RHSA-2026:67714HighCVSS 8.8

Red Hat Security Advisory: RHACS 4.11.4 security and bug fix update

Published
September 15, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-46600 — golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-56864 — golang.org/x/mod/sumdb: golang.org/x/mod/sumdb: Integrity bypass via malicious GOSUMDB CVE-2026-56865 — golang.org/x/mod/sumdb/tlog: golang.org/x/mod/sumdb/tlog: Supply chain compromise via transparency log tile verification bypass CVE-2026-67313 — axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON CVE-2026-67321 — axios: axios: Denial of Service via object serialization bypass CVE-2026-75838 — dompurify: DOMPurify: Cross-Site Scripting via IN_PLACE sanitization CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing

🎯 Affected products48

  • Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel9@sha256:20dcc92179b27c68ac813377d81196b9f4f0ce7e8eb589a16ebcbf01fc497ec9_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel9@sha256:71e2aeaed00e891f1c042e378ffddda7af33ef77361e3c6c4ea3ff3ef845ab28_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel9@sha256:87fd2d66a69b3f0cc618df3e5ee5b802247c7c2289b133df8a77adb83273c0f9_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel9@sha256:e7c60b513d6232b4e7032ce3911477130f4d83f1ab4a7d1369e981af73f07881_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel9@sha256:048d369716141af400f03209b3db7ce9e59492687630b298e632d6ab22f746ac_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel9@sha256:661014b7b3c50b5497bb7349f896415e9893d4053506d2783210e1ea1268cde5_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel9@sha256:9080477328bdaf1b4d86a2ea92c69abf92907b33ebb2e5e85a69f3a75b81644c_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel9@sha256:a41a86cacd15f563f725305f6168b0412743167677ef94739ca40188117df03a_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-fact-rhel9@sha256:1addb59c97b2740a4379cc084dae8c5bb4a1bd30b7acad2661688fe5b5391ad3_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-fact-rhel9@sha256:bddf2904de7192d81c6073eea143f259f9931fb144c4d4aa93de29a149fee93c_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-main-rhel9@sha256:75efce54d3c9f4018cd49e2ddb1538cb15220907e9ce87e3fb9024c98972d838_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-main-rhel9@sha256:7a103abbda45856d9a452adececd7c3d5ddcbf5bef1174ce1f03e9dde2ad1497_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-main-rhel9@sha256:c29bc100783b563e98a69a14bf804ec27154d59a1afeb03445d8cf09728d5648_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-main-rhel9@sha256:db8e55f5930ff9cdaa4157e22b079bd940ae1af24a4612a1aaa423c2991bb670_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-operator-bundle@sha256:347a16467b2685d3984307f64d688b7a04612a3587241325c29df936a8ca8625_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-rhel9-operator@sha256:10f8b89f86f262c900a2411a1f51d8d1b470aa9bf0e235196cbc8704a70fc4c4_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-rhel9-operator@sha256:3eddadaffde572beb6f6be1a5278079db17dd9b688f6c17d2af294640d25de3a_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-rhel9-operator@sha256:8d43d3b7477fd3964629f76c32c034ce80da5f1fc5209e3efadcca3f1eaded1a_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-rhel9-operator@sha256:ebb10fa5a737080fcbeae0f667c44455a1cfad8c1ec8da0848626d3591f9bab2_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel9@sha256:151d4cfcfe658f9b8dd8e96da73e206d3542cde42aebbb12f6a78df6da28f9e8_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel9@sha256:66baff5ebd4690964d13959f06dac3e290633c9bd4ea7e94e2d8bed699274c87_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel9@sha256:993c8a4235295580bcca4a39f69f3d186022521e2df611c28ce1717559e8e4d9_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel9@sha256:d3ac995dedc65b9c35c1dadabda90bfdba2a98fab6c40559dada3901e8abb03c_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel9@sha256:00e34e6dde53107cae2590d9c225ed84326a613d5b6c1b08cd382ca0ea008ba8_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel9@sha256:41ee7f98ca41160f51202fe5fa9bd605e8cfae9e4c9ab0596df0d4033bd25b1a_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel9@sha256:45be09d8a5fc2d587caa4a21753a0fa6396b3b3c46930295cea0f36d9efa76f4_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel9@sha256:7e5467fb3bf719f9ebad59e9410708ddce1a74a959fe52ffc56455a25eedeb60_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel9@sha256:25489738ca30933709cb58f6ec78f95c58eeffe4a78ac3e05b3ded42be782063_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel9@sha256:a6d718cbb81e354cf8d6d5dbdfa804ef46037c36cb6798bfa666593d05294108_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • +18 more not shown

✅ Remediation

If you are using an earlier version of RHACS, you are advised to upgrade to the version of RHACS mentioned in the synopsis and release notes in order to take advantage of the enhancements, bug fixes, and/or security patches in the release. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: No mitigation is available for this vulnerability. Update the affected packages to golang.org/x/mod version 0.40.0 or later, or Go toolchain version 1.25.13, 1.26.6, or 1.27.0-rc.3 or later. Workaround: To mitigate this vulnerability, avoid using DOMPurify with a custom IN_PLACE sanitization configuration that includes an element-removal hook. Default DOMPurify configurations are not affected by this flaw. Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stringify. Where qs.parse is used directly, set allowPrototypes: false unless prototype keys are required. For Express applications, review whether the default query parser configuration is necessary. Wrapping qs.stringify calls in try/catch can limit impact to individual requests.

🔗 References (18)