SB20260921121 - Red Hat Enterprise Linux 9 update for grafana
Published: September 21, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 11 vulnerabilities.
1) Improper Authorization (CVE-ID: CVE-2026-27137)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass email address constraints during X.509 certificate chain verification.
The vulnerability exists due to improper enforcement of email constraints in crypto/x509 when verifying certificate chains containing multiple email address constraints with shared local parts but different domains. A remote attacker can present a certificate chain with malformed email constraints to cause only the last constraint to be applied, leading to improper validation.
This issue only affects Go 1.26 and requires the certificate chain to chain to a trusted root. A trusted CA must issue the malicious certificate.
2) Improper Certificate Validation (CVE-ID: CVE-2026-33810)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass certificate name constraints.
The vulnerability exists due to improper certificate validation in the Certificate.Verify function in crypto/x509 when verifying a certificate chain containing excluded DNS constraints and wildcard DNS SANs that use different letter case than the constraint. A remote attacker can present a specially crafted certificate chain to bypass certificate name constraints.
This only affects validation of otherwise trusted certificate chains issued by a root CA in the VerifyOptions.Roots CertPool or in the system certificate pool.
3) Improper access control (CVE-ID: CVE-2026-33377)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges on a specific dashboard.
The vulnerability exists due to improper access control in the dashboard import functionality when importing a dashboard with write access to an existing dashboard. A remote user can overwrite a dashboard not owned by them to escalate privileges on that specific dashboard.
The user must have write access to the dashboard to exploit this issue.
4) Improper access control (CVE-ID: CVE-2026-33376)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass IP-based access restrictions for the Auth Proxy feature.
The vulnerability exists due to improper access control in the Auth Proxy IPv6 allow-list handling when evaluating IPv6 addresses without an explicitly specified mask. A remote attacker can use an IPv6 address that matches the unintended default /32 range to bypass IP-based access restrictions for the Auth Proxy feature.
Only the Auth Proxy feature is affected; other authentication methods such as Okta, SAML, and LDAP are unaffected.
5) Resource exhaustion (CVE-ID: CVE-2026-42127)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in the public dashboard query handler. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
6) Uncontrolled Recursion (CVE-ID: CVE-2026-33818)
CWE-ID: CWE-674 - Uncontrolled Recursion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in Unmarshal and UnmarshalWithParams in encoding/asn1 when parsing deeply nested recursive structures. A remote attacker can supply specially crafted ASN.1 input to cause a denial of service.
7) Resource exhaustion (CVE-ID: CVE-2026-56860)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in net/url URL.Parse and URL.ResolveReference when processing relative paths containing parent directory ('..') segments. A remote attacker can send specially crafted input to cause a denial of service.
8) Resource exhaustion (CVE-ID: CVE-2026-56853)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper timeout handling in net/http when processing new connections for unencrypted HTTP/2 support. A remote attacker can open a connection and withhold the expected HTTP/2 client preface bytes to cause a denial of service.
Only servers configured to support unencrypted HTTP/2 are vulnerable.
9) Cross-site scripting (CVE-ID: CVE-2026-56858)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to inject arbitrary content, potentially leading to cross-site scripting.
The vulnerability exists due to improper neutralization of special elements in html/template when rendering pathological inputs that close an unescaped '/' early. A remote attacker can supply crafted input data to inject arbitrary content, potentially leading to cross-site scripting.
10) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-56862)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper state management in crypto/tls when processing handshake messages before handshake completion. A remote attacker can send repeated KeyUpdate messages to cause a denial of service.
11) Uncontrolled Recursion (CVE-ID: CVE-2026-56859)
CWE-ID: CWE-674 - Uncontrolled Recursion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in encoding/xml Decoder.DecodeElement when parsing deeply nested XML input. A remote attacker can send specially crafted XML data to cause a denial of service.
Remediation
Install update from vendor's website.