Red Hat Security Advisory: Red Hat build of Cryostat security update
🔗 CVE IDs covered (36)
📋 Description
CVE-2026-6734 — undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing
CVE-2026-6860 — eclipse-vertx/vert.x: eclipse-vertx/vert.x: Denial of Service via TLS handshake with wildcard server name
CVE-2026-9697 — undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy
CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection
CVE-2026-12151 — undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames
CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity
CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
CVE-2026-39828 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions
CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses
CVE-2026-39835 — golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header
CVE-2026-44249 — netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
CVE-2026-44290 — protobufjs: protobufjs: Denial of Service via crafted schema
CVE-2026-44291 — protobufjs: protobufjs: Arbitrary Code Execution via prototype pollution
CVE-2026-44292 — protobufjs: protobufjs: Data integrity impact due to prototype pollution
CVE-2026-44893 — netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message
CVE-2026-45416 — netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
CVE-2026-45674 — netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation
CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray
CVE-2026-45740 — protobufjs: protobufjs: Denial of Service via crafted JSON descriptors
CVE-2026-46384 — github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: Integer Overflow in Avro Decoder
CVE-2026-46385 — github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: CPU Exhaustion in Avro Decoder via Unbounded Block-Count Iteration
CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
CVE-2026-46599 — golang.org/x/image/tiff: golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data
CVE-2026-46625 — js-cookie: JavaScript Cookie: Cookie attribute manipulation via prototype pollution
CVE-2026-47691 — io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records
CVE-2026-48043 — netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
CVE-2026-48059 — netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers
CVE-2026-48779 — ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments
CVE-2026-50010 — netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
CVE-2026-50559 — io.quarkus/quarkus-vertx-http: Quarkus: Authorization bypass in HTTP path-based policies via encoded characters
CVE-2026-54512 — jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
CVE-2026-54513 — jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
🎯 Affected products21
- Cryostat 4 on RHEL 9
- cryostat/cryostat-agent-init-rhel9@sha256:56a21c05b7e6face6abbb05a1165d02640779cda3dc829e21237840e7cbac579_amd64 as a component of Cryostat 4 on RHEL 9
- cryostat/cryostat-agent-init-rhel9@sha256:a9a7a4aff8961cea3f5a4cd5b3370c5f13105e9461f4fb0de70bcfa7b5facab1_arm64 as a component of Cryostat 4 on RHEL 9
- cryostat/cryostat-db-rhel9@sha256:1dadbcd03e36720ff1bccd2fa77cdb7096e94322794f5ad3b8a511d08c0c30d3_amd64 as a component of Cryostat 4 on RHEL 9
- cryostat/cryostat-db-rhel9@sha256:c1d344fddcfb7ff4ca4bc3a2ba88917c918879b8411aef0dc1c252e151e7df5f_arm64 as a component of Cryostat 4 on RHEL 9
- cryostat/cryostat-grafana-dashboard-rhel9@sha256:681a38cf4bd5f892dd76e634d754106d55c1dc78ed1a59c6003fd75d8e285101_arm64 as a component of Cryostat 4 on RHEL 9
- cryostat/cryostat-grafana-dashboard-rhel9@sha256:ea227ce33a7d948d284c10f3f590ddfdc5058459a52b87c46ce882ac32a82a0f_amd64 as a component of Cryostat 4 on RHEL 9
- cryostat/cryostat-openshift-console-plugin-rhel9@sha256:c8915feceaaf08a0f3a05df8a61f44b8cfca2b23872219828a694cee047252a1_amd64 as a component of Cryostat 4 on RHEL 9
- cryostat/cryostat-openshift-console-plugin-rhel9@sha256:f226753fa98b6492d7fffc0d669d1e003f5146c6214d3cbad96d0e3fd8f03663_arm64 as a component of Cryostat 4 on RHEL 9
- cryostat/cryostat-operator-bundle@sha256:8aba4092e4ca595ee8df8f878754f698059c72d956022a1fe9e123d6ed7a7fa6_amd64 as a component of Cryostat 4 on RHEL 9
- cryostat/cryostat-operator-bundle@sha256:f6f18f4a84f0a0381e5d03893d2968050537f7e20b08b61b54e922c4d9359292_arm64 as a component of Cryostat 4 on RHEL 9
- cryostat/cryostat-reports-rhel9@sha256:a93361b346844f7ec4108a9658cb5fdd61c8963e90ee15e52fb213b1bb4d01c6_arm64 as a component of Cryostat 4 on RHEL 9
- cryostat/cryostat-reports-rhel9@sha256:b34a578607642a41719d12a902df7b4549606f37e773f6b20ed047b94c1739fe_amd64 as a component of Cryostat 4 on RHEL 9
- cryostat/cryostat-rhel9-operator@sha256:98849e3734fbdeb2252a6d4863f999ebba93155c5c650e42711c76c82b6c6b45_amd64 as a component of Cryostat 4 on RHEL 9
- cryostat/cryostat-rhel9-operator@sha256:bd3419415c6e31e2c5269b371d8097e69cad1ff84cea5b98b4892ffad05a501f_arm64 as a component of Cryostat 4 on RHEL 9
- cryostat/cryostat-rhel9@sha256:c0b028b465d8e6f3b262659195c01deee13538c1e34a823bffb7624bbb5252fc_amd64 as a component of Cryostat 4 on RHEL 9
- cryostat/cryostat-rhel9@sha256:cb6b42fb943940abf1e5c7c9f6050a7f950066497c89dd1306051697d7d207a6_arm64 as a component of Cryostat 4 on RHEL 9
- cryostat/cryostat-storage-rhel9@sha256:51b54fe0f6d011cd59eaa810f62d4d8b8dde5c0ebd75684cbc2eac104466c467_amd64 as a component of Cryostat 4 on RHEL 9
- cryostat/cryostat-storage-rhel9@sha256:a6ab21c3097a8268cba87c6eeb1f512454da0c68410031c4160c7d7378920850_arm64 as a component of Cryostat 4 on RHEL 9
- cryostat/jfr-datasource-rhel9@sha256:2d9c9f1cd1ff98721ea2ee56e86319bc6bc403f9b444e0fbe802ecb89b589134_amd64 as a component of Cryostat 4 on RHEL 9
- cryostat/jfr-datasource-rhel9@sha256:89b841456cfe46bf4d3b6bd32dea131c51241d2b1bd266d408eac78ed79c395a_arm64 as a component of Cryostat 4 on RHEL 9
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The single most impactful mitigation is applying network egress controls to restrict which external destinations affected applications can reach. Because the vulnerability causes requests to be misrouted to wrong origins, limiting the set of reachable origins directly reduces the attack surface. These controls collectively limit the blast radius of the connection pool misrouting — the attacker must compromise one of the explicitly allowed destinations rather than any arbitrary origin — but they do not fix the underlying logic bug. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: To mitigate this issue, Red Hat recommends configuring applications to avoid parsing or loading protobuf schemas or JSON descriptors from untrusted sources. If processing untrusted schemas is unavoidable, implement strict validation to reject option names containing unsafe property path components before loading them. Additionally, consider running schema processing in an isolated environment to limit the blast radius of potential corruption. Workaround: Mitigation involves preventing prototype pollution within applications that utilize protobufjs. Administrators should ensure that untrusted input cannot pollute `Object.prototype` in the application or its dependencies. Additionally, isolating schema and message processing from untrusted application states can prevent attacker-controlled properties from being resolved as valid protobuf type information. Workaround: To mitigate this issue, applications should avoid directly passing attacker-controlled plain objects to protobufjs message constructors. If processing untrusted JSON input, it is crucial to validate or sanitize object keys and explicitly reject any `__proto__` properties before constructing protobuf messages. This operational control prevents the manipulation of message instance prototypes. Workaround: To mitigate this issue, configure applications utilizing Netty's `SslClientHelloHandler` to specify a non-zero value for the `maxClientHelloLength` parameter. This will enable the internal length validation, preventing the eager allocation of large memory buffers when processing crafted TLS ClientHello messages. Refer to your specific application's documentation for details on configuring Netty's TLS handler. A restart of the affected application or service is required for the configuration changes to take effect. Workaround: To mitigate this issue, avoid loading untrusted protobuf JSON descriptors in applications utilizing protobufjs. If untrusted descriptors must be processed, implement validation at an outer boundary to reject excessively nested structures. Alternatively, isolate the descriptor loading process in an environment that can be safely restarted in case of a denial of service. Workaround: Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available. Workaround: Upgrade to a fixed golang.org/x/crypto/ssh release via updated golang or package rebuilds. Ensure SSH servers use supported public-key callback configurations with source-address validation as intended. Workaround: Update affected Go applications to use golang.org/x/image version 0.41.0 or later, which limits the amount of compressed data the decoder will process. As a workaround, restrict accepted image formats at the application edge and reject TIFF input where it is not a required format. Applications that do not decode untrusted TIFF images are not affected. Workaround: Upgrade to version 2.18.8, 2.21.4, or 3.1.4 or later to address this vulnerability. If upgrading is not immediately possible, remove BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() from the application’s ObjectMapper configuration to eliminate the affected deserialization path. Rebuild and restart the application to apply the configuration change. As an additional mitigation, disable polymorphic deserialization of untrusted data where possible by avoiding or removing default typing features such as activateDefaultTyping() or enableDefaultTyping(). When polymorphic deserialization is required, restrict allowed subtypes using a strict whitelist of trusted application packages and avoid broad or permissive type validation rules.
🔗 References (39)
- selfhttps://access.redhat.com/errata/RHSA-2026:48151
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2466990
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2467822
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477081
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477088
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477100
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477111
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2477914
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480680
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480681
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480684
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480687
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480689
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480757
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2480761
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2483473
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2483475
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2483482
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2484204
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2486959
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2487740
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488081
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488383
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488391
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488400
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488429
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488437
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488439
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488442
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2488480
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489661
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2489980
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2490018
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2490024
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492010
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2492015
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2494813
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_48151.json