Red Hat released Important security updates for Red Hat Advanced Cluster Security for Kubernetes (RHACS) 4.5, 4.6, and 4.7. Updated images—RHACS 4.5.9, 4.6.5, and 4.7.2—remediate vulnerabilities in bundled http-proxy-middleware, redoc, golang-jwt/jwt, and, for 4.5, libxml2 and OpenSSL. The fixes include CVE-2024-21536 and CVE-2024-57083, denial-of-service issues respectively involving http-proxy-middleware and Redoc prototype pollution, plus CVE-2025-30204, which can cause excessive memory allocation while parsing JWT headers. The releases also correct selected product defects affecting compliance displays, delegated scanning, RBAC, GKE compatibility, and image-signature verification.
Red Hat also updated Submariner container images used by Red Hat Advanced Cluster Management for Kubernetes (ACM) 2.11 and 2.12, delivering Submariner 0.18.5 and 0.19.4. These images address an ICMP Packet Too Large injection issue in quic-go and memory-consumption flaws in golang.org/x/oauth2/jws and golang-jwt/jwt; the ACM 2.11 update additionally fixes sensitive HTTP-header leakage through cross-domain redirects in Go net/http and a P-256 timing side channel on ppc64le. Organizations should upgrade affected RHACS and ACM deployments to the supplied patched container images across their supported architectures.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2025:4810 for Submariner 0.18.5 images used by Advanced Cluster Management for Kubernetes 2.11. It addressed five vulnerabilities, including quic-go ICMP packet injection, Go net/http cross-domain header leakage, a P-256 timing side channel, and memory-consumption flaws in OAuth2 and JWT parsing components.
Red Hat issued Important advisory RHSA-2025:4250 for Submariner 0.19.4 images used by Advanced Cluster Management for Kubernetes 2.12. The update fixed CVE-2024-53259 in quic-go and memory-consumption issues CVE-2025-22868 and CVE-2025-30204.
Red Hat issued Important advisory RHSA-2025:3930, releasing RHACS 4.7.2 container images for earlier RHACS 4.7 users. The update fixed vulnerabilities in http-proxy-middleware, golang-jwt/jwt, and Redoc, including the Redoc prototype-pollution issue CVE-2024-57083.
Red Hat issued Important advisory RHSA-2025:3929 and updated RHACS 4.6 images to version 4.6.5. It addressed denial-of-service and prototype-pollution issues, including CVE-2024-21536, CVE-2025-30204, and CVE-2024-57083, and fixed several operational defects.
Red Hat issued Important advisory RHSA-2025:3928 for RHACS 4.5, releasing version 4.5.9 images. The update addressed vulnerabilities including the Redoc prototype-pollution flaw CVE-2024-57083, as well as issues in libxml2, OpenSSL, http-proxy-middleware, and golang-jwt/jwt.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.