RHSA-2026:68333HighCVSS 8.6

Red Hat Security Advisory: Red Hat build of Cryostat security update

Published
September 16, 2026
Last Modified
September 19, 2026

🔗 CVE IDs covered (30)

📋 Description

CVE-2026-15075 — vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects CVE-2026-15076 — io.vertx/vertx-web: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation CVE-2026-16308 — io.quarkus/quarkus-rest: io.quarkus/quarkus-vertx-http: io.quarkus.resteasy.reactive/resteasy-reactive: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-45112 — thrift: Apache Thrift: Denial of Service due to uncontrolled resource allocation CVE-2026-48586 — thrift: org.apache.thrift/libthrift: github.com/apache/thrift: Apache Thrift: Denial of Service via improper handling of highly compressed data CVE-2026-49978 — dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution CVE-2026-54399 — org.apache.httpcomponents.core5/httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers CVE-2026-54428 — org.apache.httpcomponents.core5/httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks CVE-2026-55831 — io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing CVE-2026-55833 — netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification CVE-2026-55851 — io.netty/netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message CVE-2026-55874 — SeaweedFS: github.com/seaweedfs/seaweedfs: SeaweedFS: Information disclosure via S3 API gateway path traversal CVE-2026-55969 — thrift: github.com/apache/thrift: Apache Thrift: Denial of Service via integer overflow or wraparound CVE-2026-56745 — netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec CVE-2026-56746 — io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header CVE-2026-56819 — io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak CVE-2026-56854 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-58372 — github.com/seaweedfs/seaweedfs: SeaweedFS: Unauthorized data deletion via path traversal in S3 gateway CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-59877 — protobufjs: protobufjs: Denial of Service via crafted .proto schema CVE-2026-59899 — io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) CVE-2026-68494 — com.fasterxml.jackson.core/jackson-core: tools.jackson.core/jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass

🎯 Affected products21

  • Cryostat 4 on RHEL 9
  • cryostat/cryostat-agent-init-rhel9@sha256:bc47200b2bb00c9cb4f4ae4929d0faca3b7685ba160bafe07f773e8cfe977b6e_arm64 as a component of Cryostat 4 on RHEL 9
  • cryostat/cryostat-agent-init-rhel9@sha256:fd21840bc7fd04a3387186e8eadf3c1772b71c3a68d90c6f8f157de0c1e51826_amd64 as a component of Cryostat 4 on RHEL 9
  • cryostat/cryostat-db-rhel9@sha256:0bcd6d1e5fd1dc893c83641c96ebcdaf27fd576cd150d7c53a79ec99cd0581be_arm64 as a component of Cryostat 4 on RHEL 9
  • cryostat/cryostat-db-rhel9@sha256:a1c62ba6ab13ab0b429552304050235f5d85870de0d5733bf4bf9240661e769d_amd64 as a component of Cryostat 4 on RHEL 9
  • cryostat/cryostat-grafana-dashboard-rhel9@sha256:8d67c1c76672ecb9241469355656c751bd8b54c138d6fb16866d604bb6da95ed_arm64 as a component of Cryostat 4 on RHEL 9
  • cryostat/cryostat-grafana-dashboard-rhel9@sha256:a236a3646adf4c5b467e630cdd7b8ae4b5d874dc6342fcac1e5290c2beac0d06_amd64 as a component of Cryostat 4 on RHEL 9
  • cryostat/cryostat-openshift-console-plugin-rhel9@sha256:11bda199b4124dd05b55b07b4d7508b1029371ad650afc3bba12b486011c6b26_amd64 as a component of Cryostat 4 on RHEL 9
  • cryostat/cryostat-openshift-console-plugin-rhel9@sha256:a1c2dfa85f82dd2bd96853270cd46de8dcffe4f6f81e7646eeb032843884ff94_arm64 as a component of Cryostat 4 on RHEL 9
  • cryostat/cryostat-operator-bundle@sha256:01b7df9a63ddcffaca5f4594da01b1d0cb03fb4c0db8061266a67f027a67393b_arm64 as a component of Cryostat 4 on RHEL 9
  • cryostat/cryostat-operator-bundle@sha256:1ff5e21e25d3c96ed212689f2b368b20a935f0669af31c37a1ae90cdf6be9d9e_amd64 as a component of Cryostat 4 on RHEL 9
  • cryostat/cryostat-reports-rhel9@sha256:09183b020f24f1b478b3391109f5b42aa066f9df71febec4c642621f82d3a304_amd64 as a component of Cryostat 4 on RHEL 9
  • cryostat/cryostat-reports-rhel9@sha256:56942fe083a729c20c316899678a9b8bcb53d7cd0166bf1d026e71e7d69aee86_arm64 as a component of Cryostat 4 on RHEL 9
  • cryostat/cryostat-rhel9-operator@sha256:5091ea57743ec205834299edc38fc4bd011c7eb735bda422dc751a5084bb43af_amd64 as a component of Cryostat 4 on RHEL 9
  • cryostat/cryostat-rhel9-operator@sha256:a6932f33459645777f557163dd24c2d7dfd11bda6020d7dc144c65eda80a178e_arm64 as a component of Cryostat 4 on RHEL 9
  • cryostat/cryostat-rhel9@sha256:1bbd4a394a3ebcff86b518ec7a7d242088913052873b73cc2d7e09ed1b181c80_amd64 as a component of Cryostat 4 on RHEL 9
  • cryostat/cryostat-rhel9@sha256:4d1c6cfbce9d2a106ff1d14681fdc51d00b203f057d66e5023067b04d3429d20_arm64 as a component of Cryostat 4 on RHEL 9
  • cryostat/cryostat-storage-rhel9@sha256:5be66a00286e1733b91ea407788843a4123ff8bdcb830ec031bcd41b1e337255_amd64 as a component of Cryostat 4 on RHEL 9
  • cryostat/cryostat-storage-rhel9@sha256:66f8afe0cebac9600554636ec0493a15634e6af6e94875b65bbdfb39ae92b4b3_arm64 as a component of Cryostat 4 on RHEL 9
  • cryostat/jfr-datasource-rhel9@sha256:23ea9da4ea97cdd04d95b500fbca8edd7db908fec16043ae1fa336634ffcd1fb_arm64 as a component of Cryostat 4 on RHEL 9
  • cryostat/jfr-datasource-rhel9@sha256:2663c6efa60f097f5b0be4a15f58bf1645b3313d1ebab6c19c42b8e6cc3e234a_amd64 as a component of Cryostat 4 on RHEL 9

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, configure applications utilizing Vert.x HttpClient to strictly validate and restrict the URLs to which HTTP requests can be redirected. Implement allowlists for trusted domains and ensure that any user-supplied or external URLs processed by Vert.x HttpClient are thoroughly sanitized and validated to prevent redirection to attacker-controlled destinations. This may involve updating application-specific configurations or implementing custom URL validation logic. A service restart or reload may be required for changes to take effect. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, configure an upstream proxy or web application firewall (WAF) to enforce limits on the number and length of HTTP headers. This prevents malformed requests from reaching and exhausting the vulnerable Apache HttpComponents Core component. Consult your proxy or WAF documentation for specific configuration. A service restart may be required for changes to take effect. Workaround: If CORS short-circuit functionality is not required, disable the shortCircuit() configuration in the CorsHandler. Alternatively, implement application-level origin validation to reject requests with null Origin headers. A web application firewall (WAF) can also be configured to block requests with null or missing Origin headers. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the criteria for vulnerability selection or Red Hat Product Security recommendation. Restricting S3 write access to trusted principals reduces the risk of exploitation. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Applications that only encode or decode protobuf messages using trusted schemas are not directly affected. Until patched protobufjs packages (7.6.5 / 8.6.6) are available, do not parse .proto schema text from untrusted sources via parse, Root.load, or Root.loadSync. Where untrusted schema input cannot be avoided, isolate .proto parsing in a dedicated worker thread or subprocess and enforce an explicit timeout so a non-returning parse cannot block the main event loop. Optional process-manager controls (for example systemd restart-on-failure, or CPU/cgroup limits) may reduce host-level impact or aid recovery for supervised services, but they do not fix the parser bug and are not a substitute for input isolation or applying the update. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function.

🔗 References (33)