Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

0
Critical
Published: 07/29/2026 (07/29/2026, 21:40:48 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat has issued a security advisory for Red Hat Hardened Images RPMs, specifically updating the grafana13.1 package to address multiple vulnerabilities including CVE-2026-67213 and CVE-2026-67214. The primary vulnerability CVE-2026-67213 is a denial of service (DoS) flaw in the nanoid library used for generating unique IDs. An attacker can trigger an infinite loop by providing zero-size input to certain functions, causing the application to hang. This advisory includes updated RPMs for the affected packages. No explicit CVSS score is provided by Red Hat, but the severity is marked critical. No known exploits in the wild have been reported. The vendor advisory provides details on the fix and recommends applying the update.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 15:29:00 UTC

Technical Analysis

This advisory addresses a critical denial of service vulnerability (CVE-2026-67213) in the nanoid library used by the grafana13.1 package within Red Hat Hardened Images RPMs. The flaw allows an attacker to cause an infinite loop by supplying zero-size input to the customAlphabet or customRandom functions, resulting in resource exhaustion and application hang. The advisory also covers additional CVEs (CVE-2026-67214, CVE-2026-67312, CVE-2026-67320, CVE-2026-67321) affecting the same package. Red Hat has released updated RPMs (grafana13.1-13.1.1-0.3.hum1) for aarch64 and x86_64 architectures to remediate these issues. The advisory references the Red Hat errata RHSA-2026:48241 and provides links for applying the update. No cloud service is involved, and no known active exploitation has been reported.

Potential Impact

Successful exploitation of CVE-2026-67213 results in a denial of service condition by causing an infinite loop in the nanoid library, which hangs the application's calling thread and consumes excessive CPU resources. This can degrade application availability and responsiveness. The other CVEs listed may have additional impacts but are not detailed in the provided data. There are no reports of active exploitation in the wild at this time.

Mitigation Recommendations

Red Hat has released updated RPM packages (grafana13.1-13.1.1-0.3.hum1) that fix the vulnerabilities. Users should apply this security update promptly to remediate the issues. The vendor advisory provides detailed instructions and references for applying the update. No alternative mitigations or workarounds are specified. Patch status is confirmed by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:48241
Cve Count
4
Additional Cves
["CVE-2026-67312","CVE-2026-67320","CVE-2026-67321"]
Cvss Version
null

Threat ID: 6a81d6f4bf8831d53949f9db

Added to database: 08/16/2026, 15:27:48 UTC

Last enriched: 08/16/2026, 15:29:00 UTC

Last updated: 08/16/2026, 20:41:00 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses