RHSA-2026:59579HighCVSS 9.9

Red Hat Security Advisory: multicluster engine for Kubernetes v2.6.14 security update

Published
August 25, 2026
Last Modified
August 26, 2026

🔗 CVE IDs covered (26)

📋 Description

CVE-2024-45336 — golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect CVE-2025-22866 — crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing CVE-2026-10059 — cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via ClusterCurator ServiceAccount token CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-19130 — provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedFrom labels bypasses authorization CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-47219 — find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server CVE-2026-54272 — ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification CVE-2026-66794 — cluster-proxy-addon: cluster-proxy-addon: unauthenticated SSRF to arbitrary managed-cluster services via public Route CVE-2026-66795 — managedcluster-import-controller: managedcluster-import-controller: CSR auto-approver does not validate certificate Subject, signerName, or requester identity CVE-2026-66804 — console: console: authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure CVE-2026-66805 — console: console: stored DOM XSS via unescaped pod logs in document.write CVE-2026-66806 — console: console: TLS verification disabled when sending hub pull-secret to console.redhat.com CVE-2026-66808 — hypershift-addon-operator: hypershift-addon-operator: unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection) CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-73266 — clusterclaims-controller: clusterclaims-controller: tenant-controlled ClusterClaim labels propagated to ManagedCluster enabling cross-tenant ManagedClusterSet join CVE-2026-73267 — clusterclaims-controller: clusterclaims-controller: ManagedCluster deletion keyed solely on ClusterClaim.Spec.Namespace with no ownership check CVE-2026-73268 — cluster-curator-controller: cluster-curator-controller: spec.install.overrideJob allows arbitrary Job spec injection CVE-2026-73269 — cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA

🎯 Affected products109

  • multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:0d668fb3c0766c121dcb2fe1c50b0e650f3e5619212cfd6c5b8606cbf2f46ed5_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:478425331df9f329a5ecdeab3c308720a5332b442524863509c56e9114ec04cc_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:82c5f7aa025b65ea5a717ac6b4fbdb14cdaa70d1836f3f1e18c0bba7892d06c5_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:89c0187bbae1316dc2b339188399d35056da419ca5681c3c6b6c9ada8426ff5d_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:37f3af61b10a2983d1708cd6fca79b3a3442eb50341f988095099d6f1099aa2f_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:967fe2291e1c5dc13969ef6a8d24b570cd42fbb9fb62e5ad176e024f6c63b46c_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:a105d84c9cf07ebb22f551364b014ffe53e7e8d3d12960a1626f626ba0ef1ab2_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:d907df873261c35a9d7501d16f78cceeff34bb7df4ade3789cbc044186c3424a_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:069dc1611a272eb60a61c3c8e2c7b94d557357e1cdd84c990dc7b6c795f2d8f0_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:7462188ca4e55cd0ada1e258636c873e7e47b8c7c2209590494377afd9d12baa_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:80308f8416965c93372202ca402f493a489e57dbb926dda975eb631528aa047d_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:dca052e5d128114b2312cd1013f3fa6942a266106a1499edb755b145dfd159bd_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:05b939fdaafd6c018ac80bfdf2e0f334a22fd2561dc0ff58bd348de88d02df60_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:5065a8825698759f8433fbb34e6d996c78e92026883470d18bc79b33c3980f76_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:58e91670a23798dcb9c84cfb3d8c3c6515c46eb60b74425626d312c234bc90a6_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:6c2df804fba80d6d6c7ac5b4e2199f4da9119eb1956695194bf8103787d26a19_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:1ac9661a442222942a9a085be2c492325517626281d555f89cb5494cb8d0640f_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:22e29cd4be20eee653f291036994e8387bf058ba8cb34d7268d6b313fda1fa73_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:515e1b8d4d85bb49f87cdd857ab193707cd27c50492661d3fcfe7d39618807e9_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:95c9022b4f4afeef1fb7e45e52ef8c656e6aad20a1a7152ebeb7513d7fd90f90_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:26a3c6e4c02c695a19357b12d62cf349ad9237291b2b779ffef0cff1af75a7ca_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:6afb4e5f3dd0a89347aef6570f8b8d2ced1db67b9171e22a1b7e091c2aeeda80_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:a5f96e3ba60f2a639c5c94282445b85ea77a0b5c509011170ce2e07afbc0d071_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:a8132b6ad654d7babe77051158a9f82c5f1e27bdff7eb38ac5f307891ed8d413_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:059ffd9e76ed4a946e85b3c7ea3e51de4c4510def6fefd118a7ef28cc2a29981_arm64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:6a07e49a882b5c7242896fd8ba83d82ece6a4ae6b8b2c0116398410552c87a5b_ppc64le as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:d5dcc70669da9641e5e5e560d5f30baa70f29b2d9210cf92ce53930aa085698b_amd64 as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:e82c36f361b8eb03b4c991823fa975f81bc29b41a044e0441998e3922bb84623_s390x as a component of multicluster engine for Kubernetes 2.6
  • registry.redhat.io/multicluster-engine/cluster-proxy-rhel9@sha256:82a8076d032b2f199ecdeaff6caeca3779efe606f9acb3a18823f2b3039c6dc4_s390x as a component of multicluster engine for Kubernetes 2.6
  • +79 more not shown

✅ Remediation

For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/clusters/cluster_mce_overview#mce-install-intro Workaround: Red Hat Product Security does not have a recommended mitigation at this time. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: There is no available mitigation for this flaw other than updating the bundled find-my-way library to a fixed version (9.7.0 or later). Where feasible, restricting the affected service to HTTP/1.1 (disabling HTTP/2) removes the attack vector, since the flaw is only reachable through the HTTP/2 request path. Workaround: To mitigate this issue, restrict network access to the user-facing Route of the `cluster-proxy-addon` to trusted networks only. Implement firewall rules to limit inbound connections to the Route's exposed port, ensuring only authorized sources can reach it. This reduces the attack surface by preventing unauthenticated external access to the vulnerable proxy. Workaround: To reduce the risk of exploitation, ensure strict access controls are enforced on managed clusters, limiting the ability of untrusted users to deploy or modify pods and thus inject malicious content into container logs. Additionally, users should exercise caution when viewing "Raw" logs from potentially untrusted sources within the hub console. Workaround: To mitigate this issue, ensure that the HTTPS_PROXY environment variable is configured for the affected console component. This will enable proper TLS verification for outbound connections to console.redhat.com. Consult product documentation for specific instructions on configuring proxy settings for Multicluster Engine for Kubernetes and Red Hat Advanced Cluster Management for Kubernetes. A restart of the affected services may be required for the changes to take effect. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely. Workaround: To mitigate this issue, implement strict Role-Based Access Control (RBAC) policies to limit create and update permissions on `clustercurators.cluster.open-cluster-management.io` resources to trusted administrators only. This restricts the ability of less privileged tenants to exploit the vulnerability and escalate privileges within the Kubernetes environment. Workaround: To mitigate this issue, restrict the ability of tenants to create `ClusterCurator` resources. Implement Kubernetes Role-Based Access Control (RBAC) policies to limit `create` permissions for `clustercurators.cluster.open-cluster-management.io` resources to only trusted administrators or service accounts. Alternatively, deploy an admission controller to enforce that `metadata.name` and `metadata.namespace` fields are identical when `ClusterCurator` resources are created, preventing the vulnerable condition.

🔗 References (29)