RHSA-2026:18585HighCVSS 9.1

Red Hat Security Advisory: Assisted Installer RHEL 9 components for Multicluster Engine for Kubernetes 2.9.4

Published
May 19, 2026
Last Modified
July 28, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-7163 — assisted-service: assisted-service: Authenticated users can gain administrative access to OpenShift clusters via credential disclosure CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object

🎯 Affected products21

  • multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-image-service-rhel9@sha256:328c496a0d88ba24325f3cedde3ee8a1fa33df5da8c826a90f14166022ba8f3d_s390x as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-image-service-rhel9@sha256:854003f4573d4db404f0d1e2a121370944504dbe8f9dd166d40dbdcb5161f507_amd64 as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-image-service-rhel9@sha256:a13f669d1aaccdc187b64223e851320780d2dc89e26946cc4c0350b9937bbd78_arm64 as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-image-service-rhel9@sha256:b612551394698235fff657c2d419da965924f5ac7c74ee42c7b5e7551281bb5c_ppc64le as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-installer-agent-rhel9@sha256:1446e3b61c00b8fe64515e2cdce5a45662e8bf8e4ad22b656d18ce8e17069872_s390x as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-installer-agent-rhel9@sha256:258016beba330d58276f5b007bc4119f5ef418e8d065eb9a352e39b30f647c0c_amd64 as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-installer-agent-rhel9@sha256:5ec00882f4293c7d291e4b7a76f2cf6a12292748981c0f96ca6560a4cbcf0f6d_arm64 as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-installer-agent-rhel9@sha256:fc1f75fadaf8ce7cfe9159b81b940a2008269285e6d984d45cef8151081b98eb_ppc64le as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel9@sha256:16dddebe90650a5d8a0d3c10357c7d0a094920889921befb9a52d9377493c5f4_s390x as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel9@sha256:7eed44dc094736d426e937667cffa674db1727c236af20d8e4595f5f8a409bf2_amd64 as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel9@sha256:be551e43b6a6433533fb543fdf96e37c0217055ab19e8ba38581d27880f840e7_arm64 as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel9@sha256:c1804709c5ee7d6a6d8fb91cf78f6c874b9b22efc3b62ee23935c2899a286b73_ppc64le as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-installer-rhel9@sha256:4bea27bccc1ea90f291e5a3b3400bdd77957dc885f1e1f226f0071f1723351b1_ppc64le as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-installer-rhel9@sha256:4da51c0b5940c18089c8c6d28bb3d344c13b96dfaefe98689e6ce8b97869c83f_arm64 as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-installer-rhel9@sha256:96811580ee716e66a24cb4e1b54065dc2afd34ab0c2100e45edb70bf4d33949c_amd64 as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-installer-rhel9@sha256:9f0805fdcacc2f63b14c3aaf82749c717b6ac21020e26848d9ae7db84ab112c8_s390x as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:2a1fdca22639b568b24e7c2134bdd531112f2bf7d28ee76aa5d3c3117773ff2e_amd64 as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:48c0e808ea84176aad285d61f490b1e4128f93a7e98fdc0c2ec89098a4d5a238_s390x as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:eeae8c036c6ab2653c0141cbd44c1e28f6cfe454067e28e07a87c071e6258c16_ppc64le as a component of multicluster engine for Kubernetes 2.9.0
  • registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:fbe21c2a20bc29ec64738c5620d4efbe181282af8599b6faf285404e1f729ed3_arm64 as a component of multicluster engine for Kubernetes 2.9.0

✅ Remediation

For more information about Assisted Installer, see the following documentation: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.14/html/clusters/cluster_mce_overview#cim-intro For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.14/html/clusters/cluster_mce_overview#mce-install-intro This documentation will be available after the general availability release of Red Hat Advanced Cluster Management 2.14. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (6)