RHSA-2026:72848HighCVSS 8.1

Red Hat Security Advisory: multicluster engine for Kubernetes v2.11.7 security update

Published
September 28, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (12)

📋 Description

CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-73500 — etcd: etcd: Denial of Service via unbounded TLS handshake goroutines CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-84445 — google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests

🎯 Affected products129

  • multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:2a459a2fecd6585291882da8574a008caefa44cc30dba0e44c2b16d3cd8c65d8_s390x as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:3899da686b33ce0a2a8094246147fb362b7a128691b05c3c64687f22ce802a7f_ppc64le as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:bd956f94ca7737d80cc1181a0da671f755b4a26d2ebbcf8d3d2487f9c50597e8_amd64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:ff8a734439ce0baf682cb8d4a810d2e41fd7c8062f4f944b6201824cb5a4a44b_arm64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:6cc6cf4d574b3f67cde0f7eaa7f970cac19006197215706bb13909e21803cf7f_arm64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:bf78a15b9565a9d272f4c8046148d2343a32ba2db5bc43f5cbaa6d3db69e60c5_ppc64le as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:c37aa622686b237e47ee2ad547c59910b4760b6e90cdab28095fd00e82d6c436_s390x as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:fa9c00ba1282e65e429021236cb94a2404534dd0525a0707e01badbf456c05e2_amd64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:a487f8fd3a3666ac754b89e714fafada0d6e5813fb6610f2356fee7d9e47a9bf_ppc64le as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:a5fe95b171042632899bdc34b3ed48f4a71a923746efb7797e478c1f8e5e9067_amd64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:adc17b7452f8433ee2a510884d4cf78de403fef9f90508fbaf3ce204b789e1ef_s390x as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:ffa95927690a2a00d8d5d66af983289ddebdd95dbda98d4d118c180694d28080_arm64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:18175b14e049986a9a64694d18d05f5b7e3a92198a7f3cbefdda214dbbd34f46_s390x as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:615bceb2ac551a7c3b697c7fcb8d0c9ba22935699a4c69bcd2169c22930b2d78_arm64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:7165e0f2f9eb7a25b22e9a8cdbc8d72fdde81355f7d760793c0a584a4ff46208_amd64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:bad00010492f8bec3b6bf83f7203ad7dee26b8cc306672d508d05b0168097740_ppc64le as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:5b9c71a16a08ddcd5ff9297a67d88c3f0fa2b15805f202c8356d526566204203_ppc64le as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:9e86ba728e61c9d103cc1cf4a0aaa178eb9c8b45a73fe872ca11517de7123be7_arm64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:c3ce382828c1af5d141d5043d061a78f2d5d9472eb249689b6155e0a4ba6f693_s390x as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:feb59c2c110bb634e99d91a4ad835d2dde8cb51201a5d3be525b15476c3c5bfd_amd64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:389c82ff2a1e5ab55ca8e68652f6a46686d3e12947cfb16071964f086e29bd5a_arm64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:49c3a8c77e031a07433e5b139acd39834c8c77bc3e05606876b47123186eafa0_ppc64le as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:5ad38fec3ae4ca609be71ca71592c59d95c7de5b5dc96c3560b9967f9df33a04_s390x as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:940c8a66244e38edd65ef9acf4941e5ad1010e1237c8fc4c736e2b6b87f67bb2_amd64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:560048f484368a1bdf41640ad15346665b67734922bc58bdd1d3ad3cbdcb01e2_ppc64le as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:5a35499564b75d2e705606ea80d8f25caf0fa0f412e31275ebd684d55b661bcb_amd64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:5dc477d992c081ea4704b1594ad280d1c6b12b4beeee79a54c8083e462c3c6ad_arm64 as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:8c10149ded75f2daa1b64f2ee0cc4602938cb6ab5b12a4ffdf3f75bd59b9b173_s390x as a component of multicluster engine for Kubernetes 2.11
  • registry.redhat.io/multicluster-engine/cluster-api-provider-azure-rhel9@sha256:2c4a7bcaa799d9c13844c49e65eb2d8384a063342af5078982a6b10a6a54b938_amd64 as a component of multicluster engine for Kubernetes 2.11
  • +99 more not shown

✅ Remediation

For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/clusters/cluster_mce_overview#mce-install-intro Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Restrict network access to the etcd TLS listener to only trusted clients and networks. Configure firewall rules to limit inbound connections to the etcd client port (default 2379) and peer port (default 2380) to authorized hosts. This reduces the attack surface by preventing untrusted network attackers from reaching the vulnerable service. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams.

🔗 References (15)