d30cdbe23b9505cf7fab4cc0f64ca70_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:2db6ee2a8ffb28ee10583f3609e1506a76f9b4c540b17708c1961c2609cef2e9_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:35a655c780787b69077013a99794df5d859c401e93aef5308c7080eaf34fcda5_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:b21baef3e37f97c0a5691ce84040b639de8258e7630f9c9e418c78d05e6f843f_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:c160d6059f3ad4f8a9cfb9db7843e963add06e7bdcc843417812557fc67434b7_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:068de91b5d0fad7f0cc3d2f795c1c3f77015d260c0bca8e284a2a9fbf8216230_s390x as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:79f2432eded7ebdb078e152b5ae41329a55ebdbf7772076ff72a51010a2515be_amd64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:7dd9a383c4bbe3d1cf966a7dcb930148e90f4ba084a759adcf786204737035c5_arm64 as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:9f635dcb6f816e6bba2db8df3a021d24b10ad3699317bfbff4c8c81129ff0707_ppc64le as a component of multicluster engine for Kubernetes 2.8
- registry.redhat.io/multicluster-engine/cluster-proxy-rhel9@sha256:2db34706f1a2c179a71dc536e4124a13e24fb48156a916aea959239b6a4a03af_ppc64le as a component of multicluster engine for Kubernetes 2.8
- +79 more not shown
✅ Remediation
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/clusters/cluster_mce_overview#mce-install-intro Workaround: Red Hat Product Security does not have a recommended mitigation at this time. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: There is no available mitigation for this flaw other than updating the bundled find-my-way library to a fixed version (9.7.0 or later). Where feasible, restricting the affected service to HTTP/1.1 (disabling HTTP/2) removes the attack vector, since the flaw is only reachable through the HTTP/2 request path. Workaround: To mitigate this issue, restrict network access to the user-facing Route of the `cluster-proxy-addon` to trusted networks only. Implement firewall rules to limit inbound connections to the Route's exposed port, ensuring only authorized sources can reach it. This reduces the attack surface by preventing unauthenticated external access to the vulnerable proxy. Workaround: To reduce the risk of exploitation, ensure strict access controls are enforced on managed clusters, limiting the ability of untrusted users to deploy or modify pods and thus inject malicious content into container logs. Additionally, users should exercise caution when viewing "Raw" logs from potentially untrusted sources within the hub console. Workaround: To mitigate this issue, ensure application code validates the size parameter passed to customAlphabet or customRandom, rejecting or sanitizing zero-value inputs before passing them to nanoid. Workaround: Sanitize all user-supplied integer inputs before passing them to `nanoid` or `customAlphabet` functions in the `nanoid/non-secure` module, ensuring the size parameter is strictly a non-negative integer. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely. Workaround: To mitigate this issue, implement strict Role-Based Access Control (RBAC) policies to limit create and update permissions on `clustercurators.cluster.open-cluster-management.io` resources to trusted administrators only. This restricts the ability of less privileged tenants to exploit the vulnerability and escalate privileges within the Kubernetes environment. Workaround: To mitigate this issue, restrict the ability of tenants to create `ClusterCurator` resources. Implement Kubernetes Role-Based Access Control (RBAC) policies to limit `create` permissions for `clustercurators.cluster.open-cluster-management.io` resources to only trusted administrators or service accounts. Alternatively, deploy an admission controller to enforce that `metadata.name` and `metadata.namespace` fields are identical when `ClusterCurator` resources are created, preventing the vulnerable condition.
🔗 References (33)
- selfhttps://access.redhat.com/errata/RHSA-2026:59558
- externalhttps://access.redhat.com/security/cve/CVE-2024-45336
- externalhttps://access.redhat.com/security/cve/CVE-2025-22866
- externalhttps://access.redhat.com/security/cve/CVE-2025-30204
- externalhttps://access.redhat.com/security/cve/CVE-2026-10059
- externalhttps://access.redhat.com/security/cve/CVE-2026-12143
- externalhttps://access.redhat.com/security/cve/CVE-2026-19130
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-39831
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-45623
- externalhttps://access.redhat.com/security/cve/CVE-2026-46595
- externalhttps://access.redhat.com/security/cve/CVE-2026-46597
- externalhttps://access.redhat.com/security/cve/CVE-2026-47219
- externalhttps://access.redhat.com/security/cve/CVE-2026-54272
- externalhttps://access.redhat.com/security/cve/CVE-2026-66794
- externalhttps://access.redhat.com/security/cve/CVE-2026-66795
- externalhttps://access.redhat.com/security/cve/CVE-2026-66804
- externalhttps://access.redhat.com/security/cve/CVE-2026-66805
- externalhttps://access.redhat.com/security/cve/CVE-2026-66808
- externalhttps://access.redhat.com/security/cve/CVE-2026-67213
- externalhttps://access.redhat.com/security/cve/CVE-2026-67214
- externalhttps://access.redhat.com/security/cve/CVE-2026-69153
- externalhttps://access.redhat.com/security/cve/CVE-2026-69192
- externalhttps://access.redhat.com/security/cve/CVE-2026-73086
- externalhttps://access.redhat.com/security/cve/CVE-2026-73266
- externalhttps://access.redhat.com/security/cve/CVE-2026-73267
- externalhttps://access.redhat.com/security/cve/CVE-2026-73268
- externalhttps://access.redhat.com/security/cve/CVE-2026-73269
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_59558.json