RHSA-2026:69268HighCVSS 8.2

Red Hat Security Advisory: Red Hat build of OpenTelemetry 3.11.1 release

Published
September 21, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-46600 — golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56854 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages

🎯 Affected products14

  • Red Hat OpenShift distributed tracing 3.11.1
  • registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:254471deeb953cd1a2a8f5e7158c83a258a8c14bd063a271ffd4fb5210834e06_s390x as a component of Red Hat OpenShift distributed tracing 3.11.1
  • registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:309951d5cbd4a822318cf1fc9bd617556979de6b6bc174bd54bee43643b2f3ca_ppc64le as a component of Red Hat OpenShift distributed tracing 3.11.1
  • registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:6af9dccca6871acb3df4a3215e8d047eaa540f105557b2e4a87fca12f8f92103_arm64 as a component of Red Hat OpenShift distributed tracing 3.11.1
  • registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:dca33a0fc93d13dd74e924f7a1a1bd2ddc306736da7df1dcab2fb68858b75907_amd64 as a component of Red Hat OpenShift distributed tracing 3.11.1
  • registry.redhat.io/rhosdt/opentelemetry-operator-bundle@sha256:54ca62373801819c839407a62df4edce4f06586e286201bcc5067361c0466d2a_amd64 as a component of Red Hat OpenShift distributed tracing 3.11.1
  • registry.redhat.io/rhosdt/opentelemetry-rhel9-operator@sha256:26f19f2299d67a2c83aba1203ea451d448a4645e3072555411a5a120121168cf_ppc64le as a component of Red Hat OpenShift distributed tracing 3.11.1
  • registry.redhat.io/rhosdt/opentelemetry-rhel9-operator@sha256:5bb295c64b5d839b051ec7ff9e5f30559a0f4fe09c08e82b0541fb49a7008ecd_amd64 as a component of Red Hat OpenShift distributed tracing 3.11.1
  • registry.redhat.io/rhosdt/opentelemetry-rhel9-operator@sha256:905f971e7be37156dc36af51f5959d0d279423243e72d8ee38e1089132abbf04_s390x as a component of Red Hat OpenShift distributed tracing 3.11.1
  • registry.redhat.io/rhosdt/opentelemetry-rhel9-operator@sha256:bc0934f046e9ab4207ab1cc47d332c03e46d85352d6a2f5b8740396918df3edf_arm64 as a component of Red Hat OpenShift distributed tracing 3.11.1
  • registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel9@sha256:700c222c48682fab41370240cd33f9bc697816812acbb8966d7c236a634aee0a_arm64 as a component of Red Hat OpenShift distributed tracing 3.11.1
  • registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel9@sha256:972b79e64cf9e07c1afb7476727648b20ebd1eef6f6adb3fdd0dec20565430ad_amd64 as a component of Red Hat OpenShift distributed tracing 3.11.1
  • registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel9@sha256:c342c632f4c415a324014a04eeb8b80b580b3376fc6219a11836ca48f15f90fe_s390x as a component of Red Hat OpenShift distributed tracing 3.11.1
  • registry.redhat.io/rhosdt/opentelemetry-target-allocator-rhel9@sha256:f461acb3c226467295bd71bd528c3cd30f8889c1445eac31e434cb71fca1148f_ppc64le as a component of Red Hat OpenShift distributed tracing 3.11.1

✅ Remediation

For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/operators/administrator-tasks#olm-upgrading-operators Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (13)