Red Hat Security Advisory: RHACS 4.10.8 security and bug fix update
🔗 CVE IDs covered (11)
📋 Description
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-67313 — axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON CVE-2026-67321 — axios: axios: Denial of Service via object serialization bypass CVE-2026-75838 — dompurify: DOMPurify: Cross-Site Scripting via IN_PLACE sanitization CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing
🎯 Affected products48
- Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:3de9a655eedf1083624d14b9962b4a4cc144135e8a44442a71eb60e202722644_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:5e5f39993fbc1359a8d13fb37ca822009c20c1689e0c3a8f4c3395f5d949c74b_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:cb1d6c6418808fb46fb80cfb5d2be595e725b0f3c26cbc5094bada783aba33b1_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:f1849d6035f67bf1aec102dcf4a70f8c8af36c0295f05f4758f9ec8ebaafe630_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:4a299c974c5d81cf0d13dfefe606bb9d94360080df39cffdd50c5a196675b3c2_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:6d891c231588a5f4c7dbe4ead7ba38a611215269b0cf306a3515630a9251031d_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:bad2b7d928b7d0e37f0de4513575aed6ac6ef70fed52e8ef75c0d8a1b47c9eb2_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel8@sha256:ffc3676f82694ede87812d32a8e3d4e54040f887e9b61a9d10c7eecfbf8e3e82_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-fact-rhel8@sha256:11951e72cf94502b9878d218034a9347621916d0a589a827a128d61d651fee9c_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-fact-rhel8@sha256:8fc665890ac0b64667a6fc9398218ab81c671f4bbb2fd59e530f9e5f9d51c300_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:0eea132e557817e5336a9d93859add15de83eaadef8024da8d7cb369dffe3305_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:69b607d94e2f41ccecf85af83ed0c279b09e3bf848990c276a68db5079eee715_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:77a3c5eeb672b1e9b739c6f5ff54831d1a0a3cb15a5a8d067dc4d2f4e6a2c24b_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:a1d4524db3af47400cc17e5e7b2165dea5bc7b1b4fdb3d9a047799afca01fbf5_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-operator-bundle@sha256:bb547b85647f5509f0436ba6f2a1f5cf4e06c82c008c9df790060ca1e9b3955b_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:1e6fe63c550e9dc47d97e4031ad630005f180a746b76935a8018ded6a8070b54_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:5fea5c53638a263c33f3b360e2ffb559ee6784d820436b9c7a85813e83fe35d2_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:6bd0c9ee2181df7e2e45edc8d20cb82943b1072c765de1ad451553f11b8f82d2_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-rhel8-operator@sha256:cfe942ff34372eec0867a3612b30bf3319aa854ca55bb9fe59df37ce22a1db85_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:20f3fef4219013320ea66d1522dab67f28916768ba88fc423ab89256157e9938_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:4af080bab1958c6dc3962518296d27414501e1bf5f5cfb18510a8253b454e527_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:5163183b9e89623e9c6cb053fa5f0ac9761b0f004de5cb9734025f0ebeb1fa13_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:c34c3e22d1528265b87d40cf89afe9ad02588eb3388f29f1bde20fe99c8dae51_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:5e9e8c1eec0bbc77ebf6640b7dccf8cf6481ca4aa9dc752f01b13ba288f888ed_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:ae2b9cb5e9edecf81e4962e3ce6f22d983adb68a4a23f1f98c458aa3ecd10f21_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:c36d3e859c91abef5fa21ab3a29c0e1c499d1125d90a6736fb5be700dbd9b529_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel8@sha256:c7fc4b988114435bfeaf4e86e82373599a61b80c12dae7f1e75b2c681849951c_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:0c320b372870150b3dc0274387e35fdb8b95b9c09f068b09216512e9c5d456b7_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel8@sha256:127fd35c1940fae7301e4fc25eb44b1dca3222534778d09a4e859ce9b89f7382_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.10
- +18 more not shown
✅ Remediation
If you are using an earlier version of RHACS, you are advised to upgrade to the version of RHACS mentioned in the synopsis and release notes in order to take advantage of the enhancements, bug fixes, and/or security patches in the release. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this vulnerability, avoid using DOMPurify with a custom IN_PLACE sanitization configuration that includes an element-removal hook. Default DOMPurify configurations are not affected by this flaw. Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stringify. Where qs.parse is used directly, set allowPrototypes: false unless prototype keys are required. For Express applications, review whether the default query parser configuration is necessary. Wrapping qs.stringify calls in try/catch can limit impact to individual requests.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2026:67711
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-67313
- externalhttps://access.redhat.com/security/cve/CVE-2026-67321
- externalhttps://access.redhat.com/security/cve/CVE-2026-75838
- externalhttps://access.redhat.com/security/cve/CVE-2026-82417
- externalhttps://access.redhat.com/security/cve/CVE-2026-84375
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.10/html-single/release_notes/index#about-this-release-4108_release-notes-410
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_67711.json