CVE-2026-44990

Red Hat Security Advisory: Red Hat Advanced Cluster Management for Kubernetes v2.17.1 security update

criticalEPSS 0.6 %

Beschreibung

ApostropheCMS ist ein quelloffenes Content-Management-System für Node.js, und `sanitize-html` bietet einen einfachen HTML-Sanitizer mit einer klaren API. Unter der Standardkonfiguration können Versionen von `sanitize-html`, die älter als 2.17.4 sind, von Angreifern kontrollierten Inhalt innerhalb eines nicht erlaubten `xmp`-Elements in live HTML oder JavaScript umwandeln. Dies ist ein Bypass des Sanitizers im Standardpfad `disallowedTagsMode: 'discard'` und kann zu gespeicherten XSS-Angriffen führen, wenn Anwendungen den bereinigten Ausgang an Benutzer zurückgeben. Version 2.17.4 behebt das Problem.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.3
Quelle: nvd-v3
46.8 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.6 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-26 20:08 UTC
CWE-79

Weakness-Klassen (CWE)

  • CWE-79Base

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-10 13:20 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/44xxx/CVE-2026-44990.json">CVE-2026-44990</a>
  2. CVE Modified2026-09-09 13:20 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/44xxx/CVE-2026-44990.json">CVE-2026-44990</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:63046
    • Reference: https://access.redhat.com/errata/RHSA-2026:63103
  3. CVE Modified2026-09-07 13:20 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/44xxx/CVE-2026-44990.json">CVE-2026-44990</a>
  4. CVE Modified2026-09-01 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:60441
  5. CVE Modified2026-08-25 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: multicluster engine for Kubernetes 2.1, multicluster engine for Kubernetes 2.11, multicluster engine for Kubernetes 2.6 (+26)multicluster engine for Kubernetes 2.1, multicluster engine for Kubernetes 2.11, multicluster engine for Kubernetes 2.6 (+26)

Betroffene Betriebssysteme

  • linux

    ubuntu / containerd-stablequesting

  • linux

    ubuntu / containerd-stableresolute

  • windows

    microsoft / windows_10_1607

  • windows

    microsoft / windows_10_1809

  • windows

    microsoft / windows_10_21h2

  • windows

    microsoft / windows_10_22h2

  • windows

    microsoft / windows_11_23h2

  • windows

    microsoft / windows_11_24h2

  • windows

    microsoft / windows_11_25h2

  • windows

    microsoft / windows_11_26h1

  • windows

    microsoft / windows_server_2012r2

  • windows

    microsoft / windows_server_2012

  • windows

    microsoft / windows_server_2016

  • windows

    microsoft / windows_server_2019

  • windows

    microsoft / windows_server_2022

  • windows

    microsoft / windows_server_2025

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • apache

    cloudstack4.15.0.0 – 4.20.3.1

  • apache

    cloudstack4.21.0.0 – 4.22.1.1

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • bitnami

    golang1.26.0-0

  • bitnami

    grafana12.0.0

  • bitnami

    grafana12.3.0

  • bitnami

    grafana12.4.0

  • bitnami

    grafana13.0.0

  • bitnami

    grafana8.5.0

  • bitnami

    thrift

  • go

    github.com/go-git/go-billy/v5

  • go

    github.com/hamba/avro/v2

  • go

    github.com/iskorotkov/avro/v2

  • go

    github.com/labstack/echo/v4

Quellen & Referenzen

Verknüpfte CVEs

38 weitere CVEs anzeigen

Verknüpfte Empfehlungen

IDCVE-2026-44990