RHSA-2026:77532HighCVSS 7.5

Red Hat Security Advisory: Release of components for Service Telemetry Framework 1.5.7

Published
October 7, 2026
Last Modified
October 10, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-59885 — pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER CVE-2026-59886 — pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values

🎯 Affected products8

  • Red Hat OpenStack 1.5
  • registry.redhat.io/stf/prometheus-webhook-snmp-rhel9@sha256:4d016a5208197ddf8d28705e6d27640d4752604921050ed5aaa375d111f32d08_amd64 as a component of Red Hat OpenStack 1.5
  • registry.redhat.io/stf/service-telemetry-operator-bundle@sha256:9ea1393237b591f3643af0fd2036d75d0771db85b7cf36d61aa0d8b468bc7e25_amd64 as a component of Red Hat OpenStack 1.5
  • registry.redhat.io/stf/service-telemetry-rhel9-operator@sha256:7e97da5b0f9bbac33646021556d7f35f3c526f6538fbaa0f0fc5b7366b672f74_amd64 as a component of Red Hat OpenStack 1.5
  • registry.redhat.io/stf/sg-bridge-rhel9@sha256:03e5760749218cdd84e46360cb8d475586e564d7cbe72dcf233bae732698c9c8_amd64 as a component of Red Hat OpenStack 1.5
  • registry.redhat.io/stf/sg-core-rhel9@sha256:ce27e2953ecba5d3cac72649da7b8490e83e655973df1c3f40560c4ea672afa7_amd64 as a component of Red Hat OpenStack 1.5
  • registry.redhat.io/stf/smart-gateway-operator-bundle@sha256:5de21a496ce353c1b63241661b24b0a032c89f68ef6c9666f3fd55cf8a6701c4_amd64 as a component of Red Hat OpenStack 1.5
  • registry.redhat.io/stf/smart-gateway-rhel9-operator@sha256:1e2a937e6ba42e3288038dbee7d4963543235faca5983a746326ecc03d19db97_amd64 as a component of Red Hat OpenStack 1.5

✅ Remediation

The Service Telemetry Framework container image provided by this update can be downloaded from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available at Red Hat Container Catalog (see References). Dockerfiles and scripts should be amended either to refer to this new image specifically, or to the latest image generally. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: Update to pyasn1 version 0.6.4 or later when available for your product stream. The impact is limited to availability (denial of service) — an attacker cannot access or modify data. Applications that do not process untrusted ASN.1 input are at reduced risk. Workaround: When processing untrusted ASN.1 data with pyasn1, avoid calling prettyPrint(), str(), float(), int(), or performing comparisons or arithmetic on decoded Real (ASN.1 REAL type) objects. Instead, inspect the raw (mantissa, base, exponent) tuple directly. Where logging decoded ASN.1 structures is necessary, filter out or sanitize Real-typed values before conversion.

🔗 References (11)