Red Hat Security Advisory: Multicluster Global Hub 1.4.9 security update
🔗 CVE IDs covered (23)
📋 Description
CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
CVE-2026-34040 — Moby: Moby: Authorization bypass vulnerability
CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers
CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering
CVE-2026-46604 — golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via invalid TIFF image
CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data
CVE-2026-50151 — oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload
CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input
CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution
CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
CVE-2026-66792 — multicloud-operators-subscription: multicloud-operators-subscription: IsClusterAdmin() trusts user-settable annotations on managed clusters
CVE-2026-71235 — github.com/absmach/magistrala: Magistrala IoT Platform: Arbitrary Code Execution via Unrestricted Script Execution
CVE-2026-71576 — multicluster-global-hub: multicluster-global-hub: Manager trusts self-asserted evt.Source() for leaf-hub identity in all status handlers
CVE-2026-71577 — multicluster-global-hub: multicluster-global-hub: Spec-topic Read ACL leaks bootstrap kubeconfigs to all managed hubs during migration
CVE-2026-73500 — etcd: etcd: Denial of Service via unbounded TLS handshake goroutines
CVE-2026-75762 — multicluster-global-hub: Manager trusts self-asserted evt.Source() for leaf-hub identity in all status handlers
CVE-2026-77849 — grafana-global-hub: grafana-global-hub: Hardcoded Grafana admin credentials (admin / admin) in pkg/specsyncer
CVE-2026-80220 — postgres-exporter: postgres-exporter: pprof profiling endpoints exposed on unauthenticated metrics listener
CVE-2026-80221 — grafana-global-hub: grafana-global-hub: Direct database connection string with embedded credentials passed as environment variable
🎯 Affected products22
- Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:05c8f1b6564d0c994a24f41141ecbe80855e1d9a3c345bd0f4c056e6622bd2c8_s390x as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:37e9a14b3cadd534b6673239c77280d8ba1d3406fa6bc67e69689747f2f2145c_amd64 as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:3a4f0a22d43f48ef28fc5bfbf3deaef763a27057d798eecbd684155d1675125c_ppc64le as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:8d7c2a5e1975a8ddca99c30b4a42eb31f0a7966934dbf06baa65c73299b0892b_arm64 as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:0c07187e0d8f4c54b3731f146c9dd835f7c506888ca134498e072e19bc94ecc6_amd64 as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:3187a7f244291f05f251a8ae768e1cb426dc77cfdd618590cb794ef2c3fb5097_arm64 as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:3f0beed65a33c11b9c6b05bee51cf82d4ccdb1c58f478fd07043306f1dc7904a_s390x as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:fa1eb15dfc5b1a70f4aa2f7a08c638636f65f7f4ca16b5a22d9d5039e4a784db_ppc64le as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:19ac9a531acb74dc7744768b332a66fed272f12e85e4f8fd5e79a6bf13c4f492_amd64 as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:90239f65825c5d90b6ebcc1cd78baf45614c04c939f127a0bf4d462021fcf379_arm64 as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:976e21c6ce39e8902740452881a460ce08e939716053998a95a80c9ccfa7ebb6_ppc64le as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:99cddcc48a66352ea886f8f7cb1f9edd52cbab5c0b728e91b92e3b1d4a48455b_s390x as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:e65239d6de659e16993cb5bc3f3c5f9c4e32e6329632a1203c5b11894781c01c_amd64 as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:2be51558f1b6ee44461a1a311ba479de4728da4777fef5950bce7254f24ad960_amd64 as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:a3f1a5b471adf61d2c2d2cc057bf12fe573681a1ca7fe82a56fd8a4f127a82f8_arm64 as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:abf9507ea92208b6c7b3ba3a11aa00163fe44720e90302a3edd15bbdabfd89cb_s390x as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:f7c97db6dea7e57b647c6536d69aa718a94569c3ecb94d6fdc858b47a2eda396_ppc64le as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:15bea39bf05f2c097d77771b481e6ddd20cedb4a4e59e49db004b7582294e61e_ppc64le as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:1935d279f46862eeb512bb4157e482832359effd86c4b455d9653c4637a5e05c_amd64 as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:3bfcf80b7b5ec26d710e9d792dde397dbf064dffe76acb67085b4f34ba2ca653_s390x as a component of Multicluster Global Hub 1.4.9
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:f8e71dc10b51ac2173107505522bf2943a451ad22a3856d79da00cd3c22c48d8_arm64 as a component of Multicluster Global Hub 1.4.9
✅ Remediation
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: There is no complete inline mitigation for this issue; the fix requires upgrading golang.org/x/image to version 0.43.0 or later, which validates the strip offset before use. Where an immediate upgrade is not possible, exposure can be reduced by not decoding untrusted or externally supplied TIFF images, or by isolating TIFF decoding in a sandboxed, restartable worker process so a panic does not crash the primary service. Workaround: Upgrade to oras-go v2.6.1 or later. Workaround: Restrict network access to the etcd TLS listener to only trusted clients and networks. Configure firewall rules to limit inbound connections to the etcd client port (default 2379) and peer port (default 2380) to authorized hosts. This reduces the attack surface by preventing untrusted network attackers from reaching the vulnerable service.
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2026:67516
- externalhttps://access.redhat.com/security/cve/CVE-2026-32282
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-34040
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-46604
- externalhttps://access.redhat.com/security/cve/CVE-2026-48586
- externalhttps://access.redhat.com/security/cve/CVE-2026-50151
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-66792
- externalhttps://access.redhat.com/security/cve/CVE-2026-71235
- externalhttps://access.redhat.com/security/cve/CVE-2026-71576
- externalhttps://access.redhat.com/security/cve/CVE-2026-71577
- externalhttps://access.redhat.com/security/cve/CVE-2026-73500
- externalhttps://access.redhat.com/security/cve/CVE-2026-75762
- externalhttps://access.redhat.com/security/cve/CVE-2026-77849
- externalhttps://access.redhat.com/security/cve/CVE-2026-80220
- externalhttps://access.redhat.com/security/cve/CVE-2026-80221
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_67516.json