Red Hat Security Advisory: Multicluster Global Hub 1.8.2 security update
🔗 CVE IDs covered (21)
📋 Description
CVE-2026-17106 — github.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers
CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering
CVE-2026-46604 — golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via invalid TIFF image
CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data
CVE-2026-50151 — oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload
CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input
CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution
CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
CVE-2026-71235 — github.com/absmach/magistrala: Magistrala IoT Platform: Arbitrary Code Execution via Unrestricted Script Execution
CVE-2026-71576 — multicluster-global-hub: multicluster-global-hub: Manager trusts self-asserted evt.Source() for leaf-hub identity in all status handlers
CVE-2026-71577 — multicluster-global-hub: multicluster-global-hub: Spec-topic Read ACL leaks bootstrap kubeconfigs to all managed hubs during migration
CVE-2026-75762 — multicluster-global-hub: Manager trusts self-asserted evt.Source() for leaf-hub identity in all status handlers
CVE-2026-77849 — grafana-global-hub: grafana-global-hub: Hardcoded Grafana admin credentials (admin / admin) in pkg/specsyncer
CVE-2026-79921 — github.com/rabbitmq/amqp091-go: amqp091-go: Denial of Service via oversized AMQP payloads
CVE-2026-80220 — postgres-exporter: postgres-exporter: pprof profiling endpoints exposed on unauthenticated metrics listener
CVE-2026-80221 — grafana-global-hub: grafana-global-hub: Direct database connection string with embedded credentials passed as environment variable
🎯 Affected products22
- Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:2eaab1aa06261c35b7f3fec47792b7884ae04bbb5e631080097c33dbd9ba2a82_s390x as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:4d0554bf41068beee732eac112e5c149dec452f7292a70bef9e9507ed9857be7_ppc64le as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:7c4e86d18a27db792f81bdaca580e5d444bb051d6ed69be5c7fb729bee023490_arm64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:9187be523aa0e681bbf08ef19b615269ce0ba3f6a952fe0aa6461bb3b9008795_amd64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:02cfdd71deb8fad770bcc7df04e3ce6714fac89d1204796ee2098db9c2d334d0_arm64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:8408aa29230ad808dbb415e6ba6676fb20d4a092d51bef3350b803a5fc3173c4_s390x as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:cf3ca46916a9fb1ec3b3a58a61f450cd72a9d96c7e1025373b830f288ac897fa_ppc64le as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:cf4cf3becce69c5e75b3987afaeb06833e92393b178f51ab366f13d224e8f8de_amd64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:6c0b3f002aac0debb7d52811d21d9f8fc9d0cf2e9d2aaf92a8f47bf8093481c7_amd64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:991fc487eaa4357cd0a2e87e44780e040ee62bf85bbed4ef009e44f0ca88c304_s390x as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:a0f75fc098b74a93989ba73ae780026e549e880ccdca020aaf1a7cb61ec99860_arm64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:a6263ed1836ad0d34d120a43b09dcbb2e66a1a57cebc70ebbb6e43ef792ea506_ppc64le as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:67ee22bc6faf683e8ae37ba3cfb4152e6e14bcb477e9929dc27c99062dd8bf01_amd64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:5d918eb2a8f66bb88309d3c664a39fdf5f4b114affe94fe53e0b40c530d62cf7_s390x as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:620b374cb76bab0d293481ba3540cdd22663ef9fb67d4f5963726fd2ac4f9b75_amd64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:783a800f8a138e3248ca96f861eda148720fd4ba863bc4fae45af754dcce542d_arm64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:b1feb02ae99a463d9e6319b71ac4a3eda47de42d5c55142dc03fcf7f003dc24a_ppc64le as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:6f87d47921c4b6161c6ead31676870b12f79ba240c478dd35ff5652313f949fa_arm64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:a99ee13ca3a00455bbdeadbffe28c658764a2a938e09e16d15324fe68a0c0e00_ppc64le as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:cb7614e99220c6c8a7aad2d3d825a257b02a6404843f89d593f1a9d61ad22348_amd64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:d20697adb726ca17dcfec5d1773bd6a43e0c5c82bf730354f7c7aab83e33fbb9_s390x as a component of Multicluster Global Hub 1.8.2
✅ Remediation
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.17/html/multicluster_global_hub/index Workaround: To mitigate this issue, avoid processing tar archives from untrusted sources. When handling archives from potentially untrusted origins, ensure that the extraction process is executed with the least privileges necessary to limit the impact of any arbitrary file write attempts. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: There is no complete inline mitigation for this issue; the fix requires upgrading golang.org/x/image to version 0.43.0 or later, which validates the strip offset before use. Where an immediate upgrade is not possible, exposure can be reduced by not decoding untrusted or externally supplied TIFF images, or by isolating TIFF decoding in a sandboxed, restartable worker process so a panic does not crash the primary service. Workaround: Upgrade to oras-go v2.6.1 or later. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (24)
- selfhttps://access.redhat.com/errata/RHSA-2026:68515
- externalhttps://access.redhat.com/security/cve/CVE-2026-17106
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-46604
- externalhttps://access.redhat.com/security/cve/CVE-2026-48586
- externalhttps://access.redhat.com/security/cve/CVE-2026-50151
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-71235
- externalhttps://access.redhat.com/security/cve/CVE-2026-71576
- externalhttps://access.redhat.com/security/cve/CVE-2026-71577
- externalhttps://access.redhat.com/security/cve/CVE-2026-75762
- externalhttps://access.redhat.com/security/cve/CVE-2026-77849
- externalhttps://access.redhat.com/security/cve/CVE-2026-79921
- externalhttps://access.redhat.com/security/cve/CVE-2026-80220
- externalhttps://access.redhat.com/security/cve/CVE-2026-80221
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68515.json