Red Hat Security Advisory: Red Hat Lightspeed (formerly Insights) for Runtimes security update
🔗 CVE IDs covered (11)
📋 Description
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-84445 — google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests
🎯 Affected products6
- Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-operator-bundle@sha256:aae0571689746a48abf3b5160d471f9c22487191602776ba48ae1650a7acfe9f_amd64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:14546b6bc79cc8f36ca66e43b4467edd42ace92bca88cd0db416be948100c929_ppc64le as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:a10dc0ef22751c03a28e860b653f792951966822aec437c20c42b74f7f62a35a_amd64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:aa088e05d932581801b590253a02cc9f6e0e9167294928987e2313b949d46152_s390x as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
- registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:d9661dc6c409af70efab4814fdc5b3da9a6f23ad3b47ab99f11c0f4f011a649e_arm64 as a component of Red Hat Lightspeed (formerly Insights) for Runtimes 1.0
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2026:73538
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-41178
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-84445
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_73538.json