RHSA-2026:67540HighCVSS 8.5

Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.13.12 security update

Published
September 15, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2025-53547 — helm.sh/helm/v3: Helm Chart Code Execution CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data CVE-2026-55969 — thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-66780 — submariner-operator: Broker ServiceAccount Secret (token + CA) logged in full at TRACE verbosity CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution CVE-2026-73646 — postcss: PostCSS: Information disclosure via path traversal in source map auto-loading CVE-2026-89060 — stolostron/multicluster-observability-addon: Cross-namespace Secret disclosure in multicluster-observability-addon via unvalidated configuration references

🎯 Affected products177

  • Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:1d45c821f79eeec512fdcf757724686c359b958690ded31b7515104b23597d35_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:204d7960e6e25bc3c00cb3fcc19b9c7d3617308a01f0a627d90576b5ee743409_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:2baab0f73e00cb583399e16fa0289660052dfd34708fd75f05a86a1f41967e7a_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:f8322bdcb86dcf5726f665cd28613837052f5cc6e443ff00e1aacc82c0240eff_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:5de8c358924fb5e14a4f1e9cf85a578a005c3c5c123854fd8628c4f6be69951c_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:81e84e37324e4d4972283082eacacb89fdf5c15cc3a9abd8c3785055b21f0de8_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:b67383e989c8ef9be44056559a68ad1d00b9ba0a6b2661eb89fa71d4a635053b_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:c78f2c01a57ea2fcbb99c7f6fa44be586e970c558323c8cf761c603ba19e8f4f_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:21893d98d44e951285ec58eb136ca771be04dfc7b42361fbef7ee9cd1f6ff0bc_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:433878376a3cbcc4f7e78ac98236ead5cc244dde2ec1038519209e28b173ea41_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:77569f9b562bd80c273e88624e8b71c8017ea3ae4595c73d37955a1421e4f0f3_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:def476a1f68998c73c9254b381f979d20e1994a49e17246a9da85525943d83e9_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:41770b1ffb5320968ae5a87379b680b80df1ddbde3b28f3466ad3bb2c611d919_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:6888e5c1420aac4cd4dab8cc6d507ffbc70d93e21916ca05de33791d05dbf037_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:6a6e2de8c0de432256fef05d702138d4eac3e89e4303df2068eb99c89ca2a24f_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:ed8feeba76a4e312c0d7ce28112b7af1a64b651f203fe3a8990d59a4ed9d6750_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:340a549ba9c132aaf971e120b804c88bf56b4bc1c67f1146d0012753b73d2af6_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:618e6b7d374ae42446e016fb147f1df92492251f6216a6eb71780c88f9f5090c_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:a77beaad8d9dea548de133a2da3b8a321447c9048375c1f5e5029a70b486c530_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:afbe0f53c0c5ded35afdbf693b6568c4017ac1ec535d86fa46d3d21c654e4ca9_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:705bc8f6c5f16a7cc51cf4d96d6d192f638285044986d80654ff01e955ed75e4_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:98813d1a8430e0f28b623f1518933da57408578c8d0a2e1288345392777d5637_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:b5ba963ca077138c93014f4d7095bd349e23ba4f6130e5812f805d49995d88b4_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:c7803b27e4d3d17e5f12bab76dda9f69dff85d3ab44efb46a42b621874a516fe_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:512a6ded4d1c0d67ce8332ec142492d49673026d8c49b119ba576c1f8f75721f_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:97781999f171ed53d78eee4081bd28142664e56bc96ad621292fef00f6e4bc7d_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:ad5dca66fbdfe898ddb7ca868625fc045f81d866804f9210521001cc494de28d_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:d3f7b8a016eed5f7b491a623dd45780355ec5af60c81f8688189f078ac39dfd9_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:83584b73c231bcbe5607cc49e836c1db1f88d774f53bfc76d62267343f2b97ca_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • +147 more not shown

✅ Remediation

Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later). Workaround: Disable MCOA log-forwarding and tracing capabilities that use ClusterLogForwarder or OpenTelemetryCollector resources.

🔗 References (14)