RHSA-2026:68349HighCVSS 8.1

Red Hat Security Advisory: Logging for Red Hat OpenShift - 6.2.13

Published
September 16, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2026-15792 — github.com/moby/buildkit: BuildKit: Denial of Service via malicious client request CVE-2026-18140 — aws-smithy-json: aws-smithy-json: Denial of Service via uncontrolled recursion with deeply nested JSON CVE-2026-29181 — github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Denial of Service via crafted multi-value baggage headers CVE-2026-32283 — crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-35469 — Kubelet: CRI-O: kube-apiserver: Kubelet, CRI-O, kube-apiserver: Denial of Service via SPDY streaming code CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42502 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages

🎯 Affected products35

  • Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/cluster-logging-operator-bundle@sha256:b615929af35407d22bd2a8086e34a453231a13f53dda1d8431205b6706de1806_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:5790b96e2de8694ca3054313adf751916153fd5033d89c044730192393994368_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:8320d9de314347663fe90dd44aa772a966587d0b79dc89b5073183229e511ac2_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:9ff71e687f732a6fbf78729c35185db7e7b046c44d70a279d90539a5af9c1788_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:b261790cddf3c68ac11003d7e1396746552dce36ce88bddd0471cd1002238644_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:818c336dda928828f9f9a88aa96367cf7b6831e07baf5d6b3b966616788e9211_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:992fa8271d37bba6c7219084c4b7733cabe378767ab2f09626b8aba0d121022c_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:a0c1798159c5314af281d5732dff9fac3861f9a60d28518e1cfd9131a86bf028_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/eventrouter-rhel9@sha256:ca8e97d40c8fad6c8534b92250998f9e08cc4e9054969b64d53369837dd00fd9_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:428815869664eb625aa9113d8c904ab96786ba4df794941a4356d911908bfc34_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:57624f49f0a378d552dfe56402a5021de9633c83ab226a6c2bb5ef30d7ed4a2b_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:a87d13b4f0b4dc5bab2bf1100c48f923c04896098dc2bbb7d7b0b090c106b178_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/log-file-metric-exporter-rhel9@sha256:e9ff11de6c0bc207f6c1115cb325e8f9d982debc263266bf0c80b8cc3a608e03_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:254a4f931c66afe106b27bcf75eaf797d406d09b1477566499678bca703c45b7_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:8ccaa85ed8f1bf537c9338c1020d5ef1b2dcc1d395421c20264a0012d81b9e87_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:e64d9edc8e2d6a9fff2e47e9ceebc41dce72cae3e7c6256caeabec031a0c0735_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/logging-loki-rhel9@sha256:f9d93a0e94bb6dc05406f20d353b8c30a70f53cc43001789b3e08fde89e59447_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/loki-operator-bundle@sha256:c20d23c2a0217c9979e284696f725fa30dfea1b0af680334ad8d32305a79c619_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:07ebcf92360d02f470195b5efef42ff6c575397836e4738821a163ff5fe29686_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:67e408acce9dcc52c783e102967f552f3b6a28c58e45555e081171be4d13d5a4_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:847aaa1a157adbf06a3ab21b1017b7db2082e5f4d096afc9ec4ce802716d2b74_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:d69d304c26f30ca7082ff278998b4c11f86ffaee625bd51cfd5c7cc02fdc8ff2_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:2f45d4abe59cad318e2ae06d0181d7d69f77e8080de41a14a64bc08c4a5fdd0e_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:32461752db18080dda5f913a8bf5a8710ca0ec5299e6a9bb9706172b3edbeacb_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:a128f76e2fbe05da58d78922b442c763c86d0a739d5b5447100ec5a8d149cb70_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/lokistack-gateway-rhel9@sha256:b9f1a6c60cc04bb52e1e7c9406a5d87ecc0987ed4a5e5afea530bd2a029ac12c_arm64 as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:319a989701e651dbacee67b5fb739ab819c0c244770f8df73c86a289187643d4_ppc64le as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:480a5bd00533b4200a763ffe7c04ecf5dfaccc82fd9b273bdee7bb7cfadec0e6_s390x as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • registry.redhat.io/openshift-logging/opa-openshift-rhel9@sha256:a9cb230ed3bf10523d4cac75977d1384471658810ad1da3fc31d6ae8c6a5bb4e_amd64 as a component of Logging Subsystem for Red Hat OpenShift 6.2
  • +5 more not shown

✅ Remediation

For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ocp-4-18-release-notes For Red Hat OpenShift Logging 6.2, see the following instructions to apply this update: https://docs.redhat.com/en/documentation/red_hat_openshift_logging/6.2 Workaround: Avoid building container images using BuildKit frontends from untrusted sources. A BuildKit frontend is typically specified using a "# syntax" directive at the top of a Dockerfile, or with the "--frontend" option to the "buildctl build" command. Only use frontend images that come from a trusted source. Workaround: Restrict network access to services that process JSON input using the `aws-smithy-json` runtime. Configure firewalls to limit incoming connections to trusted sources, thereby reducing the exposure to remote unauthenticated denial of service attacks. If the service is reloaded or restarted, ensure firewall rules persist. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, review and restrict the assignment of Kubernetes cluster roles `pods/portforward (create)`, `pods/exec (create)`, `pods/attach (create)`, and `nodes/proxy (get/create)` to untrusted users or service accounts. Ensure that only authorized and necessary entities possess these permissions. Modifying RBAC policies can impact the functionality of applications and services that rely on these permissions; careful testing is recommended. Workaround: Applications utilizing `golang.org/x/net/html` should implement robust sanitization of all untrusted HTML input before rendering to prevent the creation of unexpected HTML structures that could facilitate XSS attacks. If an application does not require rendering arbitrary HTML, it should avoid processing such input.

🔗 References (17)