RHSA-2026:67541HighCVSS 8.5

Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.15.7 security update

Published
September 15, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2025-53547 — helm.sh/helm/v3: Helm Chart Code Execution CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data CVE-2026-55969 — thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-66780 — submariner-operator: Broker ServiceAccount Secret (token + CA) logged in full at TRACE verbosity CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution CVE-2026-89060 — stolostron/multicluster-observability-addon: Cross-namespace Secret disclosure in multicluster-observability-addon via unvalidated configuration references

🎯 Affected products185

  • Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:0923086467d404cb360d7ebf9a7495268c332c0e7eb1ba351a675b70ec9e5d19_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:7290d1aafb642bd2268d3287bc6bf08fd48b7cd42a2ae7ab1311dbeb538bee01_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:779da656db7bbeaba66ddcc40d5a666253f27ed30711fe1b737a76b2f55a803a_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:88035238bbc4687adca17b3202a30eea9a8000362413aa83a5e4ea2639374f05_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:1298c7fc55bdc3a1fa3802e800a1fb94019c354be0c22500146137ebd097a80c_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:1c0106b5b3b0a079e1680d8f3d82adf08b36a100b77e9659eb718588daacaab3_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:70255108d20a35fc1994404bdab9a1b026c026a0e0ff2e77f531fd78db965064_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:b32e29bee4238be225be3bec1249a0a45d37e6cbab7d120fdcb1deb6af1217a8_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:1a939530396618490019c85b3768ba806335b38f17ede155a46dc7f659bf05ab_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:433e36dfd9f618c38475a4079b66502e1736d38a83bf35032556f777af683fcc_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:4a96b9c059dc20bfc6e769dc3cbf07c7d17a67f46959aeaeb600dcc005006747_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:5fa3d234dd10341ebc5fe313d51ac83f33a8f255e8a55c1389d5563876245b29_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:aa51d55f0020ad62b15bc752ca06c3be7e03fff352e1de4ff153fabb7cd97775_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:c276213dd4b3137dedecaadcc5d3b99fe779f7fbe37435a30757c8bd084a6133_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:d639f644d4710611664d0b443dbe57234f9f6205c0232afd8a9909c419ff8899_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:f9d19c046170f09dd61ad4c7b89f05bc6ddacd33474ec4941bf78943e22e719e_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:0e373b92d1ded821dd9d112d328c83ce7f53d90e3bfd11130f8ba034428b5527_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:19c03605828c09ba57fe46c58e0755f781e914e124f6d1ac5317e1c0483a6975_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:6df9b91cc8a80eb0300bc78613c6391f93ba2230a71bef076ddf2e9d94d5b76b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:d87d6f32584ea6a5dd7971f08740e1773060c8d600d31a7f017d22f461516c98_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:57d21b960e09abf90923810a32fd14e58e374082e654d2c658372a2680a37f5d_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:a6c696adf57a5b83a1f39bb3bc1c0d8594515b92e63ade64dcc177521e24f583_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:abfee34fc0fe12d68468574a023dfc0d9341cedf6d7ce8fa286a943c25d66431_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:deb2f2272b5d9fb058e3cf21d6dcefd7c0e19dcbc35d7522b535074397732bda_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:1292ae292595f6e744bac765c4972756984cbf65fa234a27deaf96a702b5ac45_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:950dca413c6e827fa2bd7ea78d329c4dcb37989b26b97549e7e715031ee8f37e_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:c001415576967419b737f41f6d43a05de64183ba4297693b7386c52fb8d52fea_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:dddfe83e56580effd63a76c7f093c6ced3c195d2a6da8a0d1f45fb88c5147331_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:26658af5eb510e593a027658abdb63f52aebd973335e82310a9542eca4ddc725_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
  • +155 more not shown

✅ Remediation

Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later). Workaround: Disable MCOA log-forwarding and tracing capabilities that use ClusterLogForwarder or OpenTelemetryCollector resources.

🔗 References (14)