Red Hat Security Advisory: multicluster engine for Kubernetes v2.6.15 security update
🔗 CVE IDs covered (11)
📋 Description
CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-59879 — immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations CVE-2026-73500 — etcd: etcd: Denial of Service via unbounded TLS handshake goroutines CVE-2026-84445 — google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests
🎯 Affected products109
- multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:85b97c804ba6f48f17dcb4c300d11116882e8138627c7aec056e815da8624bcc_arm64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:a519d6d96da5342b972d2bde34c29b0feb3d4f86ccce183d7456fc03dab6883d_s390x as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:b1b85f9f4f38f77970a91962cc8db551b7cd2f5ded130d3b0d620c6b684249d3_ppc64le as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:e0359eb8c3c52b3aa1bc663db8d26039a61907bbe6a5e94589c6602eecf6ee5c_amd64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:8d846aeef299e7325b400c92d16bada87992e6261089cde11bf0d6f76f970f38_arm64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:ad96f0872695e4aecacb883984d29613e76f52c330dc945bda57e6dd40d5ebd9_amd64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:bd30b634ebd6256e48ba57e65dad003ab666a45fe7c8cfc79dbd2ede9d9438fc_ppc64le as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:cc3972bfc327dc9381a207f0921dd04ca633543cd2e8085f64d27f3b86298b14_s390x as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:58e1261c621ed3834d2bd79c1924c2fb8e25acc1608e652bf33e57ea3cb097f6_amd64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:5c067e3de20c0fedc18c4461cd303d5b15a7867f6bf35aaf2da5c7d5a92a8cf6_ppc64le as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:c45385947df1b2c72a87555df6bd131832656a3cdd7f3df17f29e02f7ab49ad4_arm64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:f7cfb566f05b11cff24134c8996a487167c3240b15d407886c63a8949375d996_s390x as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:2ff7bee2625495f03505c414bd3360416eb36ce3ad3b614d053088c63d4865ef_amd64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:6ef673e21a02faff180ce81771543a85b8efaa141ce324a3658dfdd236566e12_ppc64le as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:d580a3a9bd1eb91696216d5628a882cf8702644bff487dee9377c7f69b314054_arm64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:fd3a8b06f1f1d0bcb7ebd2b3613ef5082c6f0139c165a6cc0eb8b93e7e632fd9_s390x as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:01367364d011ce52be9e3aa121ddc2f6cdf3717417d654167ff1a8aec50fc594_amd64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:64e5228e37656dd5a033f548c5ecb8610743eafb76e657d35ebcd7d30d14c82e_s390x as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:69538262963f1cbbb5eca25ad4bfd9e63b1f64ddd1f17a5fafe63ae0cf66e132_arm64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:74a79106f92dbd2acc2fae69e4708953a085f8b7675529ab337d0b80049e197b_ppc64le as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:6c80ce034f119836f1a5f68b93f11adc02c97d87ad2ed6b4c6111c469a662094_s390x as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:83303d93441840ec7bc9ac267aefc54a2fb841fb3c48b1daaa141c7e09a38056_amd64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:85543d445181b7f1fe5cb53c974df8ddf01c23a8dd4c8867997a687cdd0ab4e7_ppc64le as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:ca06274d3ba409cac1f12bfb553dc55fefdaaec8f6bc4f8b4a08f29f350f8d44_arm64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:3b5536ca5bbe485d2e15b8d3ab82f4b98aa64c7343796811f69d7211c5d7dc57_arm64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:53cd0328c88c8594224d8f6d856ab75b08eb104d506806a831c63327776cf3d9_amd64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:8e7fa862db314c96f0a766c54677108fff6346cc6f07bba2816f10c408842d19_ppc64le as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:d00aa02ecd34bf564140e65b8d720916fb5050d08db3a06363a9b38e6807f68d_s390x as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-proxy-rhel9@sha256:1105c2ce28aaadb9e5432e35b717daf925b6368e44862351906de9b2465d1c03_ppc64le as a component of multicluster engine for Kubernetes 2.6
- +79 more not shown
✅ Remediation
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/clusters/cluster_mce_overview#mce-install-intro Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort. Workaround: Restrict network access to the etcd TLS listener to only trusted clients and networks. Configure firewall rules to limit inbound connections to the etcd client port (default 2379) and peer port (default 2380) to authorized hosts. This reduces the attack surface by preventing untrusted network attackers from reaching the vulnerable service.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2026:72850
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-59879
- externalhttps://access.redhat.com/security/cve/CVE-2026-73500
- externalhttps://access.redhat.com/security/cve/CVE-2026-84445
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_72850.json