Red Hat Security Advisory: Logging for Red Hat OpenShift - 6.4.6
🔗 CVE IDs covered (10)
📋 Description
CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-32285 — github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-33813 — golang.org/x/image: golang: golang.org/x/image: Denial of Service via malformed WEBP image parsing CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing
🎯 Affected products35
- Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/cluster-logging-operator-bundle@sha256:e5b7cc503692837c64463dec9b5f26d4041604af41687089e3d2fa7049d18763_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:036c4b69ad3fc3d21f3874a182250670ba05d85b92f4fb3246dbc9a1b0d5b2f1_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:20a457aef3fe79d1504b3635b44194de337345bccdaea7faed59d2b9d773a78d_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:d379c0ac1ef6531fb9a7e62d305804a3ec0fa4c15464a7c5d2701375548191c1_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:f5318fb921ce00cd615c35da79397b96159141ed5c5f83cc5fd536f6212e4a1d_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:404ab8a3b91ee87b54fedb6e123730d00d056fc4cf0333fdfe89d9d04ed19ade_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:437d5a4c488cd6bf3ab086329f64e67904d60ccde170d163b32b73b530a76000_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:8f4ce021b0c1ba39cb9b57071ea3e35b8e91a35aec8c3188cb8a61eac919c16b_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:d1ae79f914c7ba434f2886ec14c00cb794dc92f9472329a62311dcfcd6ab0750_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:0506600ba49a32d6eeb4b081e33f2a0356a348eb0af8cc9aaa96b1568dc00827_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:1317ad72523ecd91a45290485aa2b5afe9341c8e1aeed026d7e0f9c6ef06a279_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:869a15d3a384b822b84622a030f5c5f9ad7284673ca1b861732e239cdaa17ae3_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:e4a0e68923f34dfdf956a643c8e218e77cd2b8b564b256fe8134f5f36b484a3d_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:36340239fda21b0c95529e24861b98f0c427f0b2a4dcbbc15e800c4008a84170_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:4d4eff309f617b905f126770ef318cc78eee346aa57d72f9e506a875cb9cb0ff_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:613509ec4705bd051a01ff07a738c01ffc2f1766716e8a992af396cc884cfc2f_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:ffcd011e7e5fc98eac4b3a40bf4c5f8faa1e9d6ffd99375fe6a077e07887902c_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/loki-operator-bundle@sha256:303c3bf8579f485f39f83659818afea56e1cf0600fa2b27328b7ea88a2cf0aa6_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:2e27623128ad417e16531721363a85bcb3486e7d1c6e8bb136704da2804fd321_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:4715d0c1ffbffe506a4a7213159eb02b03f7b12e87fe015c270376b858cc8a5e_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:93c4438fdec9e45c6c96b5dca8de34bc634fb8e14acd4cb2832181bb0f99a012_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:f278bc4ab107d4364ccd943b6285a4880075fd33a8b118011fe2bb85cebddc08_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:35ad2b060e4847d7d523184677454213e7b119bd11490b9464d685a2b8dd7188_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:57c8fafa6ac19e0d78846633ad57ecb04ce560f3559981f875606b2da102acf0_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:ab4078df9d968b5ecc3d662c58fda45fd1827eadad28bbbfe43728b7428f26b6_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:e0921ca76f40eba9eae5600ffdf62ca80cbb4c8d6743e1682b0602703f834ac8_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:0797167a007e1c3e89d971c9513b2a51cffabe75185eecf0c07068d1aea6bbf4_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:37625fee5941abe356d51f00535636fecae3670ece4478615a49d9c98c54c8e9_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.4
- registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:62b9f7fcddea5a4f82c483679cb1366b73463434601310a440d373996a086fd3_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.4
- +5 more not shown
✅ Remediation
For OpenShift Container Platform 4.20 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ocp-4-20-release-notes For Red Hat OpenShift Logging 6.4, see the following instructions to apply this update: https://docs.redhat.com/en/documentation/red_hat_openshift_logging/6.4 Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2026:34364
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-32285
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-33813
- externalhttps://access.redhat.com/security/cve/CVE-2026-34986
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_34364.json