VYPR

multicluster-global-hub

by Red Hat

CVEs (3)

  • CVE-2026-71576HigAug 10, 2026
    risk 0.55cvss 8.5epss 0.00

    A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka client certificate, can manipulate the…

  • CVE-2026-75762impAug 31, 2026
    risk 0.44cvss 6.8epss —

    multicluster-global-hub: multicluster-global-hub: Transport-layer MITM: TLS CA bundle pulled from unvalidated ConfigMap, `InsecureSkipVerify` fallback

  • CVE-2026-71577MedAug 10, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sensitive bootstrap kubeconfigs, which…