Red Hat Security Advisory: multicluster engine for Kubernetes v2.17.3 security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-73500 — etcd: etcd: Denial of Service via unbounded TLS handshake goroutines CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-84445 — google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests CVE-2026-88031 — go.mongodb.org/mongo-driver: go.mongodb.org/mongo-driver/v2: MongoDB Go Driver: Data deletion via query-operator injection in GridFS file IDs
🎯 Affected products141
- multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:248bd1badd121681e9e332d518f8e03690f2aa96c37dedad3836bd581b59fbe8_s390x as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:90ca63c91364cc7f7482be028792cbca07323aab4fa427361b8e93c9217ec60f_arm64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:917ae9b0ff992b03ba2930a2fcf5c09e38a8d557fc7335539b7a9c2a2072a13a_amd64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:b688843712a5c7fb74d12b288deed7e8cff3ab186eb805122dcbb89cdb4b42a3_ppc64le as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:05eefffa684693fe9c35c1979ed78df3eeda88cae5839f28798c6c275d19caa5_arm64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:3e491073179676fcd71e6e97afebd01a2d4a51364db8db79ed2df4fba11f0f84_s390x as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:771fd8060f17f0f5613231b206787c368dcec3e37071d003e478c2f8178906a3_amd64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/azure-service-operator-rhel9@sha256:bbd4183e3f7932a6786925c16fc7842be2920fa4ad800b582ca3062aca9b4e0f_ppc64le as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:1b1dfc25ce999df85fcce278f86482e40281fcd55e6f500b83c83ba38e1e2c21_s390x as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:3000ff022a76f4f9aad0438ce6870ef30f8e604f6ec96f90bcb6b1044ef2a68d_ppc64le as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:a322d35b40702a8cbd3c1487d36c582feee26d5c25a6c1fab8d06ad74206a94a_amd64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:f9a55759fce6542e7b51b9db28b937680b1d9c3f72222e5788b1a5a97c0158ef_arm64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:43055551f58eba463a2c8dd2aa21140042af50da12b6605df640ec4916d4b1e9_amd64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:8893b6c7978e8cd85495968bad6f6c33fc7ab087b52d55fe8fa881cc61863cdd_ppc64le as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:a1dce1854964fd346ca5351e64e2ba8f7b1bc88717efa4c0d4b06670d8a16884_arm64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:e8b7de2ebf426b02c2af716dbab5dad138d176223f41df4d0dd426603e5edbd8_s390x as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:09ce5efab083829ca750bdc7e750c39ef099b82bc388612edf52b2c49b9f925d_ppc64le as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:23f3308d5a98f72582ffc461dd0d80d424ee4f26cb27101289ff98e09337c49f_arm64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:705d399c91d752ed6e1d41a20f6a7d478286fc5a0d54e203bb38ae88e03e43e9_amd64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:835c2b3e94e8610fa7ddd8f9d08c4f94563e1a91fb919d541f141693f4c52808_s390x as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cloudevents-conductor-rhel9@sha256:078672e6554885e6a702c9e9809cadd37409fcc0bf9b4b78bd1b27689fea4867_arm64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cloudevents-conductor-rhel9@sha256:521df8ac831b7ded20053c99347fecc71357c5411a14ce8a0f26a4c5b09c9229_amd64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cloudevents-conductor-rhel9@sha256:83637610fea363def2db1824952026aec0a62a9eda9e196ba30bcbbc5a3d3402_s390x as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cloudevents-conductor-rhel9@sha256:fbd14c00c1b4cf21f2ff9daba987c2bdc187834467aa3bef6178f65dc437d8a3_ppc64le as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:368faa16599c3ea793e83623ac329886420b170c9e12e190824524cf740eae8c_arm64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:61ac3bfb3d4a47f3bf0f0108f55f4da7a4b642422432840958cac8baec4728af_amd64 as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:b65752eb0cbfe0a9b6905fcc50c6532a8499470e541d2b82d834de3e339cc77b_s390x as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:dbffb568e00e84c31073192692c20d2f3b2e93b4759316d3fc6375ee1c1d2753_ppc64le as a component of multicluster engine for Kubernetes 2.17
- registry.redhat.io/multicluster-engine/cluster-api-provider-aws-rhel9@sha256:25cb5776778fc2892fb4556271e9bbe3b6377cfc224b614fef77cd9fc6459a44_s390x as a component of multicluster engine for Kubernetes 2.17
- +111 more not shown
✅ Remediation
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.17/html/clusters/cluster_mce_overview#mce-install-intro Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Restrict network access to the etcd TLS listener to only trusted clients and networks. Configure firewall rules to limit inbound connections to the etcd client port (default 2379) and peer port (default 2380) to authorized hosts. This reduces the attack surface by preventing untrusted network attackers from reaching the vulnerable service. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams. Workaround: If upgrading go.mongodb.org/mongo-driver to version 1.17.10 (v1) or 2.9.1 (v2) is not immediately possible, the following steps can reduce exposure: - Validate file identifiers before passing them to GridFS operations. Ensure that file IDs supplied by users or external systems are scalar values (e.g., primitive.ObjectID or string) and reject any structured BSON documents or maps. This prevents query operator injection. - Restrict who can supply GridFS file identifiers. Do not allow unauthenticated or low-privilege users to directly control the file ID parameter in GridFS API calls (Delete, OpenDownloadStream, DownloadToStream, etc.).
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:72849
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-73500
- externalhttps://access.redhat.com/security/cve/CVE-2026-75899
- externalhttps://access.redhat.com/security/cve/CVE-2026-75931
- externalhttps://access.redhat.com/security/cve/CVE-2026-75975
- externalhttps://access.redhat.com/security/cve/CVE-2026-76172
- externalhttps://access.redhat.com/security/cve/CVE-2026-84445
- externalhttps://access.redhat.com/security/cve/CVE-2026-88031
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_72849.json