RHSA-2026:68681HighCVSS 9.1

Red Hat Security Advisory: Red Hat Migration Toolkit for Containers

Published
September 17, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (34)

📋 Description

CVE-2026-14257 — brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function CVE-2026-16221 — fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-59873 — tar: node-tar: Denial of Service via crafted gzip bomb CVE-2026-59874 — tar: Node-tar: Denial of Service via malformed tar archive header CVE-2026-67313 — axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON CVE-2026-67314 — axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth CVE-2026-67320 — axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter CVE-2026-67321 — axios: axios: Denial of Service via object serialization bypass CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass CVE-2026-73088 — browserslist: Browserslist: Prototype pollution leading to denial of service CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results CVE-2026-73566 — tar: node-tar: Denial of Service via crafted long-path tar archive CVE-2026-73643 — js-yaml: js-yaml: Denial of Service via exponential parsing in flow collections CVE-2026-73646 — postcss: PostCSS: Information disclosure via path traversal in source map auto-loading CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-76844 — webpack-dev-middleware: webpack-dev-middleware: Information Disclosure via Path Traversal CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies

🎯 Affected products12

  • Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-controller-rhel8@sha256:87f134b3db20370a415bb96123c0690d598a93610f89b45823b830d281f36c6c_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-hook-runner-rhel8@sha256:b09dab61882a823bc8e5096ea1d62ddbfd1837bb6df5bf756b332935c4943bbb_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-log-reader-rhel8@sha256:9961d5c585af5831ab25f440ca32f958485a3eb84d6cce7173a7167432778f84_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-must-gather-rhel8@sha256:8e4d03a2c6e77c84439e8def9c36953576011cd224cfd50cfff9242180e6c4d7_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-openvpn-rhel8@sha256:ce435846f362de451154a574817756b44f5e1fa5d31094987a4be8935f81eb14_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-operator-bundle@sha256:8bcf84ef7c8c79bd2224b861a051917b2cce9549863fea896cbe03a513177171_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-registry-rhel8@sha256:42b6863e399bd9f95aedaedd769b5d607db2412fcaea016119bc0ff881ee125a_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-rhel8-operator@sha256:467ef1c1acaa26dffd410f265900b6db4d0f88caf3f72df376a355c0820e4298_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-rsync-transfer-rhel8@sha256:b0162a8598f4f1acf18c94bd27aca8104f1b3a4e036b8f698be05e4cbab62575_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-ui-rhel8@sha256:cc6bb647f74d614d696b8d7be5f25de0a9aebe013457495e2806b732bcbfa241_amd64 as a component of Red Hat Migration Toolkit 1.8
  • registry.redhat.io/rhmtc/openshift-migration-velero-plugin-for-mtc-rhel8@sha256:1ef05217f688e882b2354cae164a2ae7f1e24ae793dc1f0351f333e5054383f6_amd64 as a component of Red Hat Migration Toolkit 1.8

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. Workaround: Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: To reduce exposure, ensure that the `browserslist` tool processes only trusted `browserslist-stats.json`, `opts.stats`, and CLI `--stats` data. Avoid using the tool with untrusted input sources in development or build environments. If `browserslist` is integrated into automated pipelines, validate all input data originates from trusted sources. Workaround: To mitigate this issue, restrict applications from processing untrusted YAML input with affected versions of the `js-yaml` library. Implement strict input validation to ensure that only trusted and well-formed YAML data is processed. If the application is exposed to external, untrusted sources, consider isolating the application or implementing additional resource limits to prevent complete service disruption. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams. Workaround: Ensure that the configured publicPath always ends with a trailing slash (e.g., '/assets/'), or utilize the default setting ('auto'), which resolves to '/' and is unmitigated by default. Alternatively, avoid backing the middleware with a physical filesystem (writeToDisk: false). Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stringify. Where qs.parse is used directly, set allowPrototypes: false unless prototype keys are required. For Express applications, review whether the default query parser configuration is necessary. Wrapping qs.stringify calls in try/catch can limit impact to individual requests.

🔗 References (38)