Red Hat Security Advisory: Network Observability 1.12.3 for OpenShift
🔗 CVE IDs covered (16)
📋 Description
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-65819 — github.com/gopacket/gopacket: gopacket: Remote Denial of Service via crafted packet processing CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies CVE-2026-84445 — google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests
🎯 Affected products30
- Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-cli-rhel9@sha256:2fda4c6642fd343cf7bd0fe629e4d85ae95c5180b8f544c464980a7c7dde9e58_s390x as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-cli-rhel9@sha256:97a0788b5ac604ca74362198517f87499da2ec26dd449cf5fb7d6eddf28de9f6_amd64 as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-cli-rhel9@sha256:ada851d78ec38f12688e6a64166767ddd1c960f6099604e0abf06d18ad74519a_ppc64le as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-cli-rhel9@sha256:b307464aa7f189abb67b951542d74b1f89940412fd4d08ab89a9aac25de4fb38_arm64 as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-console-plugin-pf4-rhel9@sha256:474cf8c7500c50dfd569180570f00d9649691a8621ce34f82957e53d2ad95a66_s390x as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-console-plugin-pf4-rhel9@sha256:667964ca0a8379a75425a90e7f1a3c109804e91b6fbc38aa9ecc72d57949925b_ppc64le as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-console-plugin-pf4-rhel9@sha256:9d1fac43e376171a8666d299e4d06f50e102695266e5a8bf424886dcb7e305eb_amd64 as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-console-plugin-pf4-rhel9@sha256:ae786598501725df58ae66ce52607fb8f0c325456537cf41e55cae33ccd4e370_arm64 as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-console-plugin-pf5-rhel9@sha256:0d78ff17f71f5f742aae872a9a15c48a5bf0baa328b85d627ae177bf2c88e3da_arm64 as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-console-plugin-pf5-rhel9@sha256:1a51f636af388a11694876bcea3acb73885479b1b7e02417b4c13c8fde93ab2a_ppc64le as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-console-plugin-pf5-rhel9@sha256:7aa9a1a8a24b2861178d0f64ae4593cc1668562f9844f405e05cf47e94229a09_s390x as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-console-plugin-pf5-rhel9@sha256:e9e0770bdb543dd42aa3c3aa5014cbf19d913da8f58e4d69eb58132421137ac6_amd64 as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-console-plugin-rhel9@sha256:5540377f87365b5501ec4bac45334b0fc1658635c3347505fa52fe11e6f9098f_ppc64le as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-console-plugin-rhel9@sha256:b2c2987a6048c3e65be46209059f78067a7d0ebdf8d4481c607a8f322696e903_arm64 as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-console-plugin-rhel9@sha256:e3ab5b8e9d1b5306ee3e8bb46d54b5b7579653117db71f6f80bf4a7f0abbc62f_s390x as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-console-plugin-rhel9@sha256:fb8fba794fda8541fdaa0f2fcfa6467068abbaa0b4d6d497bc46837bf38a750a_amd64 as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-ebpf-agent-rhel9@sha256:068743012df5f7f0ce25e785630555ce532d50ec32a17a66e51108a5096ae38a_ppc64le as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-ebpf-agent-rhel9@sha256:0f2106026942ca06110301ece4f911b7ea0c50461cde3a5c8710e529c7f7c4c6_arm64 as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-ebpf-agent-rhel9@sha256:dae49f4e857b84f9bad0c3a477c43834cbea6118a719c793b00524ab19b7dc0a_s390x as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-ebpf-agent-rhel9@sha256:eb5f0c7e8418bde2c4a059b8f7600f478cfbd3ff46f8f8fc407b50e8dc88691b_amd64 as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-flowlogs-pipeline-rhel9@sha256:0550d8ac592cf476506a992d0d3f7beb4e6aa4414f259cda47a80e4749311537_arm64 as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-flowlogs-pipeline-rhel9@sha256:b19bfad20ee4fb3de2075251b3eb2c1ea6a76b68edac2c3bbd4523c0aa0346a8_amd64 as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-flowlogs-pipeline-rhel9@sha256:e8e427cc5103d412b4677c3aa93912cb82a5b5db8be8d21992f4341bf404f75b_s390x as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-flowlogs-pipeline-rhel9@sha256:ebe846db7b0733c85850182d709103faf3725b27b2daa3b9d08b23212dbd5cca_ppc64le as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-operator-bundle@sha256:f838339b4bd024f76fead96f23892c7800ffdfb243538369bed23c4f64eef8e3_amd64 as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-rhel9-operator@sha256:065492e0defff65abc0c2fb776b19506e65ff65924e39eaa4e2488e884376dea_arm64 as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-rhel9-operator@sha256:0d0a2e283bcfc021884410130d3dba6b7b4edfc28223cf7a2e203c2b6b3e6a9b_amd64 as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-rhel9-operator@sha256:42309d715ad9d81fd87b5e20d0ae8f41c4ec1f05f71e3b55b610ac6533d75253_ppc64le as a component of Network Observability (NETOBSERV) 1.12.3
- registry.redhat.io/network-observability/network-observability-rhel9-operator@sha256:4e81294ae472aa938a644e4672b264f5a71e3935e83322c238c960cf8d440005_s390x as a component of Network Observability (NETOBSERV) 1.12.3
✅ Remediation
For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: - Upgrade gopacket to a version containing commit 210f25f or later. - If upgrading is not immediately possible, restrict network access to services that process untrusted packet data using gopacket. Where possible, use the recovering `gopacket.NewPacket(..., gopacket.Default)` code path instead of `DecodingLayerParser` or direct `DecodeFromBytes` calls, accepting the performance trade-off. Ensure that packet capture interfaces are not exposed to untrusted network segments. Workaround: To mitigate this issue, ensure application code validates the size parameter passed to customAlphabet or customRandom, rejecting or sanitizing zero-value inputs before passing them to nanoid. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams.
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2026:70593
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-56852
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-65819
- externalhttps://access.redhat.com/security/cve/CVE-2026-67213
- externalhttps://access.redhat.com/security/cve/CVE-2026-75899
- externalhttps://access.redhat.com/security/cve/CVE-2026-75931
- externalhttps://access.redhat.com/security/cve/CVE-2026-75975
- externalhttps://access.redhat.com/security/cve/CVE-2026-76172
- externalhttps://access.redhat.com/security/cve/CVE-2026-84292
- externalhttps://access.redhat.com/security/cve/CVE-2026-84375
- externalhttps://access.redhat.com/security/cve/CVE-2026-84394
- externalhttps://access.redhat.com/security/cve/CVE-2026-84445
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.openshift.com/container-platform/latest/observability/network_observability/network-observability-operator-release-notes.html
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_70593.json