Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.13.6 security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2025-13465 — lodash: prototype pollution in _.unset and _.omit functions CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61728 — golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip CVE-2026-21721 — grafana/grafana/pkg/services/dashboards: Grafana Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig
🎯 Affected products177
- Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:01382838a23f75a6c03b30c68e9e42d72c22d773a4891260c639f7c8b60ffd87_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:1c74aaa66b6be9f5eb1f55851f1cc3f2a3878882c3fc972cd24232e9022f74e2_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:696d1f7c4b5415e49760f7a66368aa0260284b12b108d5feb560838a9bce8a6f_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:7328602aa637f1b555ecd56c05d6ade8dbee48fae78a0118b1e39774b8383704_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:3ae25beb920ec77de14769895f60da6a3d83fc41192ca5da5f976076853e5a50_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:c9bf774dfa3f5a66339a86f22961c54b2b41199efd173b016a2c7c57407dae40_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:d1cac9d50ec20e770ae41aa8f90474c269d80e84a9990e2c3e613a892b0c044c_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-cluster-permission-rhel9@sha256:ddb5d8c476bcc9b6d4a7c0d116a2f5150acbfa80cc890d77d5d90bd496a7860e_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:0ffd5a902860aad15377e20b1e6481e6cf746fa3e33509df0f88f93f9a9f8034_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:abcf4d6f42dec254d8b4197282fb449daf13d4724ed23ddc2aafde0328338f74_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:b6ea1f6389ad207c45321ab5a36c03949986e74ef9dbf5e3d2fdb2ceb5c4a602_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-addon-controller-rhel9@sha256:e126327d69e48f2844f5beafc34514d31e9f3eed0ac393399edf80cf31a2eabe_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:0f7b1ee143f154e6e33c452f95fd0a0afb7fd020e758a991d18abde990e49e0c_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:6363dfb96f394aef2b07b3a36c85d3af60dc3594ab615327176ba520704a4356_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:849cf23afa514a1d86073fed2424e487893655510721a0b9c0d4be4cf59bf60b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-governance-policy-framework-addon-rhel9@sha256:a8843c7b628767803f2aa4b2658dc0a932157b20f98507004929036108c7dfb2_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:428a52072881ee7714539f7721313ca78e06fd0e39ceb8de12f8a0d33fb4cd55_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:5145c15e9fa57bdd1d072e7c88f27d5f8f51caf395e542ad8fb54a098f8c24fb_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:cb76c81b895dfb5bc384407baf76c5c74d9b509342e665f3d5ff234a40f16236_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:d7dae765d402cd9522c23689fc0e72f47659fc2f1184b8b16c51b6c5c6a2b890_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:5af546f1d36b01b320fd950d227cdd8f62a765facc8614ba277fe218c5649e61_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:921a7995304e4648ac2fd0c08bec7d95adc09caca4d6d124cbba4ff8043edf19_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:a0928fa238b82f2c00778064d0f1e52ff507ffef7a0a3756b1f2f2022d375e4b_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-multicluster-observability-addon-rhel9@sha256:fdc436ea03cb2d06976da109061aa0793672c306deef23708ee9e0b39395b6f7_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:2adb87f4433d9516e2111150bccafbbb8dec179bdf3fe3acd38d7b27411cb666_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:4afad9568dc7dd2d90c396d08d596258e813bb67e2901135b539f279af382e09_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:508d4d8ee312e8d720eeca38f3823438548c5ab1260d8fa822ca49765f7aeef5_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-must-gather-rhel9@sha256:a31ab1ae8b4c3ead24f9ce3c913a4754972bd548d6e5b10ca22e61a6d9d3539a_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-prometheus-config-reloader-rhel9@sha256:35ba01a14b8f7a0ed0e79fd9efe48280d26afa10a316daaec512f39cc6839adb_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- +147 more not shown
✅ Remediation
Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, implement strict input validation before passing any property paths to the _.unset and _.omit functions to block attempts to access the prototype chain. Ensure that strings like __proto__, constructor and prototype are blocked, for example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this vulnerability, implement a timeout in your archive/zip processing logic to abort the operation if it exceeds a few seconds, preventing the application from consuming an excessive amount of resources.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:8229
- externalhttps://access.redhat.com/security/cve/CVE-2025-13465
- externalhttps://access.redhat.com/security/cve/CVE-2025-58183
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61728
- externalhttps://access.redhat.com/security/cve/CVE-2026-21721
- externalhttps://access.redhat.com/security/cve/CVE-2026-22029
- externalhttps://access.redhat.com/security/cve/CVE-2026-25639
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/updates/classification/#important
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_8229.json