Red Hat Security Advisory: Submariner v0.24 security fixes and container updates
Submariner is a Kubernetes operator that enables cross-cluster connectivity for services and pods, implementing KEP-1645 (Multi-Cluster Services API). After deploying the Submariner operator, it can enable direct networking between pods and services across different Kubernetes clusters. For more information about Submariner, see the Submariner open source community website at: https://submariner.io/.
AI Analysis
Technical Summary
CVE-2026-27136 is a vulnerability in the golang.org/x/net/html package used by Red Hat Advanced Cluster Management for Kubernetes. When arbitrary HTML is parsed and rendered, it can produce an unexpected HTML tree that bypasses sanitization mechanisms, enabling Cross-Site Scripting (XSS) attacks. This flaw can lead to information disclosure or arbitrary code execution in affected applications. The vulnerability requires user interaction and is rated as Important by Red Hat with a CVSS v3 base score of 8.1. The Red Hat advisory provides updated container images in version 2.13.10 that address this and other security issues. The update is recommended to mitigate these risks.
Potential Impact
Successful exploitation of CVE-2026-27136 can allow attackers to bypass HTML sanitization, resulting in Cross-Site Scripting (XSS) attacks. This may lead to disclosure of sensitive information such as user cookies and session data, or execution of arbitrary code in the context of the affected application. The vulnerability affects confidentiality and integrity but does not impact availability. Exploitation requires user interaction with crafted malicious HTML content. No known active exploits have been reported.
Mitigation Recommendations
A security update is available in Red Hat Advanced Cluster Management for Kubernetes version 2.13.10, which includes fixes for CVE-2026-27136 and other vulnerabilities. Users should apply this update after ensuring all previously released relevant errata are installed. No alternative mitigations meeting Red Hat's criteria for ease of use and applicability are currently available. Refer to Red Hat's official documentation for update procedures.
Red Hat Security Advisory: Submariner v0.24 security fixes and container updates
Description
Submariner is a Kubernetes operator that enables cross-cluster connectivity for services and pods, implementing KEP-1645 (Multi-Cluster Services API). After deploying the Submariner operator, it can enable direct networking between pods and services across different Kubernetes clusters. For more information about Submariner, see the Submariner open source community website at: https://submariner.io/.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-27136 is a vulnerability in the golang.org/x/net/html package used by Red Hat Advanced Cluster Management for Kubernetes. When arbitrary HTML is parsed and rendered, it can produce an unexpected HTML tree that bypasses sanitization mechanisms, enabling Cross-Site Scripting (XSS) attacks. This flaw can lead to information disclosure or arbitrary code execution in affected applications. The vulnerability requires user interaction and is rated as Important by Red Hat with a CVSS v3 base score of 8.1. The Red Hat advisory provides updated container images in version 2.13.10 that address this and other security issues. The update is recommended to mitigate these risks.
Potential Impact
Successful exploitation of CVE-2026-27136 can allow attackers to bypass HTML sanitization, resulting in Cross-Site Scripting (XSS) attacks. This may lead to disclosure of sensitive information such as user cookies and session data, or execution of arbitrary code in the context of the affected application. The vulnerability affects confidentiality and integrity but does not impact availability. Exploitation requires user interaction with crafted malicious HTML content. No known active exploits have been reported.
Mitigation Recommendations
A security update is available in Red Hat Advanced Cluster Management for Kubernetes version 2.13.10, which includes fixes for CVE-2026-27136 and other vulnerabilities. Users should apply this update after ensuring all previously released relevant errata are installed. No alternative mitigations meeting Red Hat's criteria for ease of use and applicability are currently available. Refer to Red Hat's official documentation for update procedures.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:47737
- Cve Count
- 11
- Additional Cves
- ["CVE-2026-27145","CVE-2026-39821","CVE-2026-42508","CVE-2026-44740","CVE-2026-44990","CVE-2026-45447","CVE-2026-46595","CVE-2026-50151","CVE-2026-53488","CVE-2026-59869"]
- State
- PUBLISHED
Threat ID: 6a6ae5229c2644c7f8983e30
Added to database: 07/30/2026, 05:46:10 UTC
Last enriched: 08/14/2026, 22:55:38 UTC
Last updated: 09/15/2026, 01:45:37 UTC
Views: 49
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.