RHSA-2026:72885HighCVSS 8.1

Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.13.13 security update

Published
September 28, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42127 — grafana: Grafana: Denial of Service due to excessive memory allocation via large JSON payloads CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages

🎯 Affected products177

  • Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:21fb427d8e042a8abf2e76f440c8706055c3bfb9c2c3f3903806a24b14b0cdc1_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:aba3ebc6043c249b0386836d2e1ce9e340a3dd1c19b24cda795d44ecdb5fc3dc_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:d0c928aae278d8a37dd1291f7c3e4cc08ace2b42b291017951540fe11d83df87_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:e069e2110d1503785ff934e24386654468abb38de77ca1923737cc3cf2e3e09f_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:030af5d161541a8ac70b02855ea85ae206de679afb1268042209657495750123_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:6bbdfa7b10b6cc7ccb7136960f7a99f18cd8a839e99ec66de162c4f7e28c42f3_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:ddeb9b0d97a3d1c9351ca7e031f3c297b7a5b9dab4ee7539f2e59397ba35e9c7_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:f9f3362790dcbd1391d3b0ad20046ab31dd424754c9a6955f370921cc4e8316f_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:72ccbd538dc7825d4da1b767fc9d9b330b35c608e975200fdaa3e879710c8af1_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:7bafd33e892cc2b8468e4360e87c5d5996865310d2427fb9728fdd67d87ff7ce_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:a0ea78e1e1cacec8872c1adb65e795a6cdd4b630883d41bb7ec6c97ac94e6923_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:d867269f43113de3a28295474dccfa583ea7c47271a16b489cb10d6f3f9a2055_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:2136b34ab35be68bd497a6fdfb82bb01479419e3c5cdb574570c1d52d71c8dad_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:593c257c52fed3a7d248fbaca2909a185f52e2d4fb78daf4e41c3a14b97d774c_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:66f572891d0d980c4453152b5174acda6967427cbd7315299785f16ba498c6ae_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:c059073c1b51062b05bc4ccc44052114d3d273a0ac12f3b35316f69f97a3643c_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:244ae03070c3ef1e98d17bf2f11dec548911ba272b576d60aa007153ec6aa2ce_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:9b278dab1c05dc65281dc6e35fd37e0c207cbae04998bce6c0fc9d57bd9138a7_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:9bcca4d17278d95888e4a0552cd6e07315df1193b04c0e397add16400a20103b_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:ddf1f2c0757c5fc1cc45810ee2f01496c5913b94e0d05073fa0f6b7d43b8df4c_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:451f907e1ceefafd07545444f810d243117db549e02a3b7dd0933d372e5ba9c7_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:6e07f916a88c09cf178f875e4734f19aad9d40f95f50119522a099a018ea7eb9_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:8cd4e749229e621b487b4d2c0e2e9f5f9f4ceae38cb03ffd85980cb1a1fe7410_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:a5035f66ad807b179cd6c4d02a1ee94359032ecde4ec6c1a38f6ed6be2fa4ab9_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:4be2bdadfd3d6e1783de0fe17708c43e0a696797462088c560b075902ace34fb_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:56b45571a42b25b9649278e471895806fd83bdc360e82c1e7d10a7fbaee5773c_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:5d010489443a42f4b45cef421892e72ebd27becd8f932dd4cc81a2c99ea16d19_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:d66caa6cd8897634948b83f353584e211eb16cb004dd7ddffb5e4560943c959f_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:40d2481318af77b9b5cb10b30fb1c7aaf0070538d5f3649d71a42ab7b878597b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • +147 more not shown

✅ Remediation

Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Restrict network access to the Grafana instance to only trusted clients and networks. This can be achieved by configuring firewall rules to limit inbound connections to the Grafana service port. If Grafana is exposed via a reverse proxy, ensure the proxy is configured to limit request body sizes to prevent large payloads from reaching Grafana. A service restart may be required for network configuration changes to take effect. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (15)