Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.11.13 security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
🎯 Affected products165
- Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:0a4112cb62f18edc92c3ea0226127879f22550480c4b6089ce0c3acfa6e0cdbc_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:0c720cb6c20fc39d24e13e8731de95b8702aeb218e29623fe5bb54dbe082b1d2_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:b090a89b8b478189e9c4ebc8bc0fd2b58e92a9a202246b8642c75f20b2af79c2_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:f2aa296d0e91e3878fce888378ac6da4fb57355ca5b62d4f06ed6703ede9b222_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:469732cd60ad125a91a979f37383148456af88d3384386ca008455377815ab8e_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:a95860c048d1041e5c4cf88a62c9725712ef33411472645bc787696bdb5f3102_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:ae51769b8f330531e5710d256aa4c6473203b84aff797bdc5a803b763544660a_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:cb84795e49e7925d9be2929e0f4f43ed017996b32ec5cb42613542b305af5138_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:0388be84b2bdc091a56b11095648b4ce96f6d2b38301176bf38588d72adc05fd_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:989e002cd1b75b2bf006a7b2f166e44765f2e61526f2c4999bf7a80d8b3f61e4_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:b40d5a23310cd3a6ae36e757551ddb8c0ba97b9bba26458c827a007444011903_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:d2d1bb5d330816cf8182122cdfa68cc13ada24878f53be7dba53e71dd250e17a_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:2a69284657686cf4a03b40fc1077c3acdc683dd7032cf3e8a6724acc389d20ab_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:b8a67b032765821a09470904ec2250fa4d5661db65fd01f3825f258b600b0967_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:c01913fac8ef06776c546ae82a6e49ed26baa806f2382475ddec7c5037b8fd8b_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:fa69b718c25e45700026eb357f4b4e73431b5832deb446ac20d8251bd341f063_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:aaa30229b5b1dd0b2ce13fccb6ee9b9fec780ff83e7b776f1553556d05bb6b0a_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:da9362973950ded06f1eb2fe9f5506096c7722e539afc0b4f0753206d40169d1_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:dba2583c3b88eb30e53fbbf449e1237babef536c6733c742bec6f79e87c7854c_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:fe74191a66d4d694ea4e4b672303fb4824baaa53e4c270eaaf4c5a7a4339b36a_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:00934926ae8dda3a59ec52d2a9dda6bec5ad3c40d81f75c4fa0eb07ad079cb90_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:109421c68dc5ec3569491f53dba39bb38440c566480976ae701894a344d6e9e1_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:3842306d78edf26ddac5ca0c11825757395345d93c1bf84349375c0e7797ce95_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:e91b1bba994e742dcd156cba8fa4b782a1031a05af2c77544eeeb262cfd6007c_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:24ed9b13ebe8680f7a320dcecf77958b782d3ea59d1cf33cb52b7f3674b59861_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:6b231eab8166c93d0e6e8279f3e0c605cae2524de19d61bce29cc05d01fd4d54_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:845e41525e4d0554f2e5e4dc05df4197f1136faa144462fb82fcbfa4d5883373_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-prometheus-rhel9@sha256:b45f074067cca15cbdae79834145a035d51a10d977860382da9c6cd685015c7a_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-search-indexer-rhel9@sha256:2774e5b4c3392dc859a724c8225799f4337d1b6cb437303e8dbcfb35834d4fc0_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- +135 more not shown
✅ Remediation
Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:72882
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_72882.json