A flaw was found in search-v2-api. (CVE-2026-71469)
CVE-2026-71469 is a high-severity vulnerability in the search-v2-api component of Red Hat Advanced Cluster Management for Kubernetes. An unauthenticated attacker can exploit an unbounded tokenReviews cache by sending requests with unique bearer tokens, causing memory exhaustion of the search-api pod and resulting in a denial of service (DoS). There is no official patch available yet. The vendor recommends mitigating the risk by restricting network access to the search-v2-api component using network policies to limit connections to trusted sources and restarting the pod after applying these policies.
AI Analysis
Technical Summary
CVE-2026-71469 is a denial-of-service vulnerability in the search-v2-api component of Red Hat Advanced Cluster Management for Kubernetes. The flaw arises because each unique bearer token sent by an unauthenticated attacker creates a permanent entry in an unbounded tokenReviews cache that is not properly cleared. This leads to memory exhaustion of the search-api pod, causing service unavailability. The vulnerability is due to allocation of resources without limits or throttling (CWE-770). The attack vector is network-based with low complexity and no privileges or user interaction required. The vulnerability has a CVSS 3.1 base score of 7.5, indicating high severity.
Potential Impact
An unauthenticated attacker can cause a denial of service by exhausting memory resources of the search-api pod through unbounded growth of the tokenReviews cache. This results in service unavailability of the search-v2-api component. There is no impact on confidentiality or integrity. The vulnerability affects availability only.
Mitigation Recommendations
No official patch or fix is currently available for this vulnerability. The vendor advises mitigating the risk by restricting network access to the search-v2-api component via network policies that limit incoming connections to trusted sources only. After applying these network policies, the search-v2-api pod should be restarted to enforce the new rules. This mitigation reduces the attack surface and prevents unauthenticated denial-of-service attempts.
A flaw was found in search-v2-api. (CVE-2026-71469)
Description
CVE-2026-71469 is a high-severity vulnerability in the search-v2-api component of Red Hat Advanced Cluster Management for Kubernetes. An unauthenticated attacker can exploit an unbounded tokenReviews cache by sending requests with unique bearer tokens, causing memory exhaustion of the search-api pod and resulting in a denial of service (DoS). There is no official patch available yet. The vendor recommends mitigating the risk by restricting network access to the search-v2-api component using network policies to limit connections to trusted sources and restarting the pod after applying these policies.
CVSS v3.1
Score 7.5high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-71469 is a denial-of-service vulnerability in the search-v2-api component of Red Hat Advanced Cluster Management for Kubernetes. The flaw arises because each unique bearer token sent by an unauthenticated attacker creates a permanent entry in an unbounded tokenReviews cache that is not properly cleared. This leads to memory exhaustion of the search-api pod, causing service unavailability. The vulnerability is due to allocation of resources without limits or throttling (CWE-770). The attack vector is network-based with low complexity and no privileges or user interaction required. The vulnerability has a CVSS 3.1 base score of 7.5, indicating high severity.
Potential Impact
An unauthenticated attacker can cause a denial of service by exhausting memory resources of the search-api pod through unbounded growth of the tokenReviews cache. This results in service unavailability of the search-v2-api component. There is no impact on confidentiality or integrity. The vulnerability affects availability only.
Mitigation Recommendations
No official patch or fix is currently available for this vulnerability. The vendor advises mitigating the risk by restricting network access to the search-v2-api component via network policies that limit incoming connections to trusted sources only. After applying these network policies, the search-v2-api pod should be restarted to enforce the new rules. This mitigation reduces the attack surface and prevents unauthenticated denial-of-service attempts.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-6gx2-rqm4-38f9
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-71469"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a7d12d2bf8831d5396c18c5
Added to database: 08/13/2026, 00:41:54 UTC
Last enriched: 08/13/2026, 00:56:17 UTC
Last updated: 08/13/2026, 02:41:00 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.