Red Hat Security Advisory: Red Hat OpenShift distributed tracing platform (Tempo) 3.9.2 release
Red Hat OpenShift distributed tracing platform (Tempo) 3. 9. 2 addresses multiple security vulnerabilities including an authorization bypass in gRPC-Go due to improper HTTP/2 :path validation, denial-of-service flaws in XPath processing and JSON parsing, and several issues in Go standard libraries affecting certificate validation, race conditions, and resource exhaustion. These fixes prevent unauthorized access, denial-of-service conditions, and potential code execution paths. No breaking changes or deprecations are introduced in this release.
AI Analysis
Technical Summary
This Red Hat OpenShift Tempo 3.9.2 release includes security fixes for several vulnerabilities: a gRPC-Go authorization bypass caused by improper validation of the HTTP/2 :path pseudo-header allowing attackers to bypass security policies; an XPath component infinite loop leading to CPU exhaustion; a Go JOSE library denial-of-service via malformed JSON Web Encryption objects; lodash _.template function code injection risk through unvalidated options.imports keys; Go crypto/x509 and crypto/tls package fixes addressing denial-of-service and certificate validation bypasses; a race condition in Go's Root.Chmod function allowing permission changes on unintended files; and denial-of-service issues in JSON parser and path-to-regexp components due to malformed inputs or complex regex patterns. Each vulnerability is mitigated by proper input validation, limiting resource consumption, or correcting logic errors.
Potential Impact
The vulnerabilities fixed in this release could allow remote attackers to bypass authorization controls, cause denial-of-service conditions by exhausting CPU or memory resources, execute arbitrary code through template injection, or bypass TLS certificate validation leading to unauthorized connections. These impacts affect the confidentiality, integrity, and availability of services running Red Hat OpenShift Tempo prior to version 3.9.2. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
An official fix is available in Red Hat OpenShift distributed tracing platform (Tempo) version 3.9.2. Users should upgrade to this version to address the described vulnerabilities. The vendor advisory confirms that these issues are resolved in this release. No additional mitigation actions are required beyond applying this update.
Red Hat Security Advisory: Red Hat OpenShift distributed tracing platform (Tempo) 3.9.2 release
Description
Red Hat OpenShift distributed tracing platform (Tempo) 3. 9. 2 addresses multiple security vulnerabilities including an authorization bypass in gRPC-Go due to improper HTTP/2 :path validation, denial-of-service flaws in XPath processing and JSON parsing, and several issues in Go standard libraries affecting certificate validation, race conditions, and resource exhaustion. These fixes prevent unauthorized access, denial-of-service conditions, and potential code execution paths. No breaking changes or deprecations are introduced in this release.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat OpenShift Tempo 3.9.2 release includes security fixes for several vulnerabilities: a gRPC-Go authorization bypass caused by improper validation of the HTTP/2 :path pseudo-header allowing attackers to bypass security policies; an XPath component infinite loop leading to CPU exhaustion; a Go JOSE library denial-of-service via malformed JSON Web Encryption objects; lodash _.template function code injection risk through unvalidated options.imports keys; Go crypto/x509 and crypto/tls package fixes addressing denial-of-service and certificate validation bypasses; a race condition in Go's Root.Chmod function allowing permission changes on unintended files; and denial-of-service issues in JSON parser and path-to-regexp components due to malformed inputs or complex regex patterns. Each vulnerability is mitigated by proper input validation, limiting resource consumption, or correcting logic errors.
Potential Impact
The vulnerabilities fixed in this release could allow remote attackers to bypass authorization controls, cause denial-of-service conditions by exhausting CPU or memory resources, execute arbitrary code through template injection, or bypass TLS certificate validation leading to unauthorized connections. These impacts affect the confidentiality, integrity, and availability of services running Red Hat OpenShift Tempo prior to version 3.9.2. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
An official fix is available in Red Hat OpenShift distributed tracing platform (Tempo) version 3.9.2. Users should upgrade to this version to address the described vulnerabilities. The vendor advisory confirms that these issues are resolved in this release. No additional mitigation actions are required beyond applying this update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:9385
- Cve Count
- 12
- Additional Cves
- ["CVE-2026-4645","CVE-2026-4800","CVE-2026-4926","CVE-2026-25679","CVE-2026-27137","CVE-2026-32280","CVE-2026-32282","CVE-2026-32285","CVE-2026-33186","CVE-2026-33810","CVE-2026-34986"]
- Cvss Version
- null
Threat ID: 6a160952e29bf47b50618c9a
Added to database: 5/26/2026, 8:57:54 PM
Last enriched: 5/26/2026, 8:59:50 PM
Last updated: 5/26/2026, 9:00:39 PM
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.