RHSA-2026:67538HighCVSS 8.1

Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.11.12 security update

Published
September 15, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data CVE-2026-55969 — thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-66780 — submariner-operator: Broker ServiceAccount Secret (token + CA) logged in full at TRACE verbosity CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution CVE-2026-73646 — postcss: PostCSS: Information disclosure via path traversal in source map auto-loading

🎯 Affected products165

  • Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:6213f3b27f47b0f7a87652bc961c60721ee3ef2e809aaad33dacda706f392670_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:add4ca6f6973eaaebff00ed0c5d3c3d71af95bc9cb003f6c95d7420e74a6adc6_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:cbce66f9f603cb7f7bb33190022ac95575d82dbaaf4c2790cd8e9b353c4895c8_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:ea21c9bb5e7007c35e48cfd70ffe234761b21c089870c781beda7087744ff218_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:38be38a418ffd2863bf745a1115034a65bc1133cf869278fee19376b32f67d9f_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:44d7b45b837421954c0dd5c3c672db77eb7cbe98fe54a0e82a0df8dfb069df3c_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:ae5b5fdc727526f0cde1ef4e2e4b3db045e34d1d849e099e641d0ec539d9bdb7_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:db496a840c8f7bbad9f88ff808b147a7409ef35f126f98287616de3e61041b66_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:5be59e9c830d97c26d674207ce075f88afbcbfa5c3e448881858951509b4d8d2_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:6e3e248820e533889930bd55c675d39cf8821903f91e78fd8402b7b8c196db70_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:8ccf8ff40b9dc391d10735960a9c3eb3ca9bc4bec3a22e063e9e41945c976876_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:f449a6f04909c6f7a02dbb603e20a76adbd81f3381b1f0504fdab8774eb57470_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:2d281c0306744a16f86bbc497e81ce31d4d22a1872e5cb4091ee6fa712fd30d7_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:46e334bdf1afd4b1355732f3cbfc13c2a9ecc84a4ba4216e2a73dd8a51789dfd_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:d1a70d2e096bfbb1e29bee791d91e2e1c4bcfc4bfd6a566f8bd576c275206327_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:e2fb5bfe6430cab69bcf3d8e11a079d9cb25f3f88927e43f08ef70aad1f07a63_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:2f6d13370ad07950e91ed2c17224510f1a6448e9510f2b8ca2ef02a0d1d614ca_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:5936915288f80fdeb30eea8ee777b1a317c0c10f31faf6a234fcdecb6257fd6d_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:e08edd68460a92c192972326f9645cd1aa49c5e20e62edf08710938e1ba8d27f_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:ef85b072ceb581215e1ab8b1f7d28285ea350e11726ac612ab259d667caf253a_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:0396cd551344170d4589409eb99b7646bc6b0102132ecca1702a661502d2d75e_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:0787166d0335ed631ffc9c50bf2e61ddea130da73aef1fdea453f708ec5e0e38_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:66313df28749a50a6905d8e4d89638b27a3dfc63e5a4b62a5d9ba1b95d27a63b_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:b694e85ec14e5022c1a3a51fef45c4bb0a190b1d6df8e01f6192b830c76ac135_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:5fd4bc298d56902a866ed0303944a2df62f0e9239584dc1da395790d860f88dc_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:c602e84c5b6ce4b59b1b6ca2cf8b0cf2cd72cfaa4942f79ed1a68604ebab15d6_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:e15cd8194de068c5c95f2e1762e1dab4142edac8eb4514fd09f025f6ee943f58_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:e4a47a41fee17e06212841ac746991cb78ffab3d80d81a5aeeba27c1a5f9ca7f_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • registry.redhat.io/rhacm2/acm-search-indexer-rhel9@sha256:21e5bebaff778a804a56812b7ecd742a0546b8fe9641d4e0b7bd6a2061c79ea0_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
  • +135 more not shown

✅ Remediation

Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later).

🔗 References (15)