Red Hat Security Advisory: Logging for Red Hat OpenShift - 6.5.2
🔗 CVE IDs covered (14)
📋 Description
CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-32282 — golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-33813 — golang.org/x/image: golang: golang.org/x/image: Denial of Service via malformed WEBP image parsing CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-42151 — github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API CVE-2026-42154 — github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input
🎯 Affected products35
- Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/cluster-logging-operator-bundle@sha256:40c83c7127b6b90b9984b3c73b3cbad1c3a8f7af3dc792e5320d6defb9eb22e0_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:5b4e3a421f13bd33d03185f4071b3e633767eb06a9875a02ca793d43fd1514c7_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:93e605c4231903b7a73e7578f8977a5c6029c767ab801f29b726d2e6ff290feb_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:d9bc0d110bbc7b7ec8a2401f34cde12e470980086bb04fc532a9885917c06b7f_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:ee6505e36b31ecc38b080c2e56b7b26afd3c7db9b30d17947e6bcb6cf7f0e44e_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:01271821684bdb4791a1e757092e3799247ac91519f8516599c7cf9080407076_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:958178be4fc3798cdd531660e14514c370ac334b8a27a31a8f08db3244f17341_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:b881afc31c6e287608699dfc9d38bf38ff3616b2b133cc4726f0060ce99b16de_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:c237813ec28c79232f1f8d5bb2f875157323d10ddceddf3f722cd885c3c5c4d5_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:15b1be865c1d4df2fd1171acb46922ba864555b18dfc71febd372e11a5d0eb8e_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:55c2e8cbb4c7e89ed719c136d401c1fa49198e4a98a2dfe78c5eacb5ee2cadc8_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:8d334ebdf403e2a15a664c1960044c6852f3e00b55ce2f2e808f6213ae70e00f_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:ceb52082d9002ba1762e6653bc39b4253f05a7cd58a42c664c7a658e6133a7e8_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:17a67ac2934041f996b19574bbeffa9e56d8486969785ae219215384cfd4162f_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:18ea59f76a1ddd747712fbb3314f55cfdefb4e12a39ad9f0d22c26d25e8b04b4_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:1c687dff9904d440a9efefc95bd82ac1cf10df5c030ee8a3164621bc84e447fc_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:fad58cb6ca31afd96f8ef741cad73c4328c24361dfad022848c227f129c5b4b5_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/loki-operator-bundle@sha256:21c630e1de77a6e18b0b774ebfc5ccef2191fef60da0c7914d0a81d5be236ea3_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:51538cb4de3a2767509d5a7869f9a63a054416e7163c38714bce9bd83da1b619_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:902fe34ead11574878df61323db6ac53f3ad55d13d40f72b8d514ea0356e1a81_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:bff77adab78f874b962324a9674157383dfe4570309d24c7b2a6acebead62a39_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:e2a0befa5c4dbcb56ef33f46ccdb27d5e02f8f5facdbf2fa0b9c6e6dd53a476e_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:9ffa7e5a2ed3f92a6eb30792dc878add38b41f7ce5ca03a6f1a2c8b12300070a_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:a6a946b8e424db855be70e94c1cab3e5dcf56be8b5caec8d48b3b4579310a25a_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:de70e3309c799110feacba1b6d64bf153818e21790500da6ea75c05f276bedcd_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:f49b88b70726cb222fa43685d3a6704ccd8778a2a82b7c5c4aee4b47c54d3bcb_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:11caeb0f6c63f361d12e2c223aa0e1e363c79d8495a008f5b996184dfdd15d57_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:66b2f52b2abd9e3a1fcd1ef4aa926a0f8613730918a2b7743ce61d1ce9b103c7_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:deefcb8674d1899581331ba7899baedb7f9c5355b2b3e4f11b5414b1ae58a8be_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.5
- +5 more not shown
✅ Remediation
For OpenShift Container Platform 4.21 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html/release_notes/ocp-4-21-release-notes For Red Hat OpenShift Logging 6.5, see the following instructions to apply this update: https://docs.redhat.com/en/documentation/red_hat_openshift_logging/6.5 Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: To mitigate this issue, restrict network access to the Prometheus remote read endpoint (/api/v1/read). Configure firewall rules or network policies to permit connections only from trusted internal networks or authorized clients. This action reduces the attack surface by limiting exposure to unauthenticated remote attackers. A service restart or reload may be required for the changes to take effect. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2026:56340
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-32281
- externalhttps://access.redhat.com/security/cve/CVE-2026-32282
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-33813
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-42151
- externalhttps://access.redhat.com/security/cve/CVE-2026-42154
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-42502
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_56340.json