Skip to main content

Threats Tagged 'cve-2026-48586'

View all threats tagged with 'cve-2026-48586'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-48586

Threats Tagged 'cve-2026-48586'

Click on any threat for detailed analysis and mitigation recommendations

This release of the Red Hat OpenShift distributed tracing platform (Tempo) provides new features, security improvements, and bug fixes. Breaking changes: * High availability defaults for TempoStack deployment sizes: Before this update, only the ingester component was scaled for high availability while all other components defaulted to a single replica, leaving the overall ingest and query paths vulnerable to single points of failure. With this update, when you set a non-demo deployment size (1x.pico, 1x.extra-small, 1x.small, or 1x.medium) in the spec.size field of the TempoStack custom resource, the Operator defaults each component to at least 2 replicas, and scales throughput-bound components at larger sizes. Watch your resource consumption, as running more replicas per component increases the total CPU and memory consumed by the deployment. Explicit per-component replicas values always take precedence. For more information, see https://redhat.atlassian.net/browse/TRACING-6169. Deprecations: * Jaeger Query is deprecated: The Jaeger Query component in the Tempo Operator is deprecated and will be removed in a future release. The Tempo Operator emits a warning when the Jaeger Query feature is enabled. To visualize traces, use the distributed tracing UI plugin as the recommended replacement for the Jaeger UI. For more information, see https://redhat.atlassian.net/browse/TRACING-6509. Technology Preview features: * None Enhancements: * High availability for TempoStack deployments: You can use the spec.replicationZones field in the TempoStack custom resource to define zone-aware replication. By using this feature, you can deploy TempoStack instances with higher resilience by spreading replicas across topology zones and ensuring minimum pod availability during disruptions. For more information, see https://redhat.atlassian.net/browse/TRACING-6168. * Service name and namespace auto-complete with query RBAC enabled: When you enable query Role-Based Access Control (RBAC) in a multi-tenant TempoStack deployment, the Tempo gateway supports auto-complete for non-sensitive attributes such as service name and namespace. Before this update, all tag value API endpoints were blocked when query RBAC was enabled, which prevented the Service Name drop-down filter in the distributed tracing console plugin from displaying results. With this update, the gateway allows the search tags API for non-sensitive attributes while still protecting sensitive span data. As a result, the Service Name filter and other non-sensitive attribute drop-down list items work correctly in multi-tenant RBAC mode. For more information, see https://redhat.atlassian.net/browse/TRACING-6485. Bug fixes: * TempoStack and TempoMonolithic status conditions accurately reflect pod readiness: Before this update, the status field of the TempoStack or TempoMonolithic custom resource might show Ready=false even when all pods were ready, or vice versa. With this update, the Operator watches Deployment and StatefulSet status changes, and the status conditions accurately reflect actual pod readiness. Deleted pods are removed from the pod status map. As a result, the status field reliably indicates the current state of the deployment. For more information, see https://redhat.atlassian.net/browse/TRACING-6453. * Gateway redirect URL respects the custom ingress hostname: Before this update, setting a custom hostname with the spec.template.gateway.ingress.host field in the TempoStack custom resource did not update the OpenShift OAuth redirect URL, so authentication redirects pointed to the wrong URL. With this update, the Operator uses the custom hostname when generating the redirect URL, and gateway authentication works correctly with custom ingress hostnames. For more information, see https://redhat.atlassian.net/browse/TRACING-6435. * Gateway starts on clusters that use external OIDC authentication: Before this update, on clusters using external OpenID Connect (OIDC) authentication instead of the built-in OpenShift OAuth server, the Tempo gateway container failed to start because it could not auto-discover the OpenShift OAuth endpoints. With this update, the gateway handles external authentication and starts correctly on such clusters. For more information, see https://redhat.atlassian.net/browse/TRACING-6646. Known issues: * None

Join the discussion

Red Hat® AI Inference Server

Join the discussion

Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in. This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which add new features and enhancements, bug fixes, and updated container images. See the following Release Notes documentation, which will be updated shortly for this release, for additional details about this release: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.17/html-single/release_notes/index#acm-release-notes

Join the discussion

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Join the discussion

This update includes the following RPMs: tempo2.10: * tempo2.10-2.10.7-0.2.hum1 (aarch64, x86_64) * tempo2.10-2.10.7-0.2.hum1.src (src) Security Fix(es): tempo2.10: * CVE-2026-48586 * CVE-2026-55969

Join the discussion

This update includes the following RPMs: jaeger: * jaeger-2.20.0-0.5.hum1 (aarch64, x86_64) * jaeger-2.20.0-0.5.hum1.src (src) Security Fix(es): jaeger: * CVE-2026-48586 * CVE-2026-55969

Join the discussion

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Join the discussion

This update includes the following RPMs: opentelemetry-collector: * opentelemetry-collector-0.157.0-0.1.hum1 (aarch64, x86_64) * opentelemetry-collector-0.157.0-0.1.hum1.src (src) Security Fix(es): opentelemetry-collector: * CVE-2026-56852

Join the discussion

This update includes the following RPMs: opentelemetry-collector: * opentelemetry-collector-0.157.0-0.1.hum1 (aarch64, x86_64) * opentelemetry-collector-0.157.0-0.1.hum1.src (src) Security Fix(es): opentelemetry-collector: * CVE-2026-56852

Join the discussion

This package provides a server-side implementation of the FIDO Device Onboard (FDO) specification, written in Go. FDO is an open standard for the late binding of device credentials, allowing for automated and secure on-boarding of devices when they are first powered on in their final location. Security Fix(es): * github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability (CVE-2026-33816) * crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Showing 1 to 10 of 11 results

Filters:Tag: cve-2026-48586
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses