Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (6)
📋 Description
CVE-2026-8595 — grafana: Grafana: Stored Cross-Site Scripting via malicious dashboard field name CVE-2026-8609 — grafana: Grafana: Denial of Service via unbounded memory growth in OAuth login route CVE-2026-9765 — grafana: Grafana: Privilege escalation via broken access control CVE-2026-21723 — grafana: Grafana: Denial of Service via uncontrolled memory usage in alertmanager templates CVE-2026-33382 — grafana: Grafana: Denial of Service via excessive memory allocation from large API request payloads CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing
🎯 Affected products4
- Red Hat Hardened Images
- grafana13-1-main@aarch64 as a component of Red Hat Hardened Images
- grafana13-1-main@src as a component of Red Hat Hardened Images
- grafana13-1-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate this issue, restrict network access to the Grafana instance to trusted internal networks or localhost. If a reverse proxy or load balancer is deployed in front of Grafana, configure it to implement rate limiting on requests to the OAuth login endpoint to prevent an attacker from exhausting system resources. If OAuth is not required, consider disabling it in the Grafana configuration, though this may impact user authentication workflows. Workaround: If not required, disable anonymous access to prevent unauthenticated exploitation of the Alertmanager templates test endpoint. Refer to Grafana’s official documentation for configuration details. To protect against low-privileged authenticated users triggering this flaw, configure a reverse proxy or WAF to block or strictly rate-limit traffic to /api/alertmanager/grafana/config/api/v1/templates/test. Workaround: Deploy a reverse proxy or API gateway (e.g., Nginx) in front of Grafana configured to strictly limit the maximum HTTP request body size, dropping oversized payloads before they reach the backend. As a defense-in-depth measure, restrict network access to trusted internal clients via firewall rules. Note: Applying these proxy and network changes may require a service reload, causing a temporary interruption.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:63165
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-84375
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-17033
- externalhttps://access.redhat.com/security/cve/CVE-2026-19197
- externalhttps://access.redhat.com/security/cve/CVE-2026-21723
- externalhttps://access.redhat.com/security/cve/CVE-2026-9765
- externalhttps://access.redhat.com/security/cve/CVE-2026-8595
- externalhttps://access.redhat.com/security/cve/CVE-2026-33382
- externalhttps://access.redhat.com/security/cve/CVE-2026-8609
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_63165.json