RHSA-2026:50843HighCVSS 9.1

Red Hat Security Advisory: Logging for Red Hat OpenShift - 6.0.16

Published
August 5, 2026
Last Modified
August 20, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header

🎯 Affected products35

  • Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/cluster-logging-operator-bundle@sha256:c3dbf8252b7abd2ddb5ce367bef6de204d6eadd3590d56f1931453ff727aa1ff_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:0a3cbe776357421fe89b45e9f5da54259fb91825925660e9efd2e2058b82672e_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:4a4be2066a79e4d4779d174e8843f43de6d8e643d8136b7e7d78d12c27788fbe_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:6bf40033c56ff4b18d70a84b86097d5edf3c640567a332768e229a52c16ab25a_s390x as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:92047276401431f998d391f0366d33d90a4029a6c73ed89f7f1d916f99ac26e0_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:369ddc0d5aa123640e8a719e8e585af2cc8b1056f36a7d7f6c9362a774a26081_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:3b3c5451e18fe1ed223ca20bec6a2af114ef47f82891de3758c11b24abc00bee_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:6202d1c557103a08a7ab222049ce45da93c6178c0fdbd778aa4b409877f5c7e5_s390x as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:bef988925bd6f52d407fa498baabafadab6dcfbbb4986fc80ffaf7c05cda264b_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:6c13d56ccaea21e2b92777800c74835899ed22b1ae9090a98a9b449ee8b582ed_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:8ec20dee97b97f503e3893bea2e0f791cde84713c1d4a137ee0b44eab1e7c17b_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:b4dbce1521cbbf4fc466820a51422e8b05aba5b35d700bacfa2766f53ff30ba8_s390x as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:b5103b88ec32ec7be0b17de57add891f64a7629e7475e4e77db6079b30c9b877_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:02d7bfd18770557675eba97e03a460a57513a258fbac418fe8fc8ca11efd395d_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:3cc618c7311d7770113f7fdc461bfcf95ffe5bc9c4fca4e972cc954cb9d23fb9_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:4e6a7d903b99e3642158eb12058b5bff69bacaccb18e809bfe3d623d997bef7e_s390x as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:5c9f1b213c785c7dcba7a4553c7cfac258d16df281c023b7d8fa357592ee0117_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/loki-operator-bundle@sha256:53b8c48918c6801dc54b5503c88514263e904b493799a5721d5a9a4bb0236fd9_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:1a930ff4b2a73ac06a7fd42f83eabd937cf11357e7ff9d6d2ae7a6dfe8561f71_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:81ff53215a86347b5b0455ff7348d9cdebd832ab18b862038a04f7788abbbfc6_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:d45818a542571917247e98749c920f6bd7e349f5169d913b6fe5c21dcb15a82e_s390x as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:d59351cdcac44e2709d56ba5e8ef64dd58343594599e8680bf3f9a569f9f5de7_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:1b1badc0f7eed34ec9470f363de2d937d474c320faa7716fa92ec354a91cb062_s390x as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:220506ea930bc8f1b609c9ef58d754dcc81a99ee056e6ae60ee1e3b92e63e15c_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:a2fa2922cd00d4117b3f7fac7850685ab8dc2c37bac71f127928c96b64379b41_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:d2fbdc365db49efb8f12d3232c21c54ea54986c9f2c96f2f7ce7f821f5f71889_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:74bed7bb202e555583267183d21cb3bd7c6a3f5f2ae6c99732ccd48bac691cdc_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:a55144687551d73c998535a2ea5676c42bcf5325a0ebaeb4f6be0074b2875c4f_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6
  • registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:a553bd05359427feb841f8e5376de97303b378644616a0dba6cbd8290f23d678_s390x as a component of Logging Subsystem for Red Hat OpenShift 6
  • +5 more not shown

✅ Remediation

For OpenShift Container Platform 4.16 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ocp-4-16-release-notes For Red Hat OpenShift Logging 6.0, see the following instructions to apply this update: https://docs.redhat.com/en/documentation/red_hat_openshift_logging/6.0 Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package.

🔗 References (13)