Skip to main content
EPSS 0.6%top 55%

Red Hat Security Advisory: Red Hat Lightspeed (formerly Insights) for Runtimes security update

0
High
Published: 09/29/2026 (09/29/2026, 22:11:35 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

An update is now available for Red Hat Lightspeed (formerly Insights) for Runtimes on RHEL 9. Security fix(es): * gRPC-Go: DoS via malformed RPC requests (CVE-2026-84445) * Go net/mail: DoS via pathological email address parsing (CVE-2026-42499) * Go net/mail: DoS via crafted email inputs (CVE-2026-39820) * Golang MIME: DoS via maliciously-crafted MIME header (CVE-2026-42504) * Go encoding/asn1: DoS via excessive recursion in Unmarshal (CVE-2026-33818) * Golang crypto/tls: DoS via indefinite KeyUpdate messages (CVE-2026-56862) * Go html/template: XSS via pathological input (CVE-2026-56858) * Go net/http: Unencrypted HTTP/2 DoS (CVE-2026-56853) * Go: DoS via XML decoding recursion depth issue (CVE-2026-56859) * golang net/url: DoS from quadratic complexity in path resolution (CVE-2026-56860) * OpenTelemetry-Go: DoS via oversized baggage headers (CVE-2026-41178) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected software

Affected versions
<1.25.13>=1.26.0-0 <1.26.6>=1.27.0-0 <1.27.0=0=1.26.0-0=1.27.0-0<1.26.6=1.26.6=0.46.0-r1=2.0.4-r3Red HatRed Hat Lightspeed (formerly Insights) for RuntimesRed Hat Lightspeed (formerly Insights) for Runtimes 1.0amd64registry.redhat.io/rh-lightspeed-runtimes/runtimes-inventory-rhel9-operator@sha256:a10dc0ef22751c03a28e860b653f792951966822aec437c20c42b74f7f62a35a_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/30/2026, 16:14:06 UTC

Technical Analysis

This advisory covers a security update for Red Hat Lightspeed (formerly Insights) for Runtimes on RHEL 9 that addresses multiple vulnerabilities in Go language components including gRPC-Go, net/mail, MIME, encoding/asn1, crypto/tls, html/template, net/http, XML decoding, net/url, and OpenTelemetry-Go. The vulnerabilities primarily allow denial-of-service attacks through malformed or malicious inputs, and one XSS vulnerability via pathological input. The update includes patched RPM packages for golang1.25 and related components. The vendor advisory confirms the availability of patches and provides detailed package versions for remediation.

Potential Impact

The vulnerabilities allow attackers to cause denial-of-service conditions in affected components by sending malformed or maliciously crafted inputs, potentially disrupting service availability. One vulnerability allows cross-site scripting (XSS) via pathological input. There are no reports of known exploits in the wild. The impact is primarily service disruption and potential security bypass in template rendering.

Mitigation Recommendations

A security update is available and should be applied promptly. Red Hat has released patched versions of golang1.25 packages (version 1.25.13-0.1.hum1) that address these vulnerabilities. Users should update to these versions as per Red Hat's advisory instructions. No additional mitigation steps are indicated by the vendor.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:54836
Cve Count
6
Additional Cves
["CVE-2026-56853","CVE-2026-56858","CVE-2026-56859","CVE-2026-56860","CVE-2026-56862"]
State
PUBLISHED

Threat ID: 6a825c60bf8831d539f21ebc

Added to database: 08/17/2026, 00:57:04 UTC

Last enriched: 09/30/2026, 16:14:06 UTC

Last updated: 10/01/2026, 05:08:51 UTC

Views: 124

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:54836https://images.redhat.com/https://access.redhat.com/security/cve/CVE-2026-56853https://access.redhat.com/security/updates/classification/https://access.redhat.com/security/cve/CVE-2026-56860https://access.redhat.com/security/cve/CVE-2026-56859https://access.redhat.com/security/cve/CVE-2026-33818https://access.redhat.com/security/cve/CVE-2026-56862https://access.redhat.com/security/cve/CVE-2026-56858Canonical URLReference 11Reference 12Reference 13Reference 14Reference 15Reference 16Reference 17Reference 18https://access.redhat.com/errata/RHSA-2026:60304https://access.redhat.com/security/updates/classification/#important251581525158202515827251583825158392515840RHEL-246425Canonical URLhttps://access.redhat.com/errata/RHSA-2026:60305RHEL-246426Canonical URLhttps://access.redhat.com/errata/RHSA-2026:60306RHEL-246423Canonical URLWID-SEC-W-2026-2850 - CSAF VersionWID-SEC-2026-2850 - Portal VersionOSS Security Mailing list vom 2026-08-13Go Vulnerability Report vom 2026-08-13Go Vulnerability Report vom 2026-08-13Go Vulnerability Report vom 2026-08-13Go Vulnerability Report vom 2026-08-13Go Vulnerability Report vom 2026-08-13Go Vulnerability Report vom 2026-08-13Go Vulnerability Report vom 2026-08-13openSUSE Security Update OPENSUSE-SU-2026:11517-1 vom 2026-08-16openSUSE Security Update OPENSUSE-SU-2026:11516-1 vom 2026-08-16SUSE Security Update SUSE-SU-2026:3640-1 vom 2026-08-18Red Hat Security Advisory RHSA-2026:56223 vom 2026-08-18Red Hat Security Advisory RHSA-2026:56143 vom 2026-08-18SUSE Security Update SUSE-SU-2026:3641-1 vom 2026-08-18Red Hat Security Advisory RHSA-2026:54580 vom 2026-08-18openSUSE Security Update OPENSUSE-SU-2026:21593-1 vom 2026-08-21openSUSE Security Update OPENSUSE-SU-2026:21592-1 vom 2026-08-21https://access.redhat.com/errata/RHSA-2026:61882Canonical URLReference 56Reference 57https://access.redhat.com/errata/RHSA-2026:62405Canonical URLhttps://access.redhat.com/errata/RHSA-2026:62404Canonical URLhttps://access.redhat.com/errata/RHSA-2026:63127Canonical URLhttps://access.redhat.com/errata/RHSA-2026:6240624678092467820Canonical URLhttps://access.redhat.com/errata/RHSA-2026:63163Canonical URLhttps://access.redhat.com/errata/RHSA-2026:62407Canonical URLhttps://access.redhat.com/errata/RHSA-2026:626312484204Canonical URLhttps://access.redhat.com/errata/RHSA-2026:62753Canonical URLhttps://access.redhat.com/errata/RHSA-2026:62602Canonical URLhttps://access.redhat.com/errata/RHSA-2026:63119Canonical URLhttps://access.redhat.com/errata/RHSA-2026:62803Canonical URLhttps://access.redhat.com/errata/RHSA-2026:66363https://access.redhat.com/security/cve/CVE-2026-41178https://access.redhat.com/security/cve/CVE-2026-56852https://access.redhat.com/security/cve/CVE-2026-71556https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/security_and_compliance/external-secrets-operator-for-red-hat-openshiftCanonical URLhttps://access.redhat.com/errata/RHSA-2026:64827https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/postinstallation_configuration/configuring-multi-architecture-compute-machines-on-an-openshift-cluster#multiarch-tuning-operatorhttps://github.com/openshift/openshift-docs/blob/main/post_installation_configuration/configuring-multi-arch-compute-machines/multi-arch-tuning-operator-release-notes.adochttps://github.com/openshift/openshift-docs/blob/main/post_installation_configuration/configuring-multi-arch-compute-machines/multiarch-tuning-operator.adochttps://github.com/outrigger-project/multiarch-tuning-operatorCanonical URLhttps://access.redhat.com/errata/RHSA-2026:679752484830Canonical URLhttps://access.redhat.com/errata/RHSA-2026:68527Canonical URLhttps://access.redhat.com/errata/RHSA-2026:70394https://redhat.atlassian.net/browse/WTO-523https://redhat.atlassian.net/browse/WTO-530https://redhat.atlassian.net/browse/WTO-537https://redhat.atlassian.net/browse/WTO-544https://redhat.atlassian.net/browse/WTO-551Canonical URLhttps://access.redhat.com/errata/RHSA-2026:71112https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.7/whats_new-async_updateshttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.7#Upgrade251751825175232517527Canonical URLhttps://access.redhat.com/errata/RHSA-2026:72885https://access.redhat.com/security/cve/CVE-2026-42127https://access.redhat.com/security/cve/CVE-2026-42151https://access.redhat.com/security/cve/CVE-2026-42504Canonical URLhttps://access.redhat.com/errata/RHSA-2026:70593https://access.redhat.com/security/cve/CVE-2026-65819https://access.redhat.com/security/cve/CVE-2026-67213https://access.redhat.com/security/cve/CVE-2026-75899https://access.redhat.com/security/cve/CVE-2026-75931https://access.redhat.com/security/cve/CVE-2026-75975https://access.redhat.com/security/cve/CVE-2026-76172https://access.redhat.com/security/cve/CVE-2026-84292https://access.redhat.com/security/cve/CVE-2026-84375https://access.redhat.com/security/cve/CVE-2026-84394https://access.redhat.com/security/cve/CVE-2026-84445https://docs.openshift.com/container-platform/latest/observability/network_observability/network-observability-operator-release-notes.htmlCanonical URLhttps://access.redhat.com/errata/RHSA-2026:73538https://access.redhat.com/security/cve/CVE-2026-39820https://access.redhat.com/security/cve/CVE-2026-42499Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses