Red Hat Advanced Cluster Management for Kubernetes

29 known vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes, 6 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-93685 CVSS 5.4 medium A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a…
  • CVE-2026-92615 CVSS 6.6 medium A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config…
  • CVE-2026-89060 CVSS 7.7 high A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s…
  • CVE-2026-66786 CVSS 9.1 critical A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource…
  • CVE-2026-13676 CVSS 7.5 high fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path…
  • CVE-2026-44990 CVSS 9.3 critical ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API…
  • CVE-2026-44496 CVSS 7.5 high Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the…
  • CVE-2026-44495 CVSS 7.7 high Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains…
  • CVE-2026-44494 CVSS 8.7 high Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a…
  • CVE-2026-44492 CVSS 8.6 high Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6…
  • CVE-2026-44488 CVSS 7.5 high Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request…
  • CVE-2026-44487 CVSS 8.2 high Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a…
  • CVE-2026-44486 CVSS 7.5 high Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy…
  • CVE-2026-6322 CVSS 7.5 high fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters…
  • CVE-2026-42044 CVSS 9.1 critical Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a…
  • CVE-2026-42043 CVSS 10.0 critical Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL…
  • CVE-2026-42041 CVSS 6.5 medium Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a…
  • CVE-2026-42039 CVSS 6.9 medium Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects…
  • CVE-2026-42033 CVSS 7.4 high Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by…
  • CVE-2026-40895 CVSS 6.9 medium follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior…
  • CVE-2026-40175 CVSS 4.8 medium Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific…
  • CVE-2025-62718 CVSS 6.3 medium Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname…
  • CVE-2026-29181 CVSS 7.5 high OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each…
  • CVE-2026-33816 CVSS 9.8 critical Memory-safety vulnerability in github.com/jackc/pgx/v5.
  • CVE-2026-33815 CVSS 9.8 critical Memory-safety vulnerability in github.com/jackc/pgx/v5.
  • CVE-2026-29786 CVSS 8.2 high node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the…
  • CVE-2026-25639 CVSS 7.5 high Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios…
  • CVE-2026-24842 CVSS 8.2 high node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses…
  • CVE-2025-11065 CVSS 5.3 medium A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This…