Red Hat Security Advisory: grafana security update
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): * crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137) * crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810) * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820) * grafana: Grafana: Privilege escalation via dashboard overwrite (CVE-2026-33377) * grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default (CVE-2026-33376) * golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136) * golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681) * golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502) * grafana: Grafana: Denial of Service due to excessive memory allocation via large JSON payloads (CVE-2026-42127) * grafana: Grafana: Denial of Service via unbounded memory growth in OAuth login route (CVE-2026-8609) * grafana: Grafana: Denial of Service via excessive memory allocation from large API request payloads (CVE-2026-33382) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
This advisory covers a set of security fixes for Grafana and related Go libraries in Red Hat Enterprise Linux 10. Key vulnerabilities include CVE-2026-33377 (privilege escalation via dashboard overwrite), CVE-2026-33376 (unauthorized access due to incorrect IPv6 allow-list default), and CVE-2026-8609 (denial of service via unbounded memory growth in OAuth login route), among others. The update also addresses multiple denial of service and cross-site scripting vulnerabilities in Go crypto/x509, net/mail, golang.org/x/net/html, and other packages. Red Hat has released updated packages for RHEL 10 and its Extended Update Support versions to fix these issues.
Potential Impact
Successful exploitation of these vulnerabilities could allow attackers to escalate privileges within Grafana, gain unauthorized access via the authentication proxy, or cause denial of service conditions through resource exhaustion. Other underlying Go library vulnerabilities could lead to certificate validation bypass, denial of service, or cross-site scripting attacks. The overall security impact is rated Moderate by Red Hat.
Mitigation Recommendations
Red Hat has released updated packages for Grafana and related components in Red Hat Enterprise Linux 10 and its Extended Update Support versions. Users should apply these official updates promptly to remediate the vulnerabilities. For detailed update instructions, refer to the Red Hat advisory at https://access.redhat.com/articles/11258. No additional mitigations are specified or required beyond applying the vendor-provided patches.
Red Hat Security Advisory: grafana security update
Description
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): * crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137) * crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810) * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820) * grafana: Grafana: Privilege escalation via dashboard overwrite (CVE-2026-33377) * grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default (CVE-2026-33376) * golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136) * golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681) * golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502) * grafana: Grafana: Denial of Service due to excessive memory allocation via large JSON payloads (CVE-2026-42127) * grafana: Grafana: Denial of Service via unbounded memory growth in OAuth login route (CVE-2026-8609) * grafana: Grafana: Denial of Service via excessive memory allocation from large API request payloads (CVE-2026-33382) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers a set of security fixes for Grafana and related Go libraries in Red Hat Enterprise Linux 10. Key vulnerabilities include CVE-2026-33377 (privilege escalation via dashboard overwrite), CVE-2026-33376 (unauthorized access due to incorrect IPv6 allow-list default), and CVE-2026-8609 (denial of service via unbounded memory growth in OAuth login route), among others. The update also addresses multiple denial of service and cross-site scripting vulnerabilities in Go crypto/x509, net/mail, golang.org/x/net/html, and other packages. Red Hat has released updated packages for RHEL 10 and its Extended Update Support versions to fix these issues.
Potential Impact
Successful exploitation of these vulnerabilities could allow attackers to escalate privileges within Grafana, gain unauthorized access via the authentication proxy, or cause denial of service conditions through resource exhaustion. Other underlying Go library vulnerabilities could lead to certificate validation bypass, denial of service, or cross-site scripting attacks. The overall security impact is rated Moderate by Red Hat.
Mitigation Recommendations
Red Hat has released updated packages for Grafana and related components in Red Hat Enterprise Linux 10 and its Extended Update Support versions. Users should apply these official updates promptly to remediate the vulnerabilities. For detailed update instructions, refer to the Red Hat advisory at https://access.redhat.com/articles/11258. No additional mitigations are specified or required beyond applying the vendor-provided patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:54178
- Cve Count
- 4
- Additional Cves
- ["CVE-2026-33376","CVE-2026-33377","CVE-2026-33382"]
- State
- PUBLISHED
Threat ID: 6a7c9b55bf8831d539cde26e
Added to database: 08/12/2026, 16:12:05 UTC
Last enriched: 09/24/2026, 07:03:44 UTC
Last updated: 09/28/2026, 01:47:46 UTC
Views: 95
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.