Red Hat Security Advisory: Multicluster Global Hub 1.8.2 security update
🔗 CVE IDs covered (21)
📋 Description
CVE-2026-17106 — github.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers
CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering
CVE-2026-46604 — golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via invalid TIFF image
CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data
CVE-2026-50151 — oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload
CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input
CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution
CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
CVE-2026-71235 — github.com/absmach/magistrala: Magistrala IoT Platform: Arbitrary Code Execution via Unrestricted Script Execution
CVE-2026-71576 — multicluster-global-hub: multicluster-global-hub: Manager trusts self-asserted evt.Source() for leaf-hub identity in all status handlers
CVE-2026-71577 — multicluster-global-hub: multicluster-global-hub: Spec-topic Read ACL leaks bootstrap kubeconfigs to all managed hubs during migration
CVE-2026-75762 — multicluster-global-hub: Manager trusts self-asserted evt.Source() for leaf-hub identity in all status handlers
CVE-2026-77849 — grafana-global-hub: grafana-global-hub: Hardcoded Grafana admin credentials (admin / admin) in pkg/specsyncer
CVE-2026-79921 — github.com/rabbitmq/amqp091-go: amqp091-go: Denial of Service via oversized AMQP payloads
CVE-2026-80220 — postgres-exporter: postgres-exporter: pprof profiling endpoints exposed on unauthenticated metrics listener
CVE-2026-80221 — grafana-global-hub: grafana-global-hub: Direct database connection string with embedded credentials passed as environment variable
🎯 Affected products22
- Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:2c812623490bba09d1fdeb595686bfff1e90b6c31dc563533212f87abc56fc01_s390x as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:b8f1f7489eb65d4161d67802b6231714f91fec3e531119c1c30bd8a5cd6b000a_arm64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:ba58eb7ea0463459218cbe493faea59105a4ce954f6d8f3fb3447ac7958ab4e8_amd64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:d50c662083de7084d90165f5d0f7f4b1986aa04334aee78ad3fd82fbe37a91df_ppc64le as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:51a06c0911cd26f67f9a2e8bcdd1e9523e88a8cd6c1e3c497c0fb12c5625f197_arm64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:7092341d99cdb2da484f2770c94c48f0fc38e1c3f59c854ad7bdea0e6db8aa73_amd64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:7514779fdd0ec7f734986bd02bac08cf3a5133871bb44580febc6f28eec0f6e0_s390x as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:e7af92caa4e3c17f82a60cef6f8406bcd0b55eea88abbdf7619022a3038c1600_ppc64le as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:6c0b3f002aac0debb7d52811d21d9f8fc9d0cf2e9d2aaf92a8f47bf8093481c7_amd64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:991fc487eaa4357cd0a2e87e44780e040ee62bf85bbed4ef009e44f0ca88c304_s390x as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:a0f75fc098b74a93989ba73ae780026e549e880ccdca020aaf1a7cb61ec99860_arm64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:a6263ed1836ad0d34d120a43b09dcbb2e66a1a57cebc70ebbb6e43ef792ea506_ppc64le as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:42ecc29d988d1b4c370d7ea5cb0619d29a6938b01c093864e17837c3dd047314_amd64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:71c89e77a3f95146827710ad22d77b3b279a5b42b6068a497a1dc169e07f4677_s390x as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:8e93edd9411902d3a826d0ea67f86f23cb5ebf8fcb746652e5ad44753be5345d_amd64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:a8fa93d288d8919041c7bdab43c133b6251462483e5475a1b8e87d31ffb81e57_ppc64le as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:c438ac2ce14366ffa5bc4defa829b0694eefd7427966618a9a0482bf5b58d591_arm64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:2fb54434e80fd99e0f4ffb8f568181c78047aa2ef75f105a5247a1c1e32f0bb6_ppc64le as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:315b101e0c3bf4624321aede464e6bc1c994eb40d0f1bf230eb3988a28dc48b5_s390x as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:949e39031b1a6f4006b220c67380ae29f64835e08712ff790d9a1f5d90c2a2ee_amd64 as a component of Multicluster Global Hub 1.8.2
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:e7640a28e2f17e2f4f69ef01c644201650d25ddff0c96f41fad26f5d4b2e9380_arm64 as a component of Multicluster Global Hub 1.8.2
✅ Remediation
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.17/html/multicluster_global_hub/index Workaround: To mitigate this issue, avoid processing tar archives from untrusted sources. When handling archives from potentially untrusted origins, ensure that the extraction process is executed with the least privileges necessary to limit the impact of any arbitrary file write attempts. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: There is no complete inline mitigation for this issue; the fix requires upgrading golang.org/x/image to version 0.43.0 or later, which validates the strip offset before use. Where an immediate upgrade is not possible, exposure can be reduced by not decoding untrusted or externally supplied TIFF images, or by isolating TIFF decoding in a sandboxed, restartable worker process so a panic does not crash the primary service. Workaround: Upgrade to oras-go v2.6.1 or later. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (24)
- selfhttps://access.redhat.com/errata/RHSA-2026:73038
- externalhttps://access.redhat.com/security/cve/CVE-2026-17106
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-46604
- externalhttps://access.redhat.com/security/cve/CVE-2026-48586
- externalhttps://access.redhat.com/security/cve/CVE-2026-50151
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-71235
- externalhttps://access.redhat.com/security/cve/CVE-2026-71576
- externalhttps://access.redhat.com/security/cve/CVE-2026-71577
- externalhttps://access.redhat.com/security/cve/CVE-2026-75762
- externalhttps://access.redhat.com/security/cve/CVE-2026-77849
- externalhttps://access.redhat.com/security/cve/CVE-2026-79921
- externalhttps://access.redhat.com/security/cve/CVE-2026-80220
- externalhttps://access.redhat.com/security/cve/CVE-2026-80221
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_73038.json