Skip to main content
EPSS 0.7%top 49%

Red Hat Security Advisory: RHACS 4.10.4 security and bug fix update

0
High
Published: 06/17/2026 (06/17/2026, 10:26:32 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

See the release notes (link in the references section) for a description of the fixes and enhancements in this particular release.

Affected software

Affected versions
=0>=2.6 <2.9.5Red Hatmulticluster engine for Kubernetesmulticluster engine for Kubernetes 2.6amd64registry.redhat.io/multicluster-engine/assisted-installer-rhel8@sha256:b1eb0d2804359d83c18c8eec4dc663001b7f89e954a31fd2c47053c27cb4437e_amd64multicluster engine for Kubernetes 2.9registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:ffa91edb4cdc029533e51a628674e6fa101a34e61550241b5c1ac3f7a80d426a_amd64Red Hat Advanced Cluster Security for KubernetesRed Hat Advanced Cluster Security for Kubernetes 4.9registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:6972f0c1cbb441f82433e265b3da8cdd8dc6856c56424585ee4ced3fe5c09ae1_amd64Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 8)ppc64legit-lfs-0:3.4.1-11.el8_10.ppc64le01.26.0-01.27.0-0registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:0dea3f88818977c2392172f46f00c2298360811d7f1d8a8878a947ee986f68e9_amd64Red Hat Advanced Cluster SecurityRed Hat Advanced Cluster Security 4.9Red Hat Enterprise Linux AppStream (v. 9)srcgit-lfs-0:3.7.1-4.el9_8.1.srcRed Hat Enterprise Linux AppStream (v. 10)git-lfs-0:3.7.1-5.el10_2.5.srcRed Hat OpenShift EnterpriseRed Hat OpenShift Container Platform 4.22Red Hat Advanced Cluster Security for Kubernetes 4.10registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:cc671d793496771a5ab3573787848947b8b38cbf0de653c48d1a59e38d6f540b_amd64grafana-pcp-0:5.3.0-7.el10_2.srcgrafana-pcp-0:5.1.1-17.el9_8.srcgrafana-0:9.2.10-31.el8_10.srcgrafana-pcp-0:5.1.1-16.el8_10.srcRed Hat Enterprise Linux AppStream EUS (v.9.6)ignition-0:2.21.0-7.el9_6.srcaarch64go-toolset-0:1.26.5-1.el9_8.aarch64go-toolset-0:1.26.5-1.el10_2.aarch64x86_64osbuild-composer-0:132.2-10.el9_6.x86_64Red Hat OpenShift Container Platform 4.20<0.27.2-r1<0.29.0-r0MicrosoftAzure Linux3.0Azure Linux 3.0application-gateway-kubernetes-ingresss390xgo-toolset-0:1.26.5-1.el10_2.s390xRed Hat Enterprise Linux AppStream E4S (v.9.4)ignition-0:2.17.0-2.el9_4.1.srcmulticluster engine for Kubernetes 2.9.0<1.18.1-r0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 23:43:43 UTC

Technical Analysis

CVE-2026-39821 is a vulnerability in golang.org/x/net/idna where the ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to ASCII-only hostnames, such as xn--example-.com being normalized to example.com instead of producing an error. This improper validation can allow an attacker to supply a Punycode hostname that passes an ASCII-only authorization check but is normalized to a restricted ASCII hostname, resulting in privilege escalation. Red Hat products including RHEL, OpenShift, and Advanced Cluster Security that ship the Go toolchain or bundle golang.org/x/net are exposed. The issue is addressed by upgrading to a fixed golang.org/x/net release with the corrected idna handling.

Potential Impact

The vulnerability allows privilege escalation by bypassing hostname validation checks, potentially granting unauthorized access to restricted hostnames. The impact is rated high by Red Hat, with confidentiality and integrity impacts considered high, but no availability impact. The exposure is broad across multiple Red Hat products that include the affected Go packages.

Mitigation Recommendations

Red Hat advises upgrading to the fixed golang.org/x/net release that includes the corrected idna processing. This is done via updated golang or dependent package rebuilds provided by Red Hat. Users should apply the security updates released by Red Hat for their affected products as detailed in the Red Hat Security Advisory RHSA-2026:26546. No alternative mitigations are specified.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:26546
Cve Count
2
Additional Cves
["CVE-2026-46595"]
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a32cf199f87a2db092a4a05

Added to database: 06/17/2026, 16:45:13 UTC

Last enriched: 08/14/2026, 23:43:43 UTC

Last updated: 09/14/2026, 00:52:57 UTC

Views: 112

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:26546https://access.redhat.com/security/cve/CVE-2026-39821https://access.redhat.com/security/cve/CVE-2026-39828https://access.redhat.com/security/cve/CVE-2026-39829https://access.redhat.com/security/cve/CVE-2026-39835https://access.redhat.com/security/cve/CVE-2026-42508https://access.redhat.com/security/cve/CVE-2026-46595https://access.redhat.com/security/updates/classification/https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.9/html-single/release_notes/index#about-this-release-498_release-notes-49Canonical URLReference 11Reference 12Reference 13Reference 14Reference 15Reference 16Reference 17Reference 18Reference 19Reference 20Reference 21Reference 22Reference 23Reference 24Reference 25Reference 26Reference 27Reference 28Reference 29Reference 30Reference 31Reference 32Reference 33Reference 34Reference 35Reference 36Reference 37Reference 38Reference 39Reference 40Reference 41Reference 42Reference 43Reference 44Reference 45Reference 46Reference 47Reference 48Reference 49Reference 50Reference 51Reference 52Reference 53Reference 54Reference 55Reference 56Reference 57Reference 58Reference 59Reference 60Reference 61Reference 62Reference 63Reference 64Reference 65Reference 66Reference 67Reference 68Reference 69Reference 70Reference 71Reference 72Reference 73Reference 74Reference 75Reference 76Reference 77Reference 78Reference 79Reference 80Reference 81Reference 82Reference 83Reference 84Reference 85Reference 86Reference 87Reference 88Reference 89Reference 90Reference 91Reference 92Reference 93Reference 94Reference 95Reference 96Reference 97Reference 98Reference 99Reference 100Reference 101https://access.redhat.com/security/cve/CVE-2026-53488Canonical URLCanonical URLhttps://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.10/html-single/release_notes/index#about-this-release-4104_release-notes-410Canonical URLhttps://access.redhat.com/security/cve/CVE-2026-44486https://access.redhat.com/security/cve/CVE-2026-44487https://access.redhat.com/security/cve/CVE-2026-44488https://access.redhat.com/security/cve/CVE-2026-44492https://access.redhat.com/security/cve/CVE-2026-44494https://access.redhat.com/security/cve/CVE-2026-44495https://access.redhat.com/security/cve/CVE-2026-44496https://access.redhat.com/security/cve/CVE-2026-44990Canonical URLhttps://access.redhat.com/security/updates/classification/#important2498152RHEL-193476Canonical URLCanonical URLCanonical URLRHEL-193473Canonical URLReference 124Reference 125Canonical URLCanonical URLCanonical URLCanonical URLCanonical URLCanonical URLReference 132Reference 133Reference 134Reference 135Reference 136Reference 137https://access.redhat.com/errata/RHSA-2026:52826Canonical URLReference 140Reference 141Reference 142Reference 143Reference 144Reference 145Reference 146Reference 147Reference 148Reference 149Reference 150Reference 151Reference 152Reference 153Reference 154Reference 155Reference 156Reference 157Reference 158https://access.redhat.com/security/cve/CVE-2026-42502https://access.redhat.com/errata/RHSA-2026:56143Canonical URLhttps://access.redhat.com/errata/RHSA-2026:54580Canonical URLhttps://access.redhat.com/errata/RHSA-2026:56223Canonical URLReference 166Reference 167Reference 168Reference 1692493622Canonical URLhttps://access.redhat.com/errata/RHSA-2026:59549Canonical URLReference 174Reference 175Reference 176Reference 177Reference 178Reference 179Reference 180Reference 181Reference 182Reference 183Reference 184Reference 185Reference 186Reference 187CVE-2026-39821 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna - VEXMicrosoft Support LifecycleCommon Vulnerability Scoring SystemReference 191Reference 192Reference 193Reference 194Reference 195Reference 196Reference 197Reference 198Reference 199Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses