RHSA-2026:67842HighCVSS 9.8

Red Hat Security Advisory: Multicluster Global Hub 1.7.3 security update

Published
September 16, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (21)

📋 Description

CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root CVE-2026-33815 — github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-34040 — Moby: Moby: Authorization bypass vulnerability CVE-2026-46604 — golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via invalid TIFF image CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data CVE-2026-50151 — oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-71235 — github.com/absmach/magistrala: Magistrala IoT Platform: Arbitrary Code Execution via Unrestricted Script Execution CVE-2026-71576 — multicluster-global-hub: multicluster-global-hub: Manager trusts self-asserted evt.Source() for leaf-hub identity in all status handlers CVE-2026-71577 — multicluster-global-hub: multicluster-global-hub: Spec-topic Read ACL leaks bootstrap kubeconfigs to all managed hubs during migration CVE-2026-75762 — multicluster-global-hub: Manager trusts self-asserted evt.Source() for leaf-hub identity in all status handlers CVE-2026-77849 — grafana-global-hub: grafana-global-hub: Hardcoded Grafana admin credentials (admin / admin) in pkg/specsyncer CVE-2026-79921 — github.com/rabbitmq/amqp091-go: amqp091-go: Denial of Service via oversized AMQP payloads CVE-2026-80220 — postgres-exporter: postgres-exporter: pprof profiling endpoints exposed on unauthenticated metrics listener CVE-2026-80221 — grafana-global-hub: grafana-global-hub: Direct database connection string with embedded credentials passed as environment variable

🎯 Affected products22

  • Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:11066fb9dd7c5eb0264356f94f647b21040be8afcbaaa6edde3f331f26df9ddb_ppc64le as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:b46207d31581411bb23599249bed969d18d0cf1b307f4330c1ac7795cec45dbe_arm64 as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:ecff4e70310291b88bc9feea15ef398806134ac8702b168843333d082f626584_s390x as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:f4fcf5ebf61d34197552258d2fed70fe3ab6ceb0fe95a5cabe4d343356920d8b_amd64 as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:5fa26d8fdf99b4d54a5873a677e6f49ee5e75ac5d54d3126fbafc6f3fd54150d_ppc64le as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:8373764397a6f93efcc70e99be24d8ea9d4a8c2b56c943ad91ea7c8a6aff258c_s390x as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:d207ab760660ed450de4158912a65063b014f5c27ca1f6a9b85f1fa74c7d1bfa_amd64 as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:e1431b8e7defcc9143145c3ef393b6e28d417aae56f970581acbdb7d1ed87653_arm64 as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:4ef6d30eae3bb4894056f2c64cf7999cc0ea6da3b95cb943d3f2af8e784a0b61_s390x as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:52378f145b71730fd00936117e7ca5b9759216748a0d453a70cd47606efb384c_arm64 as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:6b9ede59fdcb7f1756369929b3c83c362f30a8a7730d242ccd99d1ac08893881_amd64 as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:af05905391a314b425086e819c7c5336b43a0695ae4cc4fd990a8c657a4a3dea_ppc64le as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:91be545e9c67fae82ec298439fa98da87d7add142b8d6e30751300a062ee0b35_amd64 as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:32991c61ae06fdc8326e51920c15f77d340b2520d5c969d20c8406d709e075bc_ppc64le as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:b1c16ba311296baef2fb01c268e9e1c60131947aeefdb4ed5015c83e12c3e5fb_amd64 as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:bfe69541ac625eccdbda310e82fa67dd555ac4b83265dfccd09dcf89efe24dae_arm64 as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:c6bfc03ef8202743b1aab7115d10837d8e7ca19a32ac76f92b6a2e4b37836493_s390x as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:12b14d7e21b0ec1a23b04e8bf0f0a26371d831364631256d70f1115e6b668152_s390x as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:2457ed4af69bb79ad0200723124be2be1fade8245f15974547b95215b1a84869_ppc64le as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:df27e324a758d914eab80dc0ab73d34c38c7c81fdc3884884737a252722ae6d8_amd64 as a component of Multicluster Global Hub 1.7.3
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:e188a4e40913230b8562f2d8bb7b06af4e486570eb5135ff812eaeea51b05511_arm64 as a component of Multicluster Global Hub 1.7.3

✅ Remediation

For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/multicluster_global_hub/index Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: There is no complete inline mitigation for this issue; the fix requires upgrading golang.org/x/image to version 0.43.0 or later, which validates the strip offset before use. Where an immediate upgrade is not possible, exposure can be reduced by not decoding untrusted or externally supplied TIFF images, or by isolating TIFF decoding in a sandboxed, restartable worker process so a panic does not crash the primary service. Workaround: Upgrade to oras-go v2.6.1 or later.

🔗 References (24)