Skip to content
Red HatCVE-2026-9165

Red Hat Advanced Cluster Security 4: denial of service

High7.7CVE-2026-9165 · Published Jul 6, 2026 · updated Sep 8, 2026

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Advanced Cluster Security 4
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat SSSD: path traversal
High8.0Jul 7
Red Hat SSSD: insecure default
High8.8Jul 7
Red Hat GIMP: integer overflow
High7.3Jul 7
Red Hat GIMP. The PlayStation TIM loader: integer overflow
Medium5.5Jul 6
Red Hat GIMP: memory corruption
High7.3Jul 6
A flaw exists in the org.keycloak.broker.oidc package where the OIDC broker...
Medium4.8Jul 5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.