Red Hat Security Advisory: Multicluster Global Hub 1.6.6 security update
🔗 CVE IDs covered (23)
📋 Description
CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
CVE-2026-34040 — Moby: Moby: Authorization bypass vulnerability
CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers
CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering
CVE-2026-46604 — golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via invalid TIFF image
CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data
CVE-2026-50151 — oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload
CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input
CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution
CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
CVE-2026-66792 — multicloud-operators-subscription: multicloud-operators-subscription: IsClusterAdmin() trusts user-settable annotations on managed clusters
CVE-2026-71235 — github.com/absmach/magistrala: Magistrala IoT Platform: Arbitrary Code Execution via Unrestricted Script Execution
CVE-2026-71576 — multicluster-global-hub: multicluster-global-hub: Manager trusts self-asserted evt.Source() for leaf-hub identity in all status handlers
CVE-2026-71577 — multicluster-global-hub: multicluster-global-hub: Spec-topic Read ACL leaks bootstrap kubeconfigs to all managed hubs during migration
CVE-2026-73500 — etcd: etcd: Denial of Service via unbounded TLS handshake goroutines
CVE-2026-75762 — multicluster-global-hub: Manager trusts self-asserted evt.Source() for leaf-hub identity in all status handlers
CVE-2026-77849 — grafana-global-hub: grafana-global-hub: Hardcoded Grafana admin credentials (admin / admin) in pkg/specsyncer
CVE-2026-80220 — postgres-exporter: postgres-exporter: pprof profiling endpoints exposed on unauthenticated metrics listener
CVE-2026-80221 — grafana-global-hub: grafana-global-hub: Direct database connection string with embedded credentials passed as environment variable
🎯 Affected products22
- Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:30838d5f38917dc0bb34318aaf788759e6cd418fc0f2b77be7a4f8d5d0b108b7_amd64 as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:32bb6f5b60aa12864be8c4a0dced374c7b4fab76310dc291f4843882b6e8203b_s390x as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:3353329adc7f7f14021393161aa75b46b405b824ba9eba849c9e015ebcd7bbcd_ppc64le as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:757eced3376f0afcf71e9fb275d28f03e766e1364ff32d637a3d2ac16b24712c_arm64 as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:3d51e8050687b6a4b399c5b04f04611ae60f13d3c0487cf5bc29506141ce3e45_amd64 as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:56d3a9ea7c66a5d15a866600a126b69da4130b637ca986b196bdab551054edc5_arm64 as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:b3add3141a627e33437849d27b592297136beed0f0c96660a1ba06603d4c719e_ppc64le as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:c610add9308e839e7016d3428ad51e213a0d48dfb3d6dddbec6f7922c8136005_s390x as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:443037c84f8a951ecbad39cbdac276619fa4f7ebce01a47ddafe3c822aaf4a96_arm64 as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:8235df6e5b40770f3f3b9bc38b789286e670d223b3675f67adff1af037e4edd9_amd64 as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:b600b7bc5ed89be2b357e268990b06c21859b7d224c70b3e195414d419357a91_s390x as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:e3579b13e84d230bc559e3a7379718875bb5e546576c1078c703e258354fa5f1_ppc64le as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:813a184dcbc23ee970b851393c75fe54940344010debd24efba68c6c5a05fc86_amd64 as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:4430880c68ee248d38f433c4783bc76f73ae2eeb2e407a8ed142e7f246bcf308_s390x as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:4c1fa54db1429d6f3b1ad062fa3c1dfdc35fbcbfe5d0d84087418c507581c1df_ppc64le as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:9f9673f5ae2f1dcfa87561388157534d2848f223fe3c3795fc965b0e2f713eff_amd64 as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:c365df7ad7fb349d7b746280434b4cd73f7a586544248fd760dbffa5e5ba94d1_arm64 as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:06c38fd194d64956809abb9acc3614419cdcb26a3f48636a179ba62508e92c98_amd64 as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:69989db7b777af7fedc5ddb9e2d8719316ca5564f13549f5e1ac3e2cb0fc7ce5_ppc64le as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:74a69caabe14c5b803ead049df8941b3ae60edb474da24fc91aaf8c95fa05154_s390x as a component of Multicluster Global Hub 1.6.6
- registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:983f5f54e2505e1a8d457f45d8caab5aefd70ffebeea9f9f071dd8919aa9c5f2_arm64 as a component of Multicluster Global Hub 1.6.6
✅ Remediation
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.15/html/multicluster_global_hub/index Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: There is no complete inline mitigation for this issue; the fix requires upgrading golang.org/x/image to version 0.43.0 or later, which validates the strip offset before use. Where an immediate upgrade is not possible, exposure can be reduced by not decoding untrusted or externally supplied TIFF images, or by isolating TIFF decoding in a sandboxed, restartable worker process so a panic does not crash the primary service. Workaround: Upgrade to oras-go v2.6.1 or later. Workaround: Restrict network access to the etcd TLS listener to only trusted clients and networks. Configure firewall rules to limit inbound connections to the etcd client port (default 2379) and peer port (default 2380) to authorized hosts. This reduces the attack surface by preventing untrusted network attackers from reaching the vulnerable service.
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2026:73419
- externalhttps://access.redhat.com/security/cve/CVE-2026-32282
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-34040
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-46604
- externalhttps://access.redhat.com/security/cve/CVE-2026-48586
- externalhttps://access.redhat.com/security/cve/CVE-2026-50151
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-66792
- externalhttps://access.redhat.com/security/cve/CVE-2026-71235
- externalhttps://access.redhat.com/security/cve/CVE-2026-71576
- externalhttps://access.redhat.com/security/cve/CVE-2026-71577
- externalhttps://access.redhat.com/security/cve/CVE-2026-73500
- externalhttps://access.redhat.com/security/cve/CVE-2026-75762
- externalhttps://access.redhat.com/security/cve/CVE-2026-77849
- externalhttps://access.redhat.com/security/cve/CVE-2026-80220
- externalhttps://access.redhat.com/security/cve/CVE-2026-80221
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_73419.json