RHSA-2026:68515HighCVSS 9.8

Red Hat Security Advisory: Multicluster Global Hub 1.8.2 security update

Published
September 17, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (21)

📋 Description

CVE-2026-17106 — github.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-46604 — golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via invalid TIFF image CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data CVE-2026-50151 — oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-71235 — github.com/absmach/magistrala: Magistrala IoT Platform: Arbitrary Code Execution via Unrestricted Script Execution CVE-2026-71576 — multicluster-global-hub: multicluster-global-hub: Manager trusts self-asserted evt.Source() for leaf-hub identity in all status handlers CVE-2026-71577 — multicluster-global-hub: multicluster-global-hub: Spec-topic Read ACL leaks bootstrap kubeconfigs to all managed hubs during migration CVE-2026-75762 — multicluster-global-hub: Manager trusts self-asserted evt.Source() for leaf-hub identity in all status handlers CVE-2026-77849 — grafana-global-hub: grafana-global-hub: Hardcoded Grafana admin credentials (admin / admin) in pkg/specsyncer CVE-2026-79921 — github.com/rabbitmq/amqp091-go: amqp091-go: Denial of Service via oversized AMQP payloads CVE-2026-80220 — postgres-exporter: postgres-exporter: pprof profiling endpoints exposed on unauthenticated metrics listener CVE-2026-80221 — grafana-global-hub: grafana-global-hub: Direct database connection string with embedded credentials passed as environment variable

🎯 Affected products22

  • Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:2eaab1aa06261c35b7f3fec47792b7884ae04bbb5e631080097c33dbd9ba2a82_s390x as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:4d0554bf41068beee732eac112e5c149dec452f7292a70bef9e9507ed9857be7_ppc64le as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:7c4e86d18a27db792f81bdaca580e5d444bb051d6ed69be5c7fb729bee023490_arm64 as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:9187be523aa0e681bbf08ef19b615269ce0ba3f6a952fe0aa6461bb3b9008795_amd64 as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:02cfdd71deb8fad770bcc7df04e3ce6714fac89d1204796ee2098db9c2d334d0_arm64 as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:8408aa29230ad808dbb415e6ba6676fb20d4a092d51bef3350b803a5fc3173c4_s390x as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:cf3ca46916a9fb1ec3b3a58a61f450cd72a9d96c7e1025373b830f288ac897fa_ppc64le as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:cf4cf3becce69c5e75b3987afaeb06833e92393b178f51ab366f13d224e8f8de_amd64 as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:6c0b3f002aac0debb7d52811d21d9f8fc9d0cf2e9d2aaf92a8f47bf8093481c7_amd64 as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:991fc487eaa4357cd0a2e87e44780e040ee62bf85bbed4ef009e44f0ca88c304_s390x as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:a0f75fc098b74a93989ba73ae780026e549e880ccdca020aaf1a7cb61ec99860_arm64 as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:a6263ed1836ad0d34d120a43b09dcbb2e66a1a57cebc70ebbb6e43ef792ea506_ppc64le as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:67ee22bc6faf683e8ae37ba3cfb4152e6e14bcb477e9929dc27c99062dd8bf01_amd64 as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:5d918eb2a8f66bb88309d3c664a39fdf5f4b114affe94fe53e0b40c530d62cf7_s390x as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:620b374cb76bab0d293481ba3540cdd22663ef9fb67d4f5963726fd2ac4f9b75_amd64 as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:783a800f8a138e3248ca96f861eda148720fd4ba863bc4fae45af754dcce542d_arm64 as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:b1feb02ae99a463d9e6319b71ac4a3eda47de42d5c55142dc03fcf7f003dc24a_ppc64le as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:6f87d47921c4b6161c6ead31676870b12f79ba240c478dd35ff5652313f949fa_arm64 as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:a99ee13ca3a00455bbdeadbffe28c658764a2a938e09e16d15324fe68a0c0e00_ppc64le as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:cb7614e99220c6c8a7aad2d3d825a257b02a6404843f89d593f1a9d61ad22348_amd64 as a component of Multicluster Global Hub 1.8.2
  • registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:d20697adb726ca17dcfec5d1773bd6a43e0c5c82bf730354f7c7aab83e33fbb9_s390x as a component of Multicluster Global Hub 1.8.2

✅ Remediation

For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.17/html/multicluster_global_hub/index Workaround: To mitigate this issue, avoid processing tar archives from untrusted sources. When handling archives from potentially untrusted origins, ensure that the extraction process is executed with the least privileges necessary to limit the impact of any arbitrary file write attempts. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: There is no complete inline mitigation for this issue; the fix requires upgrading golang.org/x/image to version 0.43.0 or later, which validates the strip offset before use. Where an immediate upgrade is not possible, exposure can be reduced by not decoding untrusted or externally supplied TIFF images, or by isolating TIFF decoding in a sandboxed, restartable worker process so a panic does not crash the primary service. Workaround: Upgrade to oras-go v2.6.1 or later. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (24)