Red Hat OpenShift Cluster Manager
Services on the Red Hat Hybrid Cloud Console are cloud services that provide customers with prescriptive analytics and applications to manage Red Hat environments. Because the services are hosted and managed by Red Hat, there is no infrastructure that a customer needs to deploy.
Browse the latest documentation
Latest security advisories
| Severity | Advisory/CVE | Synopsis | Date |
|---|---|---|---|
| Severity Important | Advisory/CVECVE-2026-56858 | Synopsis A flaw was found in the `html/template` component of Go (golang). Pathological inputs could prematurely close an unescaped forward slash ('/'), allowing an attacker to inject arbitrary content. This could lead to Cross-Site Scripting (XSS), where malicious scripts are executed in a user's browser, potentially compromising user data or actions. | Date |
| Severity Important | Advisory/CVECVE-2026-56862 | Synopsis A flaw was found in the `crypto/tls` package, part of `golang`. A malicious client can exploit this vulnerability by continuously sending KeyUpdate messages to a server. This forces the server to perform indefinite key derivation operations, leading to resource exhaustion and a Denial of Service (DoS) condition. | Date |
| Severity Important | Advisory/CVECVE-2026-56859 | Synopsis A flaw was found in the `encoding/xml` package of Go. The `DecodeElement` function failed to correctly track recursion depth, which could lead to stack exhaustion. A remote attacker could exploit this vulnerability by providing a specially crafted XML input, resulting in a Denial of Service (DoS) for the affected application. | Date |
| Severity Important | Advisory/CVECVE-2026-71235 | Synopsis A flaw was found in Magistrala's Rules Engine. An authenticated low-privileged user can exploit this vulnerability by creating rules with embedded Go or Lua scripts. These scripts are executed server-side without sufficient validation, allowing for arbitrary file read and write operations, access to internal databases, and Server-Side Request Forgery (SSRF) against internal microservices. This could lead to significant data compromise and unauthorized system access. | Date |
| Severity Important | Advisory/CVECVE-2026-41178 | Synopsis A flaw was found in OpenTelemetry-Go. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by sending oversized or invalid baggage headers. The `Parse` function, in affected versions, failed to reject raw-length inputs, leading to excessive processing and error logging when handling these large inputs. | Date |
Top resources
Knowledgebase
Access articles and solutions to find answers to your questions.
Troubleshooting
Connect to the right information to self-solve issues quickly and efficiently.
Go to the Hybrid Cloud Console
Access cloud offerings in the Hybrid Cloud Console.
Lifecycle
View the various levels of maintenance for each release of a product over a period from initial release to the end of maintenance.
Get support
Support cases
Get answers quickly by opening a support case with us.
Live chat
Directly access our support engineers during weekday business hours.
Call or email
Speak directly with a Red Hat Support expert by phone or through email.