Skip to main content
EPSS 0.2%top 87%

Red Hat Security Advisory: Submariner v0.24 security fixes and container updates

0
High
Published: 09/03/2026 (09/03/2026, 04:36:21 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Submariner is a Kubernetes operator that enables cross-cluster connectivity for services and pods, implementing KEP-1645 (Multi-Cluster Services API). After deploying the Submariner operator, it can enable direct networking between pods and services across different Kubernetes clusters. For more information about Submariner, see the Submariner open source community website at: https://submariner.io/.

Affected software

Affected versions
>=2.13.0 <2.13.10Red HatRed Hat Advanced Cluster Management for KubernetesRed Hat Advanced Cluster Management for Kubernetes 2.13amd64registry.redhat.io/rhacm2/acm-cli-rhel9@sha256:31bd91156f49687d2efffd3be971d9ee0e16abb420b8e8b958caa88b97770020_amd64OpenShift File Integrity Operator - FIOOpenShift File Integrity Operator - FIO 1registry.redhat.io/compliance/openshift-file-integrity-operator-bundle@sha256:c38526d3744cb4f6b2487656c617a8bf40dd996d6e8ad903aa75a69050e290c8_amd64Compliance OperatorCompliance Operator 1File Integrity OperatorFile Integrity Operator 1Red Hat OpenShift Container PlatformRed Hat OpenShift Container Platform 4.22registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:56cd8314cc9791e043cb4e5ace324013f4ce4c825fb5f9119b1a6c6871b76a3b_amd64Red Hat Advanced Cluster Management for Kubernetes 2.17registry.redhat.io/rhacm2/lighthouse-agent-rhel9@sha256:329806e6d9cee8c20823f45a67c1b0cdb4a8af957c520ef8303557576e8a32f0_amd64ppc64leregistry.redhat.io/openshift4/ose-kubevirt-cloud-controller-manager-rhel9@sha256:a9edb90a7efaeaada322b051c1b4cda47df859fad20ed42574fbe0fa00d15324_ppc64leRed Hat OpenShift Container Platform 4.21arm64registry.redhat.io/openshift4/ose-multus-route-override-cni-rhel9@sha256:c09b7a75cdaeba80d9dcd42ca5c478bfbb984c120684a079ec6621c44eea57ca_arm64registry.redhat.io/openshift4/ose-agent-installer-ui-rhel9@sha256:56a4bbf64c6839cba33d16bf751519edfbb48a4ae3d12fa573bdb28051ee0852_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 22:55:38 UTC

Technical Analysis

CVE-2026-27136 is a vulnerability in the golang.org/x/net/html package used by Red Hat Advanced Cluster Management for Kubernetes. When arbitrary HTML is parsed and rendered, it can produce an unexpected HTML tree that bypasses sanitization mechanisms, enabling Cross-Site Scripting (XSS) attacks. This flaw can lead to information disclosure or arbitrary code execution in affected applications. The vulnerability requires user interaction and is rated as Important by Red Hat with a CVSS v3 base score of 8.1. The Red Hat advisory provides updated container images in version 2.13.10 that address this and other security issues. The update is recommended to mitigate these risks.

Potential Impact

Successful exploitation of CVE-2026-27136 can allow attackers to bypass HTML sanitization, resulting in Cross-Site Scripting (XSS) attacks. This may lead to disclosure of sensitive information such as user cookies and session data, or execution of arbitrary code in the context of the affected application. The vulnerability affects confidentiality and integrity but does not impact availability. Exploitation requires user interaction with crafted malicious HTML content. No known active exploits have been reported.

Mitigation Recommendations

A security update is available in Red Hat Advanced Cluster Management for Kubernetes version 2.13.10, which includes fixes for CVE-2026-27136 and other vulnerabilities. Users should apply this update after ensuring all previously released relevant errata are installed. No alternative mitigations meeting Red Hat's criteria for ease of use and applicability are currently available. Refer to Red Hat's official documentation for update procedures.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:47737
Cve Count
11
Additional Cves
["CVE-2026-27145","CVE-2026-39821","CVE-2026-42508","CVE-2026-44740","CVE-2026-44990","CVE-2026-45447","CVE-2026-46595","CVE-2026-50151","CVE-2026-53488","CVE-2026-59869"]
State
PUBLISHED

Threat ID: 6a6ae5229c2644c7f8983e30

Added to database: 07/30/2026, 05:46:10 UTC

Last enriched: 08/14/2026, 22:55:38 UTC

Last updated: 09/15/2026, 01:45:37 UTC

Views: 49

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:47737https://access.redhat.com/security/cve/CVE-2026-27136https://access.redhat.com/security/cve/CVE-2026-27145https://access.redhat.com/security/cve/CVE-2026-39821https://access.redhat.com/security/cve/CVE-2026-42508https://access.redhat.com/security/cve/CVE-2026-44740https://access.redhat.com/security/cve/CVE-2026-44990https://access.redhat.com/security/cve/CVE-2026-45447https://access.redhat.com/security/cve/CVE-2026-46595https://access.redhat.com/security/cve/CVE-2026-50151https://access.redhat.com/security/cve/CVE-2026-53488https://access.redhat.com/security/cve/CVE-2026-59869https://access.redhat.com/security/updates/classification/https://access.redhat.com/security/updates/classification/#importantCanonical URLhttps://access.redhat.com/errata/RHSA-2026:54288https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/cve/CVE-2026-32282https://access.redhat.com/security/cve/CVE-2026-42151https://access.redhat.com/security/cve/CVE-2026-42154https://access.redhat.com/security/cve/CVE-2026-42502Canonical URLhttps://access.redhat.com/errata/RHSA-2026:60441https://access.redhat.com/security/cve/CVE-2026-33814https://access.redhat.com/security/cve/CVE-2026-45623https://access.redhat.com/security/cve/CVE-2026-48801https://access.redhat.com/security/cve/CVE-2026-54423https://access.redhat.com/security/cve/CVE-2026-69153https://access.redhat.com/security/cve/CVE-2026-73566Canonical URLhttps://access.redhat.com/errata/RHSA-2026:63016https://access.redhat.com/security/cve/CVE-2026-41178https://access.redhat.com/security/cve/CVE-2026-62309https://access.redhat.com/security/cve/CVE-2026-66780https://access.redhat.com/security/cve/CVE-2026-66781https://access.redhat.com/security/cve/CVE-2026-66782https://access.redhat.com/security/cve/CVE-2026-66783https://access.redhat.com/security/cve/CVE-2026-66785https://access.redhat.com/security/cve/CVE-2026-66786https://access.redhat.com/security/cve/CVE-2026-66787https://access.redhat.com/security/cve/CVE-2026-66788Canonical URLhttps://access.redhat.com/errata/RHSA-2026:63046https://access.redhat.com/security/cve/CVE-2026-35469https://access.redhat.com/security/cve/CVE-2026-54272Canonical URLhttps://access.redhat.com/errata/RHSA-2026:63096https://access.redhat.com/security/cve/CVE-2026-39825https://access.redhat.com/security/cve/CVE-2026-69192Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses