RHSA-2026:30651HighCVSS 8.7

Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.13.9 security update

Published
June 28, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2026-35206 — github.com/helm/helm: Helm: Files written to unexpected directory via specially crafted Chart CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-43869 — Apache Thrift: Apache Thrift: Security bypass due to improper certificate validation CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name CVE-2026-46384 — github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: Integer Overflow in Avro Decoder CVE-2026-46385 — github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: CPU Exhaustion in Avro Decoder via Unbounded Block-Count Iteration CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation

🎯 Affected products177

  • Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:0a98bad8232b0dd6290f10aeec6ab866b142f4446c1b3983e7d86ac29f25f8d4_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:5816d49cd236d33f576d7642f5bde80b9435783cb68d5fa5eb8147c0f13bfadd_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:67fb40f96846bfea69aa80ac0696f6f159638716398adc759ebe3c42a5ea06a0_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:ee3e582c73cc5773a35e36179c7b47c832e48081feec73db4d0483442f306006_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:2a7f3081f76a1a86229b3d59be58a68ce8771a472b4c77be564786b351662550_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:b7dd49935f0d2373b4171f42af5e1537be5f92e3cc3e8388f90dc2e66c159641_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:c17e5b41fcf5e0e72bea62d5a95ae546c5e6c0fc2ba58576d1f1b67f51710ffd_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:dd99134a27d15d0aa4a870f182563be3b86cfd5f55d560c8374053cfcfec5af3_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:52469617259a8f845c7d5bd617a4ab9edf18d67aefc1b9cdc429d3833e32d103_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:5ef1eeb2eae05aaa97ed15ceea45674280b5b73140e9cb1bdf450b52ea32cf4c_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:e5b500061182261a2434c22f89b8ee0f684d85412ecbb528273f6292236709f7_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:f3a08c04eacf9d1350e8deede38298ac874d77737282b335304edf3644fb2a80_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:2e9da0c72a8e750cf7d7e12e01686a97eddf77ed16d3203ad80b295e4e81ccf9_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:5ee842a9e8bab7ff732cbf68f16f90531babccfb6d4a4769e4735d2e6f607bb4_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:a68ece449c8dbb40271d166f2944e9403324f2c7db2be07e86588e74b22564d5_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:d660365f98f52209ab346b7b2a08d5dd09ef5e42df0bfcb08081b5cfef3ea28d_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:140584d5e1bc3e4b7910899f144f0b978bdad3961caf52b01e2fc64ef73f2e4c_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:213a3a30a7168fe47ac445b00e83a1bb73a081e4dd597d90ac644ebc78010946_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:381c9bd9eb4672fb1486e9644a87677d2a7c694f24e998c4b0a2d65286ec32b6_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:7bf527bde07603ca6d5d3d55dfb31b1942011e21c719fb4c8ffc029257b2a80b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:1dfb4e8aab052c65b7f7a3b5f8ce25bf4b3323f896cd89dc1c5dc3294dc52b21_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:28bf296604c7b472dd4aaad0e485f53451deb95ecae278f65fc64899c892d257_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:290bddaaf3e3e161aad18a0d397606120325805c9ec5398a6db11fb89f0ef588_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:781a9315523d891bf6526002db407a87707b483a2b1c5314f7d7e36581c8070f_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:022bd56f0ed4905f878b97137f0ba22491c7eaa2e6d055f691c9fdc191b1242c_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:23bce2847e65215b8e9ec64b7c959a6d10ddb8e8196496780a9a49af34cc223f_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:8b2553e370ac1b60ae9df0772f331e4c2ca9a4d1f4304e656c020b102916a65b_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:c1d2d73a1a14b1ff24f1e3403bdb85d9df0443038cb8f27b023aafbc0ae83f3f_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:42d2ecb8dc3c31edb67134ff66912a45b665cb3c9a16e6990ab092b8277f67b6_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
  • +147 more not shown

✅ Remediation

Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available. Workaround: Upgrade to a fixed golang.org/x/crypto/ssh release via updated golang or package rebuilds. Ensure SSH servers use supported public-key callback configurations with source-address validation as intended.

🔗 References (18)