CVE-2026-71469: Red Hat Advanced Cluster Management For Kubernetes 2.11
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. This can lead to memory exhaustion of the search-api pod, resulting in a Denial of Service (DoS).
Affected products
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.11: before 1787689524 (fixed in 1787689524)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.13: before 1787263804 (fixed in 1787263804)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.14: before 1786723845 (fixed in 1786723845)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.15: before 1787238618 (fixed in 1787238618)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.16: before 1787191668 (fixed in 1787191668)
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2.17: before 1787229541 (fixed in 1787229541)
Published 2026-08-12. Last modified 2026-08-27.