RHSA-2026:39810HighCVSS 8.8

Red Hat Security Advisory: Red Hat OpenStack Services on OpenShift 18.0 (golang-github-openstack-k8s-operators-os-diff) security update

Published
July 15, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-27137 — crypto/x509: Incorrect enforcement of email constraints in crypto/x509 CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVE-2026-33810 — crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME

🎯 Affected products6

  • 9Base-RHOSO-TOOLS-18
  • Red Hat OpenStack Services on OpenShift 18.0
  • golang-github-openstack-k8s-operators-os-diff-0:0.1.1-18.0.20260602234716.a95ae05.el9ost.src as a component of 9Base-RHOSO-TOOLS-18
  • golang-github-openstack-k8s-operators-os-diff-0:0.1.1-18.0.20260602234716.a95ae05.el9ost.src as a component of Red Hat OpenStack Services on OpenShift 18.0
  • golang-github-openstack-k8s-operators-os-diff-0:0.1.1-18.0.20260602234716.a95ae05.el9ost.x86_64 as a component of 9Base-RHOSO-TOOLS-18
  • golang-github-openstack-k8s-operators-os-diff-0:0.1.1-18.0.20260602234716.a95ae05.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment.

🔗 References (13)