Red Hat Security Advisory: Multicluster Global Hub 1.5.8 security update
🔗 CVE IDs covered (23)
📋 Description
CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
CVE-2026-34040 — Moby: Moby: Authorization bypass vulnerability
CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers
CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering
CVE-2026-46604 — golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via invalid TIFF image
CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data
CVE-2026-50151 — oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload
CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input
CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution
CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
CVE-2026-66792 — multicloud-operators-subscription: multicloud-operators-subscription: IsClusterAdmin() trusts user-settable annotations on managed clusters
CVE-2026-71235 — github.com/absmach/magistrala: Magistrala IoT Platform: Arbitrary Code Execution via Unrestricted Script Execution
CVE-2026-71576 — multicluster-global-hub: multicluster-global-hub: Manager trusts self-asserted evt.Source() for leaf-hub identity in all status handlers
CVE-2026-71577 — multicluster-global-hub: multicluster-global-hub: Spec-topic Read ACL leaks bootstrap kubeconfigs to all managed hubs during migration
CVE-2026-73500 — etcd: etcd: Denial of Service via unbounded TLS handshake goroutines
CVE-2026-75762 — multicluster-global-hub: Manager trusts self-asserted evt.Source() for leaf-hub identity in all status handlers
CVE-2026-77849 — grafana-global-hub: grafana-global-hub: Hardcoded Grafana admin credentials (admin / admin) in pkg/specsyncer
CVE-2026-80220 — postgres-exporter: postgres-exporter: pprof profiling endpoints exposed on unauthenticated metrics listener
CVE-2026-80221 — grafana-global-hub: grafana-global-hub: Direct database connection string with embedded credentials passed as environment variable
🎯 Affected products22
- Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:17236075a8c306b9a86901c9b5a3e63c4f6172d36f805ef3b4aed4164749de33_s390x as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:313173e8a1fe02c23355e007513d85ef53036f1c435a82cfe3107dc94cbcb05b_ppc64le as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:58a4bdb32f3f7bcb254f76ae2c481b34211145ebd11a7113cefedb4e93f82e55_arm64 as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:b8dc820a44a21ac696952d251386783d263c2eef3d07cbcb2ea5b3daf1a685cd_amd64 as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:05292f84200ca63b7137908c5167d2ea54edb9cb8cb374a3dfc36e9295072c26_arm64 as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:757da547015422bed176779aa586b3116eb4abc58b01ed446caf67925d8b014f_amd64 as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:c1db7a5d38c35963770e0e65db0028d87650d80189bff3afa54c4e832343471c_s390x as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:f2c5a73058dcfef186abf65044a1ce2e900be467682f7d67d7c646196268f87f_ppc64le as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:1835c0a3aa84ca5c21ad010dc6f34f24c6a00321b6b7fa77c768352a5b50340a_arm64 as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:3ba4aef856fff40306d12ef5b7b52eef43d60cc24c8463afb03dea3c30118e65_ppc64le as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:853d7401081ff240e619ca0c0973e208af53f11d8f3d00eac0b142096c7f5571_s390x as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:cf0ef75db27ac45c3b4ce70a32a64f16f6730c35239f6de05cb71804d3013be3_amd64 as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:33842a0dcd762262f57189243611517169e46e12b29799fb1328cef6ed1f159b_amd64 as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:238f8f79c25cd8cffc52ee18b0a6ee404a7a890d42800aa2b19e28f5ba583554_arm64 as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:2ec38f72cb1bfef50586a9d47e0a35fe5c5940920b2f2bf8a104db074efa617a_amd64 as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:dd5325f24d9ca4acae653f97adacc28a829b874c3e3afa19180feba0f3849929_ppc64le as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:fca22af3e9921a4cb3ef36f327a5d1008579f56bbf01e79f59c82970601dee73_s390x as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:75b73e6b5eff1d02d994db5f76dfedbf7fb52f99bbd9defcd1331bfe11813446_amd64 as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:afb6a321ed95f17754bd6a2037d8c44dfbd53cf501c20fc85afcf7aaeaad53df_arm64 as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:c84ba4fbcfe5256c92f28c7e21b17e5b6c92a7be07550486bcbb6ab3d558970b_s390x as a component of Multicluster Global Hub 1.5.8
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:cc2eba544a7bbd2e0e553c4047d4fdafc3f8df62400ae0564503b60a0ef1c6c9_ppc64le as a component of Multicluster Global Hub 1.5.8
✅ Remediation
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.14/html/multicluster_global_hub/index Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: There is no complete inline mitigation for this issue; the fix requires upgrading golang.org/x/image to version 0.43.0 or later, which validates the strip offset before use. Where an immediate upgrade is not possible, exposure can be reduced by not decoding untrusted or externally supplied TIFF images, or by isolating TIFF decoding in a sandboxed, restartable worker process so a panic does not crash the primary service. Workaround: Upgrade to oras-go v2.6.1 or later. Workaround: Restrict network access to the etcd TLS listener to only trusted clients and networks. Configure firewall rules to limit inbound connections to the etcd client port (default 2379) and peer port (default 2380) to authorized hosts. This reduces the attack surface by preventing untrusted network attackers from reaching the vulnerable service.
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2026:71597
- externalhttps://access.redhat.com/security/cve/CVE-2026-32282
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-34040
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-46604
- externalhttps://access.redhat.com/security/cve/CVE-2026-48586
- externalhttps://access.redhat.com/security/cve/CVE-2026-50151
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-66792
- externalhttps://access.redhat.com/security/cve/CVE-2026-71235
- externalhttps://access.redhat.com/security/cve/CVE-2026-71576
- externalhttps://access.redhat.com/security/cve/CVE-2026-71577
- externalhttps://access.redhat.com/security/cve/CVE-2026-73500
- externalhttps://access.redhat.com/security/cve/CVE-2026-75762
- externalhttps://access.redhat.com/security/cve/CVE-2026-77849
- externalhttps://access.redhat.com/security/cve/CVE-2026-80220
- externalhttps://access.redhat.com/security/cve/CVE-2026-80221
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_71597.json