Skip to main content
EPSS 0.5%top 60%

Security update for google-cloud-sap-agent

0
High
Published: 09/14/2026 (09/14/2026, 08:32:36 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This update for google-cloud-sap-agent fixes the following issues: Security issues fixed: - CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272128). - CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279304). - CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279201). - CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278987). Non security issue fixed: - re-enable stripping and debuginfo (bsc#1210938).

Affected software

Affected versions
=1.44.0-3.3.hum1<1.42.3-r1<3.4.1-r3Red HatRed Hat Hardened Imagesaarch64golang1-25-main@aarch64opentofu1-12-main@aarch64golang1-26-main@aarch64grype-main@aarch64syft-main@aarch64spire1-14-main@aarch64opentofu1-11-main@aarch64skopeo-main@aarch64jaeger-main@aarch64prometheus3-13-main@aarch64prometheus3-5-main@aarch64yq-main@aarch64oauth2-proxy-main@aarch64opentofu1-10-main@aarch64hugo-main@aarch64kubernetes1-35-main@aarch64<1.9.1-r1<0.7.10-r1MicrosoftAzure Linux3.0Azure Linux 3.0azurelinux-image-toolskubernetes1-36-main@aarch64caddy-main@aarch64cosign-main@aarch64etcd-main@aarch64go-fdo-client-main@aarch64buildah-main@aarch64go-fdo-server-main@aarch64SUSEgoogle-cloud-sap-agent-3.15-160000.4.1.aarch64ppc64legoogle-cloud-sap-agent-3.15-160000.4.1.ppc64le

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 19:45:58 UTC

Technical Analysis

CVE-2026-56852 is a denial of service vulnerability in the golang.org/x/text library's norm.Iter component. When processing input containing invalid UTF-8 bytes, norm.Iter can enter an infinite loop, leading to resource exhaustion and application unresponsiveness. This flaw affects Red Hat Hardened Images RPMs including golang1.26 packages. Red Hat has issued a security advisory (RHSA-2026:49360) describing the issue but currently does not provide a patch or mitigation that meets their standards. The vulnerability is identified as CWE-835 (Loop with Unreachable Exit Condition).

Potential Impact

The vulnerability allows a remote attacker to cause a denial of service by providing specially crafted invalid UTF-8 input to applications using the affected golang.org/x/text norm.Iter functionality. This results in an infinite loop, causing high CPU and memory consumption and rendering the application unresponsive. There is no impact on confidentiality or integrity, only availability is affected.

Mitigation Recommendations

Currently, Red Hat does not offer a fix or mitigation that meets their criteria for ease of use, deployment, applicability, or stability. Users should monitor Red Hat advisories and update when a fix becomes available. Until then, consider limiting exposure to untrusted input that could trigger this vulnerability if possible.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:49360
Cve Count
1
State
PUBLISHED

Threat ID: 6a74cf8ebf8831d5391aebfa

Added to database: 08/06/2026, 18:16:46 UTC

Last enriched: 08/13/2026, 19:45:58 UTC

Last updated: 09/21/2026, 22:01:35 UTC

Views: 42

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:49360https://access.redhat.com/security/cve/CVE-2026-56852https://access.redhat.com/security/updates/classification/https://images.redhat.com/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:41020Canonical URLhttps://access.redhat.com/errata/RHSA-2026:44451Canonical URLhttps://access.redhat.com/errata/RHSA-2026:43801Canonical URLhttps://access.redhat.com/errata/RHSA-2026:44151Canonical URLhttps://access.redhat.com/errata/RHSA-2026:40964Canonical URLhttps://access.redhat.com/errata/RHSA-2026:42083Canonical URLReference 18Reference 19https://access.redhat.com/errata/RHSA-2026:43015Canonical URLhttps://access.redhat.com/errata/RHSA-2026:46960Canonical URLhttps://access.redhat.com/errata/RHSA-2026:43119Canonical URLhttps://access.redhat.com/errata/RHSA-2026:43554Canonical URLhttps://access.redhat.com/errata/RHSA-2026:43311Canonical URLhttps://access.redhat.com/errata/RHSA-2026:43716Canonical URLhttps://access.redhat.com/errata/RHSA-2026:43797Canonical URLhttps://access.redhat.com/errata/RHSA-2026:43803Canonical URLhttps://access.redhat.com/errata/RHSA-2026:49317Canonical URLhttps://access.redhat.com/errata/RHSA-2026:44479Canonical URLhttps://access.redhat.com/errata/RHSA-2026:54364Canonical URLhttps://access.redhat.com/errata/RHSA-2026:43866Canonical URLhttps://access.redhat.com/errata/RHSA-2026:43873Canonical URLhttps://access.redhat.com/errata/RHSA-2026:43852Canonical URLhttps://access.redhat.com/errata/RHSA-2026:54549https://access.redhat.com/security/cve/CVE-2026-73501Canonical URLhttps://access.redhat.com/errata/RHSA-2026:43906Canonical URLReference 53Reference 54CVE-2026-56852 Infinite loop on invalid input in golang.org/x/text - VEXMicrosoft Support LifecycleCommon Vulnerability Scoring Systemhttps://access.redhat.com/errata/RHSA-2026:44430Canonical URLhttps://access.redhat.com/errata/RHSA-2026:46953Canonical URLhttps://access.redhat.com/errata/RHSA-2026:48306Canonical URLhttps://access.redhat.com/errata/RHSA-2026:52912Canonical URLSUSE ratingsURL of this CSAF noticeSUSE Bug 1210938SUSE Bug 1272128SUSE Bug 1278987SUSE Bug 1279201SUSE Bug 1279304SUSE CVE CVE-2026-56852 pageSUSE CVE CVE-2026-84303 pageSUSE CVE CVE-2026-84304 pageSUSE CVE CVE-2026-84445 pageSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses