RHSA-2026:61314HighCVSS 8.7

Red Hat Security Advisory: Cluster Observability Operator 1.5.2

Published
August 31, 2026
Last Modified
September 5, 2026

🔗 CVE IDs covered (19)

📋 Description

CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-29181 — github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Denial of Service via crafted multi-value baggage headers CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-32285 — github.com/buger/jsonparser: github.com/buger/jsonparser: Denial of Service via malformed JSON input CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters CVE-2026-39830 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses CVE-2026-39831 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check CVE-2026-39832 — golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42508 — golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey CVE-2026-44740 — github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation CVE-2026-46597 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs CVE-2026-46600 — golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing CVE-2026-55677 — github.com/labstack/echo: Echo: Unauthorized Information Disclosure via URL Path Decoding Discrepancy CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-73643 — js-yaml: js-yaml: Denial of Service via exponential parsing in flow collections

🎯 Affected products98

  • Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/alertmanager-rhel9@sha256:51e1cee9ccde0bb3b363f59861a97da546215e0c012af6ef533d5e09387cb6ff_amd64 as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/alertmanager-rhel9@sha256:920567c0312f539ccce04ba94ed7539eb67a7e49fdd5479283be25be99a40780_s390x as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/alertmanager-rhel9@sha256:b051bc5cd14f8c6bfcadbca3659c04afd027fdfd8c963296d0da7fbccf8b15b0_ppc64le as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/alertmanager-rhel9@sha256:c2a60557eb2d933f41dc42c1b5116d3e9b27592e91a5839f142999cc9e5c49ee_arm64 as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/cluster-health-analyzer-rhel9@sha256:5863e3e8fc305410f3611c5d234f58dadade652429f006cc9477494468d7f75b_amd64 as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/cluster-health-analyzer-rhel9@sha256:7e883fb088a584f5a7f33e50366d48c974488671da669c340470ddfee114b791_ppc64le as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/cluster-health-analyzer-rhel9@sha256:a60c396947cbeffba5016820ef23961370195bfedb9d1b47bd4d6da55a840ac2_arm64 as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/cluster-health-analyzer-rhel9@sha256:b06af3129f86113372a7a3f0d0722b84910675a6cd7e30d5c87d4c3b7f163e66_s390x as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/cluster-observability-operator-bundle@sha256:af00e7ae2fbc7056a5ce0de131e55a99ec0860099cb5df067c52ed5234da0b6d_amd64 as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/cluster-observability-rhel9-operator@sha256:1c7533751b55047dd1aa209676359b00dc4cc1471321017d817bb930136e23f4_arm64 as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/cluster-observability-rhel9-operator@sha256:65522a8b12d1f2b188076b97ec5226b2d8cfcc6d2a589f0d9e54962f13a68f56_ppc64le as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/cluster-observability-rhel9-operator@sha256:8fa4520a60aee92e2597cd431b103583421962e6754685fdedc0e96917b4bfde_s390x as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/cluster-observability-rhel9-operator@sha256:f63fa627d028c814dfce0d3ef0b06f5044ff193376c22e2fecc50e05fdfab9f1_amd64 as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/dashboards-console-plugin-rhel9@sha256:7f94288c1b8457f679e63724465adcc98b35e1b37b2391cdf29930a47c3ba366_arm64 as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/dashboards-console-plugin-rhel9@sha256:94faef76b872ec938af52f5403d6c76848b463948b7e6fac5b3904ce0ecb0cab_ppc64le as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/dashboards-console-plugin-rhel9@sha256:e46afc8c13c15d444788b45414a25239b2ac1a7a273a316d8a43165f69022e33_s390x as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/dashboards-console-plugin-rhel9@sha256:e952b3783e077cc43a718bb9aae12577c43130899a6e0de6a64564ea7198405f_amd64 as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:04b2a23166e7edb28d543ca28dc9d1ee5436d2d587f7feb37cc55f39adb18169_amd64 as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:2ab134074d750c76fcea617ac5b286ae2bb14a4a1f5d23d18afae524d60e0576_arm64 as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:41d6a9aee2e7ebd6f5987133f7a1b5c5bb423ebd5a907321ef63d05313c98036_s390x as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:8ba6ed81afcc3647fee542d3697a2ff321f0af7983464a1b0e16bf8ccf5b7c6a_ppc64le as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf5-rhel9@sha256:0c3825a2153cc886a67d93c7034ab8d8cb1ee6dc7ecb6d7626e27644315ffcc9_s390x as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf5-rhel9@sha256:2091f9940bad29d2273bee635d1d4d736c7aca41b504c4a4ceacb2ccd9d3cc8c_ppc64le as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf5-rhel9@sha256:4591e1d37c2307adec5602bf28f30d7b297b2aaf2b89ea48671a25e9635066ce_amd64 as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf5-rhel9@sha256:a9a51e2c9476f02df0fb922b20283baa55c82ca5b30983fe31c4fdcb07ef1b9e_arm64 as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf6-rhel9@sha256:1cf801a07119fd084d79a9c26b84dbd07ada25cb219423bc121a2c870e0dab0b_arm64 as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf6-rhel9@sha256:ceeabd18a61070a03ab9466f156734d273ddc9433b6b1a0afd40f22f78545df1_ppc64le as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf6-rhel9@sha256:f5fb9e4438247a775d2bb59856cb35fab46e752f32720eb55468bee896168f84_s390x as a component of Cluster Observability Operator 1.5.0
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf6-rhel9@sha256:ff10f227a1b0930cf1a3c7c204ac44db04ab476acebc0b12159546dbe81f4ce6_amd64 as a component of Cluster Observability Operator 1.5.0
  • +68 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this denial of service vulnerability, restrict network access to any service that utilizes the `golang.org/x/crypto/ssh` library and is exposed to untrusted networks. Implement firewall rules to allow connections only from trusted hosts or networks. This action limits the ability of malicious peers to send unsolicited global request responses. A restart of the affected service may be necessary for the new network rules to be applied effectively. Workaround: To mitigate the issue, we suggest upgrading to versions 5.9.0+ or 6.0.0-alpha.1+ Workaround: To mitigate this issue, restrict applications from processing untrusted YAML input with affected versions of the `js-yaml` library. Implement strict input validation to ensure that only trusted and well-formed YAML data is processed. If the application is exposed to external, untrusted sources, consider isolating the application or implementing additional resource limits to prevent complete service disruption.

🔗 References (24)