Denial of Service Vulnerability in Red Hat Search API
CVE-2026-71469

7.5HIGH

What is CVE-2026-71469?

A flaw identified in the Red Hat Search V2 API allows an unauthenticated attacker to exploit the system by sending crafted requests with unique random bearer tokens. Each token generates a permanent entry in the unbounded tokenReviews cache, which fails to clear effectively. This oversight can lead to significant memory exhaustion within the API pod, potentially resulting in a Denial of Service (DoS) condition, thereby disrupting service availability.

Affected Version(s)

Red Hat Advanced Cluster Management for Kubernetes 2.11 1787689524

Red Hat Advanced Cluster Management for Kubernetes 2.13 1787263804

Red Hat Advanced Cluster Management for Kubernetes 2.14 1786723845

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.