Red Hat Security Advisory: multicluster engine for Kubernetes v2.17.2 security update
🔗 CVE IDs covered (25)
📋 Description
CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization
CVE-2026-19130 — provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedFrom labels bypasses authorization
CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries
CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation
CVE-2026-44990 — sanitize-html: sanitize-html: Stored Cross-Site Scripting via HTML sanitizer bypass
CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input
CVE-2026-47219 — find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server
CVE-2026-54272 — ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification
CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents
CVE-2026-66794 — cluster-proxy-addon: cluster-proxy-addon: unauthenticated SSRF to arbitrary managed-cluster services via public Route
CVE-2026-66795 — managedcluster-import-controller: managedcluster-import-controller: CSR auto-approver does not validate certificate Subject, signerName, or requester identity
CVE-2026-66804 — console: console: authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure
CVE-2026-66805 — console: console: stored DOM XSS via unescaped pod logs in document.write
CVE-2026-66808 — hypershift-addon-operator: hypershift-addon-operator: unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection)
CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation
CVE-2026-67214 — nanoid: nanoid: Denial of Service via negative size input in non-secure module functions
CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL
CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass
CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow
CVE-2026-73266 — clusterclaims-controller: clusterclaims-controller: tenant-controlled ClusterClaim labels propagated to ManagedCluster enabling cross-tenant ManagedClusterSet join
CVE-2026-73267 — clusterclaims-controller: clusterclaims-controller: ManagedCluster deletion keyed solely on ClusterClaim.Spec.Namespace with no ownership check
CVE-2026-73268 — cluster-curator-controller: cluster-curator-controller: spec.install.overrideJob allows arbitrary Job spec injection
CVE-2026-73269 — cluster-curator-controller: cluster-curator-controller: tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA
🎯 Affected products141
- multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:1b94f667f1b4d9d8d18dc997282967a79adc36f3d725fdaf27bbab309152e3f1_ppc64le as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:28d20ad256324b95702089797fed9df150ffc8c605438e352d1b0a8823ff8ac4_arm64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:43ea2804e5684613a657483b47e5484914fd9d6d57b2369840ce26ce770700ed_s390x as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:f3d371e80b911c80628f77af2831b982df5ecb2c31a01b0c4302bd7e1f5bcf55_amd64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:a1ec6e7fb539a3887102bfd1cbbbb0a201682659daa764d743570dfb68a15bf4_ppc64le as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:a223e9327b26151010bfcda521562399a769c2ec62bd047a5a52c5140fcdd3ea_amd64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:bd6c6ada53b95837700bd37ac13e241e37cb31ee036c875abe8b19dc8ff5a202_arm64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:cb6aa963152846f608b813af1148f27f65a3db4ee1e0a77f980a1fdcf02d8f4a_s390x as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:1498d1ca785392bec64325d021a4e1c9761423ab81f9e80d44a8948cce3a393d_arm64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:48f8ef0bfc8853ed22b45dffd9f880ac426cd01ecb3127e937776e91e1d65a8f_s390x as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:4cfb3077d68be5284421f14c8c804476d9b3ab2ef4af329a997c385a528e08a4_amd64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:b2e12b542ece0625796e8218cc4e9bcb6c3e25760b628b481a76fa562fa56e71_ppc64le as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:5c16fb11a2f74c77d579a5addb084965e0d60f090a398479c1e7924948a85023_ppc64le as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:6d1d6d02896f941ad20822baf5b5a9200a1989cb018cab1258945b637a01797d_s390x as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:8cd9a08751dd743599290c540cbb69d91a8e179668bba8de8c4ee520ad3dae46_amd64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:8fc459af5a1e4b23f59ea41c872dbfdd58fb7c7d934aebcd9b80ea73a3d10020_arm64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:4e6fd64d116ff5361c7a42a1e73a446c46ec4f52b5afa9e54dbf7086b6f7e5ae_amd64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:581aa8f2d72160f2f9459162cd2658f38990d564495a88211d695e0fa081326f_s390x as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:9d6d6e1842af29b5fc154ce65f9b77cd640754d29fe3867076855b0bfea6dccc_ppc64le as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:f6cb1be4562925663c40cecbef1874e0cc3b9420e72e84b7829049f6198c1926_arm64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cloudevents-conductor-rhel9@sha256:2429ab7e2f81b111d4f759bca52bace0307ce0dcf2e52d6f4b4e25ad9ec602ba_ppc64le as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cloudevents-conductor-rhel9@sha256:2ad5f3439fbb259d2a7fb53088f545da9a465ae432a31fa41c831ee8e658a193_s390x as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cloudevents-conductor-rhel9@sha256:d981a7fcaddb7da9d8799876622dcba116764a1fed410c8e8384306397590542_amd64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cloudevents-conductor-rhel9@sha256:fe3a586cbd202c2b6987668fc86aef645da77b367157613278d4bba173a19baf_arm64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:3a503d01b2e2ed6ed11b309bf79b1ad049b92ec1cc1e4ce66fc694ccacf6be87_s390x as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:97e68d7e9cfecba5222cced3f26cbaa80e2990ff393a8bba3f1847418b558bf3_arm64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:c9b3cb42de463dd5719ed011f7f3865e5ad9456df026116120533d2baa322f06_amd64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:dd3830a0e4264a7cae63408677dacfc6884db35dcf06523ad743507a5e42ae68_ppc64le as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:7850c65cfb8bce2f8f8ad1f9169d023edf3e4cd7b994965ba2172434c7e1365e_amd64 as a component of multicluster engine for Kubernetes 2.17
- +111 more not shown
✅ Remediation
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.17/html/clusters/cluster_mce_overview#mce-install-intro Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: There is no available mitigation for this flaw other than updating the bundled find-my-way library to a fixed version (9.7.0 or later). Where feasible, restricting the affected service to HTTP/1.1 (disabling HTTP/2) removes the attack vector, since the flaw is only reachable through the HTTP/2 request path. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: To mitigate this issue, restrict network access to the user-facing Route of the `cluster-proxy-addon` to trusted networks only. Implement firewall rules to limit inbound connections to the Route's exposed port, ensuring only authorized sources can reach it. This reduces the attack surface by preventing unauthenticated external access to the vulnerable proxy. Workaround: To reduce the risk of exploitation, ensure strict access controls are enforced on managed clusters, limiting the ability of untrusted users to deploy or modify pods and thus inject malicious content into container logs. Additionally, users should exercise caution when viewing "Raw" logs from potentially untrusted sources within the hub console. Workaround: To mitigate this issue, ensure application code validates the size parameter passed to customAlphabet or customRandom, rejecting or sanitizing zero-value inputs before passing them to nanoid. Workaround: Sanitize all user-supplied integer inputs before passing them to `nanoid` or `customAlphabet` functions in the `nanoid/non-secure` module, ensuring the size parameter is strictly a non-negative integer. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely. Workaround: To mitigate this issue, implement strict Role-Based Access Control (RBAC) policies to limit create and update permissions on `clustercurators.cluster.open-cluster-management.io` resources to trusted administrators only. This restricts the ability of less privileged tenants to exploit the vulnerability and escalate privileges within the Kubernetes environment. Workaround: To mitigate this issue, restrict the ability of tenants to create `ClusterCurator` resources. Implement Kubernetes Role-Based Access Control (RBAC) policies to limit `create` permissions for `clustercurators.cluster.open-cluster-management.io` resources to only trusted administrators or service accounts. Alternatively, deploy an admission controller to enforce that `metadata.name` and `metadata.namespace` fields are identical when `ClusterCurator` resources are created, preventing the vulnerable condition.
🔗 References (28)
- selfhttps://access.redhat.com/errata/RHSA-2026:59593
- externalhttps://access.redhat.com/security/cve/CVE-2026-13676
- externalhttps://access.redhat.com/security/cve/CVE-2026-19130
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-39835
- externalhttps://access.redhat.com/security/cve/CVE-2026-44740
- externalhttps://access.redhat.com/security/cve/CVE-2026-44990
- externalhttps://access.redhat.com/security/cve/CVE-2026-45623
- externalhttps://access.redhat.com/security/cve/CVE-2026-47219
- externalhttps://access.redhat.com/security/cve/CVE-2026-54272
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-66794
- externalhttps://access.redhat.com/security/cve/CVE-2026-66795
- externalhttps://access.redhat.com/security/cve/CVE-2026-66804
- externalhttps://access.redhat.com/security/cve/CVE-2026-66805
- externalhttps://access.redhat.com/security/cve/CVE-2026-66808
- externalhttps://access.redhat.com/security/cve/CVE-2026-67213
- externalhttps://access.redhat.com/security/cve/CVE-2026-67214
- externalhttps://access.redhat.com/security/cve/CVE-2026-69153
- externalhttps://access.redhat.com/security/cve/CVE-2026-69192
- externalhttps://access.redhat.com/security/cve/CVE-2026-73086
- externalhttps://access.redhat.com/security/cve/CVE-2026-73266
- externalhttps://access.redhat.com/security/cve/CVE-2026-73267
- externalhttps://access.redhat.com/security/cve/CVE-2026-73268
- externalhttps://access.redhat.com/security/cve/CVE-2026-73269
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_59593.json