Skip to content
VulniPulse
Advisory severityHigh7.5Red Hat Linux

High [CVE-2026-67321] Denial of Service via object serialization bypass

This high-severity Red Hat Linux advisory covers CVE-2026-67321 affecting Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Advanced Cluster Security for Kubernetes 4.10.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-67321 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxUnclassified
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'.

Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path. A flaw was found in axios.

A remote attacker could exploit an incomplete depth-limit bypass when the component serializes objects with specific top-level keys. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Weakness: CWE-770.

Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Security for Kubernetes 4.10; Red Hat Advanced Cluster Security for Kubernetes 4.11; and 20 more.

Affected versions
  • < 0.31.1
  • < 0.33.0
  • < 1.15.1
  • < 1.18.0

Official advisory · high-confidence parse· fetched 2 days ago·verify at source

Fixed versions
  • rhacm2/console-rhel9:1787339249
  • rhacm2/console-rhel9:1787339248
  • advanced-cluster-security/rhacs-main-rhel8:1789411269
  • advanced-cluster-security/rhacs-main-rhel9:1789411320
  • ansible-automation-platform/automation-portal:1788775748
  • grafana12-4-main-12.4.6-0.2.hum1
  • grafana13-1-main-13.1.1-0.3.hum1
  • jaeger-main-2.20.0-0.8.hum1
  • rhmtc/openshift-migration-ui-rhel8:1789546373
  • devspaces/dashboard-rhel9:1789162884
  • openshift-service-mesh/kiali-ossmc-rhel9:1787076322
  • openshift-service-mesh/kiali-rhel9:1787077108
  • openshift-service-mesh/kiali-ossmc-rhel9:1787166293
  • openshift-service-mesh/kiali-rhel9:1787165683
  • quay/quay-rhel8:1788561841
  • quay/quay-rhel8:1788594376
  • quay/quay-rhel8:1788593843
  • quay/quay-rhel8:1788191755
  • quay/quay-rhel9:1789563753
  • quay/quay-rhel9:1790690298
  • quay/quay-rhel8:1788595574
  • satellite/iop-host-inventory-frontend-rhel9:1788322243
  • satellite/iop-vulnerability-frontend-rhel9:1789660969
  • satellite/iop-host-inventory-frontend-rhel9:1788260941
  • satellite/iop-advisor-frontend-rhel9:1789659565
  • satellite/iop-vulnerability-frontend-rhel9:1789660983
  • RHSA-2026:60390
  • RHSA-2026:60388
  • RHSA-2026:67711
  • RHSA-2026:67714
  • RHSA-2026:65118
  • RHSA-2026:47619
  • RHSA-2026:48241
  • RHSA-2026:48758
  • RHSA-2026:68681
  • RHSA-2026:68754
  • RHSA-2026:59566
  • RHSA-2026:59583
  • RHSA-2026:66084
  • RHSA-2026:66523
  • RHSA-2026:70267
  • RHSA-2026:63307
  • RHSA-2026:69255
  • RHSA-2026:74511
  • RHSA-2026:65514
  • RHSA-2026:63373

Official advisory · high-confidence parse· fetched 2 days ago·verify at source

Mitigation

Upgrade to a fixed release: rhacm2/console-rhel9:1787339249, rhacm2/console-rhel9:1787339248, advanced-cluster-security/rhacs-main-rhel8:1789411269, advanced-cluster-security/rhacs-main-rhel9:1789411320, ansible-automation-platform/automation-portal:1788775748, grafana12-4-main-12.4.6-0.2.hum1. That is the remediation for this advisory.

The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.

Official advisory · high-confidence parse· fetched 2 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.