RHSA-2026:47952HighCVSS 9.1

Red Hat Security Advisory: Logging for Red Hat OpenShift - 6.2.12

Published
July 29, 2026
Last Modified
August 30, 2026

🔗 CVE IDs covered (15)

📋 Description

CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33810 — crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header

🎯 Affected products35

  • Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/cluster-logging-operator-bundle@sha256:47ca97af3513344cfd4889396e3843357323d33fddb98cce46f8e5d5a0b1a5d0_amd64 as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:0052d8243ab61cd2cf9961c8c521feae799b2b296401b8342fd4f5b52673f0a5_ppc64le as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:100e08b8c944de3a46bae4dfa155109bd6fe78479995005f47bcd4beee258924_arm64 as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:802cd3226296e0feeef79baecd2a4a32fef715af3efb60b5748c9a4ebf02dd08_s390x as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:9e5f624ea6566612b579400be7648bf2fab8eebcfe4dff301b8cb4da096960e8_amd64 as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:153ab96fc7d2bab733b62abf87631c839308d31d595d616bf8edfd2cddcabe3f_s390x as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:1853bf9f3483509135dbdfd8bf708ca6fac04bb5925585d8f7a0d7053823dcfb_amd64 as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:4fd3fcc1466cfad850d25ff825dd3e8542afb391af2d70e50a279d0829d9267c_ppc64le as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:666a815d03869f65903b2a8d87bea5aa965912521512dcb1618b0d06dcb9174e_arm64 as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:7d4101bfd718c9613264ccc2391d37893897a9ce362b443923f02824256a1a7d_amd64 as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:99310027ad651fdd6b13d1cc2698f4edeb63eef6340144c66c7f90a185c0ce8d_ppc64le as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:9eeef9597877ed7ac9a1a0d0ec1daa941a503c3e7e38135b4a263f35ad8668e5_arm64 as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:cc636250743b619bfa997f02a22850503cdbe3df90f77a27259bc1c7184b470e_s390x as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:1e316441723ad6e2ce988755709a2e2d98406fc58f06942c42b0b701e33b64b7_arm64 as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:65fb432f914dc0b384a4c7d97a3d520ee127cf9c3b773e7f91b28b7811223b62_ppc64le as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:9634da775abc1c3b64b33a7fe3e891e543caf321099eb8b989f9c833471047b2_s390x as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:a80f627cee8092acfa7f248c90f162e04d9435aa6aafa38365b68a341bdc4039_amd64 as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/loki-operator-bundle@sha256:99ad45fe6f420e59b6cc207b92e14f4e2637a1f5a4daac0776075aa365419d88_amd64 as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:161adf962803dfcc53ffedfe2cdda056760d227b0e39a9f71dd93aec8392630f_s390x as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:6f0b3b3f82757b7c908a027466f6f58adb6ef44732af52c8d80f4c2e686b6859_arm64 as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:8da02916a76bc365fdd07f25ecd6e0ea9cf5f9b61a8368a2681b98eaee5de3b6_ppc64le as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:e2574a9506247daf24517c927f3fc300be1a92941e9a637a6ac8ca7c8c8a3e53_amd64 as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:3f354761f4982ed497a7a6a9456515b42574e1eee062d1e28676ecb98f205c2e_ppc64le as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:6d706b347ad30aaa388fe171fb2b16b15a3f60a99443831ee90bf43308f61b60_s390x as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:ae8aaecae41cea28ac9a59468024942b9528de7b150453c99ceb1eb1ed8d921a_amd64 as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:b81b71052c82ae685491fbdaf45c5e5da0ac8a322ae4697ad8ea061cbd8eaf8a_arm64 as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:134bafee4bb7fcf1fbd1242ca7b5a5ce99296eed19b982f2fa0fab69aa596881_arm64 as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:22f133df7b02ce4cc6e8b8dc64d74d79ea7ba9a662811b244701f1e1a01aec0f_s390x as a component of Logging for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:6ce28aaad7cb3b99c4c332e3b465088007498b2414f04fc6e4d64338aeda193a_ppc64le as a component of Logging for Red Hat OpenShift 6.2
  • +5 more not shown

✅ Remediation

For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ocp-4-18-release-notes For Red Hat OpenShift Logging 6.2, see the following instructions to apply this update: https://docs.redhat.com/en/documentation/red_hat_openshift_logging/6.2 Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package.

🔗 References (18)