RHSA-2026:3427HighCVSS 7.5

Red Hat Security Advisory: Red Hat build of OpenTelemetry 3.9.0 release

Published
February 26, 2026
Last Modified
August 25, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url

🎯 Affected products14

  • Red Hat OpenShift distributed tracing 3.9.3
  • registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:35e07bd8a1f487a2fcb1f39579d8988a5cd037250a92408e4cf91b14054fa25e_arm64 as a component of Red Hat OpenShift distributed tracing 3.9.3
  • registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:7056374735472855598fd8e368b74ce3666e54182549cc54b29abf1927f589f1_s390x as a component of Red Hat OpenShift distributed tracing 3.9.3
  • registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:aab9d277ecf66ac98e1b582ca559afba360d15bd3695e9b82f4e2975cd94d83e_ppc64le as a component of Red Hat OpenShift distributed tracing 3.9.3
  • registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:f970e31da49e636dcf93d989cae7b4a0c752d0dea05a3f9fcdcf5b2c6ac5f04e_amd64 as a component of Red Hat OpenShift distributed tracing 3.9.3
  • registry.redhat.io/rhosdt/opentelemetry-operator-bundle@sha256:299677474d73be959b3b229c7e534c7d1f88aafc5265850c0dcd62874d38a119_amd64 as a component of Red Hat OpenShift distributed tracing 3.9.3
  • registry.redhat.io/rhosdt/opentelemetry-rhel9-operator@sha256:25d378e67f1ca2e0731e9e91b0e5b32e25d7a470ccd4c6e9f053b98561cde692_s390x as a component of Red Hat OpenShift distributed tracing 3.9.3
  • registry.redhat.io/rhosdt/opentelemetry-rhel9-operator@sha256:35e040b1ef8572a328fdd6ef47080a4ab7283d163692ca512a484532a4baa26d_amd64 as a component of Red Hat OpenShift distributed tracing 3.9.3
  • registry.redhat.io/rhosdt/opentelemetry-rhel9-operator@sha256:68d386236922cc4111eac7fb59828b611e61e4a01d983f55df26474a670852a3_ppc64le as a component of Red Hat OpenShift distributed tracing 3.9.3
  • registry.redhat.io/rhosdt/opentelemetry-rhel9-operator@sha256:a9b078c2d669a38409669a464b5fb5d9003ee8f4d1dd9fce5cbe8f24c1b70ed2_arm64 as a component of Red Hat OpenShift distributed tracing 3.9.3
  • registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel9@sha256:2b20f7c4e45efe3b492822550db1160bc36e9834d684a83f869e45e282c2529a_amd64 as a component of Red Hat OpenShift distributed tracing 3.9.3
  • registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel9@sha256:83f2f6c64882fabaac3075cb2c6b3b5ab53aa45dac6e4d93577221a018c592fa_ppc64le as a component of Red Hat OpenShift distributed tracing 3.9.3
  • registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel9@sha256:8e96cd120adaf28b22e8f9ab8028c4c0d3de04a626b9051b5c5c183832c58e80_s390x as a component of Red Hat OpenShift distributed tracing 3.9.3
  • registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel9@sha256:f722ba5871a6c036db161d5ca47c878044e9fe7e31dadcc402c5ed83e5a14b7f_arm64 as a component of Red Hat OpenShift distributed tracing 3.9.3

✅ Remediation

For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/operators/administrator-tasks#olm-upgrading-operators Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

🔗 References (5)