Red Hat Security Advisory: multicluster engine for Kubernetes v2.6.10 security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-4740 — rhacm: Open Cluster Management (OCM): Cross-cluster privilege escalation via improper Kubernetes client certificate renewal validation CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig CVE-2026-29063 — immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution
🎯 Affected products109
- multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:407afc190324598e778fc09d218da552a2430612bad6b50ff9f6bc824b788dfc_amd64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:437c27590382282a29dd543a69bbaed7ebd5421f73b98311c13f9e37c9ff553e_arm64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:865fcb2f6796be98004ad84f0fffcd7200690f56ccccf5a39af4c5888abb213e_s390x as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:f82ac0d043682cc16fb832d9027464ee65f314d70ce98687f45db50e16d2b250_ppc64le as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:0768996d28693025a487c86c72debf1fda095282412b2c33ca0f21d8d9011b8a_arm64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:5e84dda66a7735bbae425ac1a6b0e241662edb858476eb82adf72b7dff4b3916_amd64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:9f13c6203d4ba9cde9bd8932b7e86c4a9c3396bb82235601b84f6743fb1b675f_ppc64le as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:ed05bbaa85197e21425ed8f503f74c6717bb6f2112e9b57c9b115071777c1995_s390x as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:2ec4baacabb144497ea62482a3c0ccafb9c3794c5c89f9aebbe855d7d9829dbe_amd64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:72e64e8d1be38857af7beadc81e2f5f071f636b1d9233a70add5a1f18833ec45_arm64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:c17a0ffd9c9546016a87cdd75adbaaa742f8637a0d81975d7b76662ffe5b069d_ppc64le as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:e05c6ff6a481e7956a58e07f10dc15470ef2af82966b2159260077bd6ba06cf7_s390x as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:4bef3dab9db981249b3a1b3a556e615226b29fdc7a6593a3970921799817129f_ppc64le as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:901dd1ad148b84d3c1bcfa71beeaf75b836bb382bf99893f65d4629d006bcfc7_amd64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:abdca0cc6776dba16be873853e38bc62bb9d3f1eb80f1d4bcbe7829714a019b5_s390x as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:f856447bc82e37dc4da78639ff08bc1f4b4c4e0d75c3d1eeec81e3807c65ad7e_arm64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:345d589cb55ccb8afb080f04054ebc30f0cf6383742ce750f4f5656e14f4db35_amd64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:5557594c1ac0b047fea659868fdf71b8f16e0548abe8f41bf58ce80924701a16_s390x as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:8e08974a6dc10be9cb7d7a07527e8960cd93b76506355ce900e2e691208d1047_ppc64le as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:9d501eb84c2b7f9f860c5bb08d9adcc599e42ed0c3a0e24af3c32b686f005182_arm64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:8690fcbd38eeec0cde0edc5c2e46683837d6247ce657c495fc791a0bb13c0450_s390x as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:b41036dc59ecfd530609349da9b73dec177184662aaf69bac35e67d245815d2a_arm64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:b5a7706fc69c7e1b3ad3ff03c5b0e46b44cd93ce332a74acd43da8c86b6b7163_ppc64le as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:f0f363dc51f50bf822bff6b5f9072299c2404d8df1891243ae3ad6ba90c95f0a_amd64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:212c9c73fd1050e3f202703e7c5c5a466d1931d918e3f730d2c56bb2629337e2_amd64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:c6b10fd7009685d032e8c914cce4a1b2630ab99f2262fddd6dd32c048224e535_arm64 as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:d26e9fe1bf09eb1c025e28c795debabe0dda6a3f0fa112a6507b8862489de361_ppc64le as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:e246eb1fb572fe7ad7058afd783020e77dd61699a5ffd290000e80baa6bc0454_s390x as a component of multicluster engine for Kubernetes 2.6
- registry.redhat.io/multicluster-engine/cluster-proxy-rhel9@sha256:c3754441d1af76c226983b48c57b537856da6cc21272008c05dfbb8e860d25f6_arm64 as a component of multicluster engine for Kubernetes 2.6
- +79 more not shown
✅ Remediation
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/clusters/cluster_mce_overview#mce-install-intro Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:9848
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61729
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/CVE-2026-4740
- externalhttps://access.redhat.com/security/cve/CVE-2026-22029
- externalhttps://access.redhat.com/security/cve/CVE-2026-25639
- externalhttps://access.redhat.com/security/cve/CVE-2026-29063
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_9848.json