RHSA-2026:67542HighCVSS 7.7

Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.16.5 security update

Published
September 15, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (12)

📋 Description

CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data CVE-2026-55969 — thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-66780 — submariner-operator: Broker ServiceAccount Secret (token + CA) logged in full at TRACE verbosity CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-89060 — stolostron/multicluster-observability-addon: Cross-namespace Secret disclosure in multicluster-observability-addon via unvalidated configuration references

🎯 Affected products189

  • Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:12c03e203c1e3602302a1bf5bc897effd04f4bebf637282463b2fe9060ed73b5_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:bcc1fb8a0409911a46c2cb45c61b3c62d04619f90e9e87a1e6dadba5e93394c1_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:d385f686400d70dd0289c6130dee8d01ef41c8758e86cf80f521b9e7aab180f2_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:e0674e7959cb094957a174e51a699969cf396c3d0bebb6c850ae1a2451aca4e8_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:57105911a22500e4a4d97e15fe6a8a79c6bd74182223d5fd2e28b9c50cce3575_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:85f2c49f6ed85cb743238f3ff0f182f778820c0b0b832e228491acfee892272c_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:a4efa41025264e068ac814e6910fd8aefeff6655e90e34925e0a2fe83b31f9ee_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:aadf8ababb8b969bd3954cb8e9e3e2e4b2c8c0ca77259d6bb0d16ab2e8c39359_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:20af3491bffb8950ea80b02650579f59105bb05ff0bb0befd6b19f28a02c7199_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:65bff2d215bc7e0d43605af962e3feaa34baef498dba3a4bc7f485d105bafaf9_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:6fc3a9857415b6a8f568c9c0b5e9b8dad7d98f5f0b7a941d1912bff02d6d2406_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:af856b3350eb53452f4e04d27a1ea7ecb7aa2cb2fb9a18de2eef03b9be2be733_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:42e61c4c2ae3f8ec0bd344a495d913e1c4539e2fd4bf9eea0f6071e97abf06f2_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:726bbd038d6ef81ab88e80a806e99a5a0a6d1b2427465a3943eeb87ee0dc2abb_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:9ef736948f8ef15c879eaa994ae47b58ea4d65dcd18b273a514d25a19232d4fa_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:ebf61801b40113dd577422f38bedc45868c00ed22aee1d5a4dbfbbffe3fc21ef_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:49f72d87fade9078149bfc353d191438c62636e447867ee595b45bbe4c69207f_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:6163b507a8c699995fe5b835565b222fd5964d11e54d54595790502f98c247a5_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:acb792b8e8db517f896f023f07f6901a24c510b667cf2327b975be1c3170d887_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:b882b9f56c3649d5f893d6cf9ec2469911b0b4685ce0a9ff2949fa34b412e9b7_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:93e9d2ada0ac227f7065f1e96282891a27e11c868a86606e71b4c936f711e032_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:bd5309afabd8ee60de47f0a730b4868d25a570c35b9ab72a7f314b7ffc6fdc51_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:d3a78739c7b2381e6ee7d085168f80be5055ada58668ab597f874b0d1171628e_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:fece2c51ecc1ebff09d332d70156e499797949a7b99b5266494d7d42ef3f2cb0_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:1502b7802adf33c569b80b0fb8573609fc738853e188e16c127ee3bbada76a44_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:20c87905d3b1618ffe21ab10df4457eddb4d1c85d5d4f377f84ec86355cf5677_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:59e219b2b8852dd8cf0bfaa10522bc753307b33f6c125415d4727b16e3423daf_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:e987b5f14c82ba483c659ca14a27eb85352078c653cfce99d150c80dce160fb5_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:246fa1b7e295e2b766a1a91183b857ee062ff6c6d9781c57a590b8c9509c91ea_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.16
  • +159 more not shown

✅ Remediation

Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later). Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams. Workaround: Disable MCOA log-forwarding and tracing capabilities that use ClusterLogForwarder or OpenTelemetryCollector resources.

🔗 References (16)