RHSA-2026:36207HighCVSS 8.8

Red Hat Security Advisory: RHACS 4.11.1 security and bug fix update

Published
July 7, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (12)

📋 Description

CVE-2026-9165 — stackrox: stackrox: Unbounded GraphQL query depth allows authenticated denial of service CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate CVE-2026-42264 — axios: Axios: Prototype pollution allows information disclosure and request manipulation CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation CVE-2026-53488 — github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin

🎯 Affected products48

  • Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel9@sha256:70dbc4b2fd02c6006d01fd31277c79e1152a04e678316853cc9650004a88c8f6_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel9@sha256:93e15662b963e2da7c1ca4ad5c47df2a49d6df5857c9cb44157c88a1eb14c99c_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel9@sha256:a67c68062eb3fe78067524fbef175c6f4dcb2876138fbafc17c8f5aef930ffb5_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel9@sha256:fd0e68ad1f3d790efc1a7637a63668df741a3195d86260291ca7ff85fe72bed2_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel9@sha256:063b28090fce858259efe584b09d7329b766ae461926e8d78f6fac1cf6738055_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel9@sha256:0964f3f379136662c8c3817b2a7d3b787808fab2b742cd7ea53d5f6c2248d1c9_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel9@sha256:bc05850aa1cefea5105198c9af51c64f2b255df1c1ccbb30f3c12a2d4c549f1b_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-collector-rhel9@sha256:f5a7d92dc9cb85b9a4d70d871ab1748e80435e9ddba74ba3818e92ec57f7cf78_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-fact-rhel9@sha256:1ba125d01f712a5fb85db400a0cd9d2240c36529d7d0c8e925acfd3c45845bec_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-fact-rhel9@sha256:2801fe77997c4325f9d1e154eae8c63a4fc808e2c31c773a60c47d63268b1bbc_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-main-rhel9@sha256:41fd9a9bc849f2c7c6439532bd537c34384b88be30b37629c5e271e0e4be7db4_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-main-rhel9@sha256:55d7e178435c881a57a88aa6747cd6dedd3c3a512014d0509919dceef13b2946_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-main-rhel9@sha256:5fef4993574a20a48a9f93e5f07967d13b7b26e8f7e83e2222ea5bbe1f500409_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-main-rhel9@sha256:d785df86cfd97ff76e6d9426b247543faa91efaeb950f6b2e6b97f9e67624043_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-operator-bundle@sha256:2fe25a8ac9612f29a625969bb25d24938abb298e9a9e1e79fb3aa34c6a0e5f76_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-rhel9-operator@sha256:307402d2c8c46b74c1a855dad9fdd9f4013c057256513b4d1d58ac980ed8d2e0_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-rhel9-operator@sha256:91710d1c3f67e096b682cb6fa118c70d40bbbc36e3293aa3bea9890775d70236_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-rhel9-operator@sha256:b9d25811da46af4766d41e7543cc54a2820b2b9a4c190585e34166620cf070f7_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-rhel9-operator@sha256:fbd34cb7d74c9e699337157c4c26bc714b541e00645948cccedb5e7afb258003_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel9@sha256:93dc86f2358079474a9f5ce67e0e6430c2cdbe8a01155be8020165fce2e73f2b_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel9@sha256:a8c0e823eb62db8ff39de33d6401670e2f65cac8e640b64a9ffeae8ecc0c12bc_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel9@sha256:d50e48a12a217855c373b865df663f50355e4f76fba33de65e50bdc333112c4a_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel9@sha256:eab9c2e2d1ea614bf898c0cba75223f7960a61b7d2315815d6410e3c4f62d7f8_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel9@sha256:39470e0a40255d8d0bcfb6a3e82d77bfd57fdbff5452179f69eed7cff417a103_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel9@sha256:69531d80a6af41db1c28f54a8acfea85594fca34c754c8049e75b331e998a973_s390x as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel9@sha256:7a6b045c058be14ab95043bc3c6680bba5ab54a060ae45dbc7e6e8896fb093d8_ppc64le as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-rhel9@sha256:ab57133805270163a3cb99e972b183e8613a6fbfcc943eae5b542d923d572244_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel9@sha256:1c03e0ce9e3b48c8c0f2a9c65dfe3d9b344cd82ac776dc210ef23b91745b0682_amd64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • registry.redhat.io/advanced-cluster-security/rhacs-scanner-db-slim-rhel9@sha256:3783cfecf52a9c532c4e64ed93078581c8ca200efda661efc63ae1fac4391d57_arm64 as a component of Red Hat Advanced Cluster Security for Kubernetes 4.11
  • +18 more not shown

✅ Remediation

If you are using an earlier version of RHACS, you are advised to upgrade to the version of RHACS mentioned in the synopsis and release notes in order to take advantage of the enhancements, bug fixes, and/or security patches in the release. Workaround: There is no complete mitigation other than installing the update once available. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: Upgrade to a fixed golang.org/x/crypto/ssh release via updated golang or package rebuilds. Ensure SSH servers use supported public-key callback configurations with source-address validation as intended. Workaround: Restrict container image pulls to trusted registries using admission policies or image signature verification. Where containerd is used as the container runtime, disable or restrict the binary:// logger URI scheme in the containerd configuration to prevent the label-to-logger attack path.

🔗 References (16)