Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Red Hat Security Advisory: Red Hat OpenShift distributed tracing platform (Tempo) 3.9.2 release

0
High
Published: Tue Apr 21 2026 (04/21/2026, 15:08:38 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift distributed tracing platform (Tempo) 3. 9. 2 addresses multiple security vulnerabilities including an authorization bypass in gRPC-Go due to improper HTTP/2 :path validation, denial-of-service flaws in XPath processing and JSON parsing, and several issues in Go standard libraries affecting certificate validation, race conditions, and resource exhaustion. These fixes prevent unauthorized access, denial-of-service conditions, and potential code execution paths. No breaking changes or deprecations are introduced in this release.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/26/2026, 20:59:50 UTC

Technical Analysis

This Red Hat OpenShift Tempo 3.9.2 release includes security fixes for several vulnerabilities: a gRPC-Go authorization bypass caused by improper validation of the HTTP/2 :path pseudo-header allowing attackers to bypass security policies; an XPath component infinite loop leading to CPU exhaustion; a Go JOSE library denial-of-service via malformed JSON Web Encryption objects; lodash _.template function code injection risk through unvalidated options.imports keys; Go crypto/x509 and crypto/tls package fixes addressing denial-of-service and certificate validation bypasses; a race condition in Go's Root.Chmod function allowing permission changes on unintended files; and denial-of-service issues in JSON parser and path-to-regexp components due to malformed inputs or complex regex patterns. Each vulnerability is mitigated by proper input validation, limiting resource consumption, or correcting logic errors.

Potential Impact

The vulnerabilities fixed in this release could allow remote attackers to bypass authorization controls, cause denial-of-service conditions by exhausting CPU or memory resources, execute arbitrary code through template injection, or bypass TLS certificate validation leading to unauthorized connections. These impacts affect the confidentiality, integrity, and availability of services running Red Hat OpenShift Tempo prior to version 3.9.2. No known exploits in the wild have been reported at this time.

Mitigation Recommendations

An official fix is available in Red Hat OpenShift distributed tracing platform (Tempo) version 3.9.2. Users should upgrade to this version to address the described vulnerabilities. The vendor advisory confirms that these issues are resolved in this release. No additional mitigation actions are required beyond applying this update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:9385
Cve Count
12
Additional Cves
["CVE-2026-4645","CVE-2026-4800","CVE-2026-4926","CVE-2026-25679","CVE-2026-27137","CVE-2026-32280","CVE-2026-32282","CVE-2026-32285","CVE-2026-33186","CVE-2026-33810","CVE-2026-34986"]
Cvss Version
null

Threat ID: 6a160952e29bf47b50618c9a

Added to database: 5/26/2026, 8:57:54 PM

Last enriched: 5/26/2026, 8:59:50 PM

Last updated: 5/26/2026, 9:00:39 PM

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses