RHSA-2026:74609HighCVSS 8.8

Red Hat Security Advisory: Cluster Observability Operator 1.5.3

Published
October 1, 2026
Last Modified
October 4, 2026

🔗 CVE IDs covered (21)

📋 Description

CVE-2026-19534 — undici: undici: Denial of Service via unrequested WebSocket subprotocol CVE-2026-39244 — adm-zip: adm-zip: Denial of Service via crafted ZIP file leading to excessive memory allocation CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input CVE-2026-56864 — golang.org/x/mod/sumdb: golang.org/x/mod/sumdb: Integrity bypass via malicious GOSUMDB CVE-2026-56865 — golang.org/x/mod/sumdb/tlog: golang.org/x/mod/sumdb/tlog: Supply chain compromise via transparency log tile verification bypass CVE-2026-59887 — linkify-it: linkify-it: Denial of Service via crafted mailto: links CVE-2026-63199 — github.com/perses/perses: Perses: Cross-scope secret disclosure due to missing authorization in datasource proxy CVE-2026-71556 — github.com/go-git/go-git/v5: go-git: Arbitrary file read/write via symbolic link resolution CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies CVE-2026-84445 — google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests CVE-2026-84961 — undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options CVE-2026-92000 — adm-zip: adm-zip: Denial of Service via crafted ZIP archives with zero declared uncompressed size CVE-2026-100690 — github.com/gohugoio/hugo: Hugo: Arbitrary file read via symbolic link sandbox escape

🎯 Affected products98

  • Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/alertmanager-rhel9@sha256:2aa9c685be4d544cf989fa2ca8118f4d3aa7adf4278c0655148b306d07ff6813_arm64 as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/alertmanager-rhel9@sha256:64e72beecd1e1067521820909c9677641504aad43f33c61ee3d69f8538608fc4_s390x as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/alertmanager-rhel9@sha256:8cfe9dcb648bec4490153db0a3a8d70dcf5fad4d6d8d13936c8311f5581012e6_ppc64le as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/alertmanager-rhel9@sha256:aff98d7f2cef39c2278c3781da250ff8bcf30d82f0b65d4cb52a47ea53caeb4f_amd64 as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/cluster-health-analyzer-rhel9@sha256:2e86c7a5135b2bb135d4bb0c8543f7f5dc4b8badc161ab9de521264f263e6e31_s390x as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/cluster-health-analyzer-rhel9@sha256:786bce056457cb758b2e2d41502f5f3a1a63e6dedb5157b79ad53513d0740895_arm64 as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/cluster-health-analyzer-rhel9@sha256:d8f591fe5df9be62f864e3943f07d9c647b8e10a7d83ffe59a3739b1f0ecdcad_ppc64le as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/cluster-health-analyzer-rhel9@sha256:dbbfddeff933aadd7260d786c33d966f48ea72945f2d34b4d40914bb4fadc954_amd64 as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/cluster-observability-operator-bundle@sha256:c51525732a913cb923ae0ff76180d816edb9fa95094ea6b956a5428339bbdffa_amd64 as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/cluster-observability-rhel9-operator@sha256:6a81c6ba5c6c197e116829cca39bb16e2cfa197a7de78d1fb3faaceca364a058_amd64 as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/cluster-observability-rhel9-operator@sha256:708c767b670cadcbbfbed9a7ef0397e77b531966b836b3486aeba33ff130f710_arm64 as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/cluster-observability-rhel9-operator@sha256:7f35a826e1b15bc26a39a51f8bf5c4fdcbec439d272ea3598d0a298ad03f1d82_ppc64le as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/cluster-observability-rhel9-operator@sha256:871a7f79694559b0908c9744736069b4c741fce1d3faa114199107208ea8bf7f_s390x as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/dashboards-console-plugin-rhel9@sha256:4c2eaf9749637935dc181ff6d94d605df2d407d2cb0c98b42c423da397a1abb4_amd64 as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/dashboards-console-plugin-rhel9@sha256:9339904ffe17f642314001d4bd0c03f37d2386aa18a641bf8795e3774ddecd7a_s390x as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/dashboards-console-plugin-rhel9@sha256:abeccc3d710c2188fbf82d25215b14a7f0a4f844a09dcbdc54cdd4836a72b5d9_ppc64le as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/dashboards-console-plugin-rhel9@sha256:ac7674bd7e0c29ac03bb48e95f0ce31107501749542992479b2dcfa9e6c3a5ee_arm64 as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:4f8298d72b446cf43419ea4c44fb11e77559961e8c544c6e5381b5c9494bfe8c_s390x as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:8e201126c5732fc4b52a7dff62aa6752918365e0d4c17040123a55b5ca361d17_amd64 as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:a4465e2a727fbcb5b097ff433ad5be533879df2196e94c17c8e5be06a19ee3a4_arm64 as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:c51811c8b2725911126b9fbfa27c84e22bedf8949dbe5ff2fe13516b6cf061d7_ppc64le as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf5-rhel9@sha256:015934e8094bbdbf93e7efdd2c64b429d2d56646c5a3ce1e11d4c5a6cffd4c07_s390x as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf5-rhel9@sha256:2e5ca6c5f3ffb09af7e515720b743a9199e59bc0cd9d9cb2393d70db5c9fb46d_ppc64le as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf5-rhel9@sha256:7e75aba089cb03d3e3184a34b372dda8d351ffb14ab073dcca4417b93d96abef_arm64 as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf5-rhel9@sha256:f46f950a2726714dbbac66acbebaa2136aeffa9932b6145279c66d316bc3b833_amd64 as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf6-rhel9@sha256:630d93f0951c828ccc39e39460e4e2fcc39e7dd1b964f27444b436aaf7ce9e5b_amd64 as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf6-rhel9@sha256:795d1b20e846376dd6605224dc8956e3a764344601ae126a287562a70aa9ce47_s390x as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf6-rhel9@sha256:eefb6cceecf47f9ebf981be50d3a13e78f7fb63670b211b9c1e39c7b0e6f7e07_arm64 as a component of Cluster Observability Operator 1.5.3
  • registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf6-rhel9@sha256:f7c23fcc84c59bfda30418a8b20f700e116df9b7367c86a6cdcaffaf59b85516_ppc64le as a component of Cluster Observability Operator 1.5.3
  • +68 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: No mitigation is available for this vulnerability. Update the affected packages to golang.org/x/mod version 0.40.0 or later, or Go toolchain version 1.25.13, 1.26.6, or 1.27.0-rc.3 or later. Workaround: No mitigation is currently available for this vulnerability. Red Hat recommends applying the available security update when it becomes available. Workaround: To reduce the risk of exploitation, do not clone or run worktree operations (checkout, status, add) on Git repositories originating from untrusted or attacker-controllable sources using an affected version of go-git. The issue is resolved by updating to go-git 5.19.2 or 6.0.0-alpha.5 (or later). Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams. Workaround: Applications that do not use BalancedPool, or that use it without a custom function-valued connect/tls option, are not affected and require no action. As a workaround until packages are updated, avoid using BalancedPool for any connection that relies on custom TLS certificate validation (e.g. certificate pinning); use Client, Pool, or Agent instead, which are unaffected. The permanent fix is upgrading undici to 7.29.1 or later (7.x line) or 8.10.2 or later (8.x line). Workaround: To mitigate this issue, implement the following operational controls: 1. Avoid processing untrusted pull requests, themes, or repository branches that execute Node.js transformation pipelines (such as PostCSS, TailwindCSS, or Babel). Builds that do not execute Node.js tools are unaffected. 2. Isolate Hugo builds inside dedicated containers or ephemeral sandboxes that have no sensitive host directories or files mounted, and run the build process with minimal privileges. Caveat: Disabling or avoiding Node.js asset transformations may prevent custom stylesheets or scripts from compiling properly, which can alter the appearance or functionality of the generated site.

🔗 References (26)