Red Hat released security updates for git-lfs on RHEL 9, Grafana on RHEL 9, the RHEL 9 toolbox package, and the OpenShift Serverless Client (kn) on RHEL 8. The advisories remediate vulnerabilities in bundled Go components affecting HTTP and HTTP/2 processing, malformed DNS-message handling, TLS/QUIC and X.509 certificate verification, multipart parsing, IP-address handling, ZIP processing, cookie/header forwarding, template escaping, and potential sensitive-URL logging.
The affected products span x86_64, s390x, ppc64le, and aarch64 systems, with several RHEL 9 advisories also covering Extended Update Support, Extended Life Cycle, AUS, and SAP-related subscriptions. Red Hat supplied git-lfs 3.6.1-1.el9, Grafana 10.2.6-4.el9, and toolbox 0.0.99.5-5.el9 packages; organizations should apply the applicable vendor updates through their standard Red Hat or OpenShift package-management processes.

See real exploitation activity before you spend the cycle.
100 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Important advisory RHSA-2026:63124 for grafana-pcp on RHEL 8. The update remediated six bundled Go-component flaws, including MIME-header, ASN.1 recursion, net/url path-resolution, unencrypted HTTP/2, TLS KeyUpdate denial-of-service issues, and an html/template cross-site scripting vulnerability.
AlmaLinux issued ALSA-2026:62577 for go-fdo-client on AlmaLinux 10, associated with RHSA-2026:62577. The update addressed CVE-2026-33810, CVE-2026-33818, CVE-2026-56860, and CVE-2026-56862; the Nessus record reported no known exploits.
AlmaLinux published ALSA-2026:62406 for grafana and grafana-selinux on AlmaLinux 9. The update remediated eight Go-component vulnerabilities affecting net/mail parsing, ASN.1 and XML decoding, URL path resolution, unencrypted HTTP/2, TLS KeyUpdate handling, and html/template cross-site scripting; no known exploits were reported.
AlmaLinux published security advisory ALSA-2026:62407 for grafana and grafana-selinux packages on AlmaLinux 8. The update remediated eight vulnerabilities, including net/mail parsing denial of service, ASN.1 and XML recursion, URL path resolution, unencrypted HTTP/2, TLS KeyUpdate handling, and an html/template cross-site scripting flaw; no known exploits were reported.
Red Hat issued Important advisory RHSA-2026:62407 for Grafana on RHEL 8, including RHEL 8.10 EUS. The update remediated eight bundled Go vulnerabilities affecting net/mail parsing, ASN.1 and XML decoding, URL path resolution, unencrypted HTTP/2, TLS KeyUpdate handling, and html/template cross-site scripting; no known public exploits were reported.
Red Hat issued Important advisory RHSA-2026:62753 for osbuild-composer-core and osbuild-composer-worker on RHEL 9.4 E4S. The update remediated eight Go vulnerabilities affecting net/mail parsing, ASN.1 and XML decoding, net/url path resolution, unencrypted HTTP/2, TLS KeyUpdate handling, and html/template cross-site scripting.
Red Hat published Important advisory RHSA-2026:62405 for affected Golang packages on RHEL 9. The update remediated six Go flaws involving ASN.1 recursion, net/url path resolution, unencrypted HTTP/2, html/template cross-site scripting, TLS KeyUpdate processing, and XML decoding; no known public exploits were reported.
Red Hat issued Important advisory RHSA-2026:62602 for Go packages on RHEL 9, updating go-toolset, golang, and associated Go package components. The update remediated six flaws involving ASN.1 recursion, net/url path resolution, unencrypted HTTP/2, html/template cross-site scripting, TLS KeyUpdate handling, and XML decoding.
Red Hat published Important advisory RHSA-2026:62406 for Grafana on RHEL 9, remediating eight bundled Go-component vulnerabilities. The update addressed net/mail parsing denial of service, ASN.1 recursion, URL path-resolution, unencrypted HTTP/2, TLS KeyUpdate, XML decoding, and an html/template cross-site scripting flaw.
Red Hat published Important advisory RHSA-2026:62803 for osbuild-composer on RHEL 9, updating affected osbuild-composer-core and osbuild-composer-worker components. The update remediated eight Go vulnerabilities in net/mail, ASN.1, XML, URL resolution, unencrypted HTTP/2, TLS KeyUpdate handling, and html/template, including denial-of-service and cross-site scripting issues.
Red Hat published Important advisory RHSA-2026:62631 for golang-github-openprinting-ipp-usb on RHEL 10.2. The update remediated six Go denial-of-service flaws in MIME-header processing, ASN.1 unmarshalling, URL path resolution, unencrypted HTTP/2, TLS KeyUpdate handling, and XML decoding.
Red Hat published RHSA-2026:60668 for Red Hat Enterprise Linux CoreOS 4 systems using Red Hat build of MicroShift 4.21.31. The Important update remediates CVE-2026-33814, in which a malformed HTTP/2 SETTINGS_MAX_FRAME_SIZE frame can trigger denial of service in golang.org/x/net's net/http/internal/http2 implementation.
Red Hat issued Important advisory RHSA-2026:61882 for Golang packages on RHEL 10 and RHEL EUS 10.0. The update remediated six Go vulnerabilities affecting ASN.1 recursion, net/url path resolution, unencrypted HTTP/2, html/template XSS, TLS KeyUpdate handling, and XML decoding; no known exploits were reported.
Amazon Linux published ALAS2-2026-3893 for Amazon Linux 2, updating golang to version 1.26.7-1. The update remediated six previously tracked Go flaws and two module supply-chain integrity issues, CVE-2026-56864 and CVE-2026-56865, involving malicious GOSUMDB/GOPROXY services bypassing transparency-log or checksum-tile validation.
Red Hat published Important advisory RHSA-2026:61245 for affected RHEL 9 osbuild-composer packages. The update remediated CVE-2026-33186, a gRPC-Go HTTP/2 path-validation authorization bypass, and CVE-2026-39821, a Punycode-label processing privilege-escalation issue in golang.org/x/net/idna and Go net/http.
Tenable published a vulnerability record for CVE-2026-82556 affecting CentOS 7 and 8 and RHEL 7 through 10. The record lists Go/Golang, container tooling, Grafana-related components, and other packages as affected, reports no known exploits, and provides no technical root cause or remediation details.
Oracle published ELSA-2026-603060 for Oracle Linux 10 Go toolset packages, including golang-bin, golang-docs, golang-misc, golang-race, golang-src, and golang-tests. The update remediated CVE-2026-33818, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, and CVE-2026-56862; no known exploits were reported.
Rocky Linux published RLSA-2026:60304 for Rocky Linux 9, updating Go-related packages to version 1.26.7+1 for rhel-9.8.z. The update remediated six flaws in ASN.1 parsing, net/url path resolution, unencrypted HTTP/2, html/template, TLS KeyUpdate handling, and XML decoding, and included a FIPS-mode CGO RAND_bytes thread-limit fix.
SUSE published SUSE-SU-2026:3815-1 for go1.25-openssl on SLED15, SLED_SAP15, SLES15, and SLES_SAP15, updating FIPS-enabled packages to 1.25.14-1-openssl-fips. The update addressed ASN.1/XML stack exhaustion, HTTP/2 and path-resolution denial of service, html/template XSS, TLS record-limit bypass, IDNA validation bypass, and GOSUMDB/GOPROXY module-verification flaws.
AlmaLinux published ALSA-2026-60306 for AlmaLinux 10, updating go-toolset and Golang package components. The advisory remediated six Go vulnerabilities: CVE-2026-33818, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, and CVE-2026-56862; no known exploits were reported.
AlmaLinux published ALSA-2026:60304 for AlmaLinux 9, updating Go-related packages including go-toolset and golang components. The advisory addressed CVE-2026-33818, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, and CVE-2026-56862; it reported no known exploits.
Red Hat issued Important advisory RHSA-2026:60306 for Go packages in RHEL 10.2.z, providing Go 1.26.7+1. The update remediated denial-of-service flaws in ASN.1, XML, net/url, unencrypted HTTP/2, and TLS KeyUpdate processing, plus an html/template cross-site scripting flaw.
Red Hat issued Important advisory RHSA-2026:60305 for the go-toolset:rhel8 module, upgrading Go Toolset to version 1.26.7+1 for RHEL 8 and RHEL 8.10 Extended Life Cycle releases. The update remediated six Go flaws affecting ASN.1 recursion, net/url path resolution, unencrypted HTTP/2, html/template XSS, TLS KeyUpdate handling, and XML decoding.
Red Hat issued Important advisory RHSA-2026:60304 for Go packages in RHEL 9, updating them to Go 1.26.7-1.el9_8. The update remediated five denial-of-service flaws in encoding/asn1, net/url, net/http, crypto/tls, and encoding/xml, an html/template cross-site scripting flaw, and a FIPS-mode CGO RAND_bytes thread-limit issue.
Red Hat reported Bug 2515820 for CVE-2026-56860, a high-severity denial-of-service vulnerability in Go net/url path resolution. Relative paths with repeated ".." segments could trigger quadratic CPU and memory consumption; the fix uses byte-buffer, index-based backtracking to eliminate the quadratic behavior.
Red Hat issued Moderate advisory RHSA-2025:7256 for git-lfs on RHEL 9 and provided git-lfs 3.6.1-1.el9. The update remediated six vulnerabilities affecting Go TLS/QUIC handling, DNS parsing, IP address processing, HTTP handling, and golang-fips.
Red Hat issued Important advisory RHSA-2025:0662 for Grafana on RHEL 9.4 lifecycle channels, providing grafana-9.2.10-21.el9_4. The update remediated go-git argument injection through a URL field (CVE-2025-21613) and denial of service via malicious Git server replies (CVE-2025-21614).
Red Hat issued Moderate advisory RHSA-2024:9089 for containernetworking-plugins on RHEL 9, providing version 1.5.1-2.el9. The update remediated CVE-2024-24788, a malformed-DNS infinite-loop flaw, and CVE-2024-24791, an HTTP 100-continue denial-of-service flaw in Go.
Red Hat published Moderate advisory RHSA-2024:9135 and released toolbox 0.0.99.5-5.el9 for RHEL 9. The update remediated four Go issues: multipart-form memory exhaustion, HTML template-escaping failure, malformed-DNS infinite loops, and HTTP 100-continue denial of service.
Red Hat issued Important advisory RHSA-2024:9473 for Grafana on RHEL 9, providing Grafana 10.2.6-7.el9_5. The update remediated CVE-2024-34156, a stack-exhaustion panic in Go's encoding/gob decoder, and CVE-2024-47875, a DOMPurify nesting-based mutation cross-site scripting flaw.
Red Hat published Moderate advisory RHSA-2024:9115 for Grafana on RHEL 9, providing Grafana 10.2.6-4.el9. It addressed five bundled Go-component vulnerabilities involving DNS and HTTP denial of service, ZIP handling, IPv4-mapped IPv6 behavior, and sensitive URL data in logs.
Red Hat issued Important advisory RHSA-2024:8678 for Grafana in RHEL 9.4 Extended Update Support and associated RHEL 9 channels, providing grafana-9.2.10-19.el9_4. The update remediated CVE-2024-9355, a golang-fips zeroed-buffer issue, and CVE-2024-47875, a DOMPurify nesting-based mutation cross-site scripting vulnerability.
Red Hat issued Important advisory RHSA-2024:8327 for Grafana on RHEL 8 and RHEL 8.10 Extended Life Cycle, providing Grafana 9.2.10-20.el8_10. The update remediated CVE-2024-9355, a golang-fips zeroed-buffer issue, and CVE-2024-47875, a DOMPurify nesting-based mutation cross-site scripting vulnerability.
Red Hat reported tracking issue 2318052 for CVE-2024-47875, a high-severity nesting-based mutation cross-site scripting vulnerability in DOMPurify. The flaw is fixed in DOMPurify 2.5.0 and 3.1.3.
Red Hat issued Moderate advisory RHSA-2024:5291 for Grafana on RHEL 8, providing Grafana 9.2.10-17.el8_10. The update remediated three bundled Go vulnerabilities involving malformed-DNS infinite loops, incorrect ZIP-file handling, and IPv4-mapped IPv6 netip Is-method behavior.
Red Hat issued Important advisory RHSA-2024:4023 for OpenShift Serverless Client (kn) on RHEL 8. The update to openshift-serverless-clients 1.12.0-7.el8 remediated six Go vulnerabilities, including HTTP/2 denial of service, sensitive-header forwarding, multipart memory exhaustion, and X.509 verification flaws.
Red Hat issued Important advisory RHSA-2024:3346 for git-lfs on RHEL 8, providing git-lfs 3.4.1-2.el8_10. The update remediated four Go vulnerabilities involving HTTP/2 CONTINUATION-frame denial of service, sensitive header and cookie forwarding on redirects, multipart-form memory exhaustion, and X.509 certificate-verification panics.
Red Hat issued Important advisory RHSA-2024:3259 for the go-toolset:rhel8 module, delivering Go Toolset 1.21.9 packages for RHEL 8. The update remediated six Go flaws affecting HTTP/2 CONTINUATION frames, redirect forwarding, multipart-form memory use, X.509 verification, mail display-name parsing, and HTML template escaping.
Red Hat issued Important advisory RHSA-2024:2724 for git-lfs on RHEL 9, providing git-lfs 3.4.1-2.el9_4. The update remediated four Go vulnerabilities affecting HTTP/2 CONTINUATION-frame handling, redirect forwarding of sensitive headers and cookies, multipart-form memory use, and X.509 certificate verification.
Red Hat issued Moderate advisory RHSA-2024:2160 for Toolbox on RHEL 9, rebasing it to version 0.0.99.5-2.el9. The update remediated Go html/template flaws CVE-2023-39318 and CVE-2023-39319 and the HTTP request resource-consumption denial-of-service flaw CVE-2023-39326.
Robb Gatica described CVE-2023-45289, a Go net/http/cookiejar redirect-handling flaw that could cause Authorization and Cookie headers to be forwarded to an attacker-controlled domain. The issue was tracked by the Go project as issue 65065.
Red Hat issued Moderate advisory RHSA-2023:6346 for Toolbox on RHEL 9, providing Toolbox 0.0.99.4-6.el9_3. The update remediated ten Go-component flaws involving YAML, HPACK, multipart and textproto resource exhaustion, HTML-template sanitization and JavaScript handling, and HTTP Host-header sanitization.
Red Hat issued Moderate advisory RHSA-2023:5867 for Grafana on RHEL 9, providing grafana-9.0.9-4.el9_2. The update remediated CVE-2023-44487, the HTTP/2 Rapid Reset denial-of-service flaw, and CVE-2023-39325, involving excessive work from rapid HTTP/2 stream resets in Go.
Red Hat issued Moderate advisory RHSA-2023:5866 for Grafana on RHEL 9.0 support offerings, providing grafana-7.5.11-6.el9_0. The update remediated CVE-2023-44487, the HTTP/2 Rapid Reset denial-of-service vulnerability, and CVE-2023-39325, involving excessive Go HTTP/2 stream-reset processing.
Red Hat issued Moderate advisory RHSA-2023:2283 for Skopeo on RHEL 9, providing skopeo-1.11.2-0.1.el9 across supported architectures. The update remediated CVE-2022-41717, excessive HTTP/2 server memory growth in Go net/http, and CVE-2022-30629, insufficient randomness in Go crypto/tls session-ticket ticket_age_add values.
Red Hat issued Moderate advisory RHSA-2023:2193 for Butane on RHEL 9, upgrading it to butane-0.16.0-1.el9 across supported architectures. The update remediated CVE-2022-27664, involving Go net/http server shutdown after GOAWAY, and CVE-2022-32189, a math/big decoding panic that could cause denial of service.
Red Hat issued Moderate advisory RHSA-2023:2236 for Toolbox on RHEL 9, providing toolbox-0.0.99.3-9.el9 for supported architectures. The update remediated Go HTTP/2 GOAWAY shutdown and memory-growth denial-of-service flaws plus a math/big decoding panic vulnerability, and fixed duplicate entries in `toolbox list`.
Red Hat issued Moderate advisory RHSA-2023:2357 for git-lfs on RHEL 9, rebasing it to version 3.2.0-1.el9. The update remediated ten Go-component vulnerabilities affecting HTTP request and reverse-proxy handling, stack exhaustion, regular-expression and HTTP/2 memory consumption, and math/big decoding denial of service.
Red Hat issued Moderate advisory RHSA-2023:2167 for Grafana on RHEL 9, providing Grafana 9.0.9-2.el9. The update remediated two Grafana flaws involving authentication-proxy privilege escalation and email-username sign-in denial, plus three Go vulnerabilities in ReverseProxy, HTTP/2 GOAWAY handling, and regexp parsing.
Red Hat issued Moderate advisory RHSA-2023:0407 for OpenShift Virtualization 4.12.0 (also listed as Red Hat Container Native Virtualization 4.12), providing kubevirt and kubevirt-virtctl 4.12.0-1057 RPMs for RHEL 7 and RHEL 8 x86_64. The update remediated 14 Go vulnerabilities affecting HTTP handling, X-Forwarded-For behavior, TLS ticket randomness, file-descriptor handling, and multiple denial-of-service and stack-exhaustion conditions.
Red Hat issued Low-severity advisory RHSA-2022:8932 for OpenShift Serverless Client kn 1.26.0 on RHEL 8. The openshift-serverless-clients-1.5.0-3.el8 update for x86_64, ppc64le, and s390x remediated CVE-2022-27191, through which golang.org/x/crypto/ssh could allow an SSH server to crash.
Red Hat issued Important advisory RHSA-2022:8057 for Grafana on RHEL 9, providing Grafana 7.5.15-3.el9. The update remediated Grafana XSS, CSRF privilege-escalation, IDOR information-disclosure, and OAuth flaws, as well as multiple Go denial-of-service and stack-exhaustion vulnerabilities.
Red Hat issued Moderate advisory RHSA-2022:8250 for grafana-pcp on RHEL 9, providing grafana-pcp-3.2.0-3.el9. The update remediated six Go vulnerabilities, including Transfer-Encoding request smuggling, ReverseProxy X-Forwarded-For handling, and four stack-exhaustion denial-of-service flaws.
Red Hat issued Moderate advisory RHSA-2022:8098 for Toolbox on RHEL 9, providing toolbox-0.0.99.3-5.el9 across supported architectures. The update remediated Go Transfer-Encoding sanitization flaw CVE-2022-1705 and stack-exhaustion flaws CVE-2022-30630, CVE-2022-30631, and CVE-2022-30632.
Red Hat issued Moderate advisory RHSA-2022:7519 for Grafana on RHEL 8, upgrading the package to grafana-7.5.15-3.el8. The update remediated 15 Grafana and bundled-component flaws, including OAuth data-source access, XSS, CSRF privilege escalation, IDOR information disclosure, Prometheus client_golang denial of service, and multiple Go request-handling and stack-exhaustion issues.
Red Hat issued Moderate advisory RHSA-2022:7129 for git-lfs on RHEL 8, providing git-lfs-2.13.3-3.el8_6 rebuilt with Go 1.17.7 or later. The update remediated nine Go and golang.org/x/text vulnerabilities, including Transfer-Encoding request smuggling, HTTP/2 GOAWAY handling, reverse-proxy X-Forwarded-For handling, parser panics, and stack-exhaustion denial of service flaws.
Red Hat issued Moderate advisory RHSA-2022:6370 for Red Hat Advanced Cluster Management for Kubernetes 2.6.0 on RHEL 8 x86_64. The release remediated Moment parsing denial of service and multiple Go flaws involving TLS ticket randomness, Transfer-Encoding handling, ReverseProxy X-Forwarded-For behavior, and stack exhaustion.
Red Hat reported Bug 2124669 for CVE-2022-27664, a medium-severity Go HTTP/2 server flaw where a connection closing after GOAWAY can hang indefinitely if a subsequent fatal error interrupts shutdown, enabling denial of service. Upstream fixed the issue in Go 1.18.6 and 1.19.1.
Red Hat issued bug-fix advisory RHBA-2022:6131 for CodeReady Workspaces 2.0 container images, backporting fixes for multiple Go vulnerabilities, including Transfer-Encoding request smuggling, X-Forwarded-For handling, and stack-exhaustion denial-of-service flaws. Users were advised to obtain the revised images, update Dockerfile or script references, and rebuild dependent images.
Red Hat issued Important advisory RHSA-2022:6042 for OpenShift Serverless Client kn 1.24.0 on RHEL 8 for x86_64, ppc64le, and s390x. The openshift-serverless-clients-1.3.1-4.el8 update remediated 15 Go, go-restful, and prometheus/client_golang flaws, including authorization bypass, request-header handling, TLS ticket randomness, panics, and stack-exhaustion denial of service.
Red Hat issued RHSA-2022:6040 for affected OpenShift Serverless 1.24 components on RHEL 8, including client-kn, eventing receive-adapter and controller, and in-memory and Kafka-broker channel components. The update remediated CVE-2022-30630, in which a separator-heavy path supplied to Go io/fs.Glob could exhaust the stack and panic an application.
Red Hat issued bug-fix advisory RHBA-2022:5800 for the codeready-workspaces/stacks-golang-rhel8 image in CodeReady Workspaces 2.0. The updated image backported fixes for multiple Go flaws covered by RHSA-2022:5775, and Red Hat advised users to upgrade and rebuild dependent container images.
Anten Skrabec reported Red Hat Bug 2107392 for CVE-2022-30633, a Go encoding/xml flaw in which crafted XML unmarshalled into a nested field using the any XML tag can recurse without bound, exhaust the stack, and panic an affected application. Red Hat also created Fedora and EPEL tracking bugs and later issued fixes across affected products.
Anten Skrabec reported Red Hat Bug 2107342 for CVE-2022-30631, a medium-severity Go compress/gzip Reader.Read flaw. An archive with many concatenated zero-length compressed files could recursively exhaust the stack, panic a Go program, and cause denial of service; Go fixed it in versions 1.18.4 and 1.17.12.
Anten Skrabec reported Red Hat Bug 2107386 for CVE-2022-30632, a medium-severity Go path/filepath.Glob flaw in which a path containing many separators can exhaust the stack and panic. Go fixed the issue in versions 1.18.4 and 1.17.12.
Anten Skrabec reported Red Hat Bug 2107371 for CVE-2022-30630, a medium-severity Go io/fs Glob flaw where a path with many separators can exhaust the stack and panic. Go fixed the issue in versions 1.18.4 and 1.17.12.
Anten Skrabec reported Red Hat Bug 2107374 for CVE-2022-1705, a medium-severity Go net/http flaw in which the HTTP/1 client could treat malformed Transfer-Encoding values as chunked encoding. In combination with an intermediary that also accepts the malformed header, the issue could enable HTTP request smuggling; Go fixed it in versions 1.18.4 and 1.17.12.
Go released versions 1.18.3 and 1.17.11 to fix CVE-2022-30629 in crypto/tls. TLS session tickets had used a non-random ticket_age_add value, allowing an observer of TLS handshakes to correlate a client's successive resumed connections.
CVE-2022-24921 was made public as a Go regexp-module stack-overflow flaw. An unauthenticated attacker could submit a sufficiently large, deeply nested regular expression to an application accepting untrusted expressions, crashing the Go runtime and causing denial of service.
Mauro Matteo Cascella reported Red Hat Bugzilla bug 2050743 for CVE-2022-21713, an IDOR vulnerability in Grafana Teams API endpoints that could let an authenticated attacker access unauthorized team data and enumerate teams. Grafana fixed the issue in versions 7.5.15 and 8.3.5.
Red Hat issued RHSA-2022:0308 to remediate CVE-2021-31525 in the heketi component of Red Hat Storage Native Client for RHEL 7. The Go net/http flaw could cause a denial-of-service crash when processing exceptionally large HTTP header values.
Red Hat issued Moderate advisory RHSA-2021:3555 for OpenShift Serverless Client kn 1.17.0 on RHEL 8. The openshift-serverless-clients-0.23.2-1.el8 update fixed incomplete Serverless remediation tracked as CVE-2021-3703 and four Go flaws affecting TLS certificates, hostname validation, ReverseProxy connection-header forwarding, and math/big.Rat exponent handling.
Red Hat issued RHSA-2021:3556 to remediate CVE-2021-33197 in affected OpenShift Serverless 1.17 components, including eventing receive-adapter, controller, in-memory channel, multi-tenant broker, and storage-version-migration packages. The Go net/http/httputil.ReverseProxy flaw could let a remote unauthenticated attacker use an empty first Connection header to cause connection-specific headers to be forwarded or arbitrary HTTP headers to be removed.
Paramvir Jindal reported Red Hat Bug 1992955 for CVE-2021-3703, finding that Serverless 1.16.0 and Knative client 1.16.0 advisories had incorrectly stated fixes for CVE-2021-27918, CVE-2021-31525, and CVE-2021-33196. The affected Knative CLI used an older Go version, while Red Hat determined Knative Serving and Eventing were not affected.
Guilherme de Almeida Suckevicz recorded CVE-2021-33197, in which Go net/http/httputil.ReverseProxy could forward connection headers when the first such header was empty, creating an unintended proxy or intermediary issue. The flaw affected Go versions before 1.15.12 and Go 1.16.x before 1.16.5 and was tracked upstream as Go issue 46313.
Guilherme de Almeida Suckevicz reported CVE-2021-33198, a Go math/big.Rat vulnerability in which inputs with very large exponents can cause excessive memory allocation, potentially resulting in denial of service. The issue affected Go versions before 1.15.12 and Go 1.16.x before 1.16.5, and was tracked upstream as Go issue 44910.
Dhananjay Arunesh reported Red Hat Bug 1983596 for CVE-2021-34558, a medium-severity Go crypto/tls flaw in which a network-positioned attacker could present a certificate with an incorrect public-key type and panic affected TLS or HTTPS clients. Go fixed the unsafe RSA public-key type assertion in versions 1.15.14, 1.16.6, and 1.17.0.
Red Hat issued RHSA-2021:2705 to remediate CVE-2021-33196 in listed OpenShift Serverless 1.16 components, including client-kn-rhel8 and Eventing components. It provided no update for Service Telemetry Framework 1.2 smart-gateway-container and sg-core-container because the product was nearing retirement and impact was assessed as low.
Red Hat issued Moderate advisory RHSA-2021:2704 for OpenShift Serverless Client kn 1.16.0 on RHEL 8. The openshift-serverless-clients-0.22.0-3.el8 update remediated Go encoding/xml infinite-loop, net/http large-header panic, and archive/zip malformed-ZIP panic or memory-exhaustion vulnerabilities.
CVE-2021-27918 was publicly disclosed as a Moderate-severity denial-of-service flaw in Go encoding/xml. A crafted XML document with an EOF condition can cause infinite parsing when an application uses a custom token parser initialized through xml.NewTokenDecoder.
Red Hat published CVE-2021-33198, a moderate-severity denial-of-service vulnerability in Go math/big.Rat. Inputs containing very large exponents could cause excessive memory allocation, leading to a panic or unrecoverable fatal error.
Red Hat released Important-security-impact advisory RHSA-2022:6308 for OpenShift Container Platform 4.8.49, delivering updated container images for x86_64, s390x, and ppc64le. The update remediated Go gzip stack exhaustion (CVE-2022-30631), a Grafana snapshot authentication bypass, and four go-getter command-injection or unsafe-download vulnerabilities.
Red Hat addressed CVE-2021-27918 through RHSA-2021:2705 for OpenShift Serverless 1.16 and RHSA-2021:3076 for RHEL 8. The flaw could cause infinite loops when applications used xml.NewTokenDecoder with a custom TokenReader that returned EOF within an XML element.
Red Hat addressed CVE-2026-33818, in which deeply nested recursive structures processed by Go encoding/asn1 Unmarshal can exhaust the stack. The remediation adds an Unmarshal recursion limit and was released for RHEL 8 through RHSA-2026:60305 and RHEL 10 through RHSA-2026:60306.
Red Hat tracked CVE-2026-56862, in which a malicious TLS client can repeatedly send KeyUpdate messages before handshake completion, causing indefinite key-derivation work and resource-exhaustion denial of service. Red Hat addressed the flaw through RHSA-2026:60305 for RHEL 8, RHSA-2026:60304 for RHEL 9, and RHSA-2026:60306 for RHEL 10.
Red Hat documented CVE-2026-56853, in which Go net/http servers configured for unencrypted HTTP/2 do not apply ReadHeaderTimeout while reading bytes to detect an HTTP/2 client preface, allowing denial of service. Red Hat remediated the issue for RHEL 8, 9, and 10 through RHSA-2026:60305, RHSA-2026:60304, and RHSA-2026:60306, respectively.
Red Hat closed tracking bug 2045880 for CVE-2022-21698, a denial-of-service flaw in Prometheus client_golang's promhttp.InstrumentHandlerCounter function affecting versions before 1.11.1. Upstream fixed the issue on its main and release-1.11 branches, and Red Hat issued remediation advisories across RHEL, OpenShift, OpenStack, and related products.
Red Hat documented CVE-2024-9355, in which specific FIPS-mode Go toolchain builds can intermittently return a zero-filled buffer from boringHMAC.Sum() because of an uninitialized CGO buffer-length variable. The issue can enable false-positive HMAC comparisons or all-zero derived keys, although OpenSSL bounds checks prevent it from being a buffer-overflow vulnerability.
Red Hat Product Security DevOps closed tracking bug 2107383 for CVE-2022-32148, in which Go httputil.ReverseProxy could add the client IP to X-Forwarded-For when the request header map contained a nil value, contrary to documented behavior. Red Hat had issued fixes across RHEL, OpenShift, OpenStack, Ceph, and other products, with later updates to be reflected on the CVE page.
Red Hat Product Security DevOps closed its tracking bug for CVE-2021-38561, an out-of-bounds-read panic in golang.org/x/text language-tag parsing that could enable denial of service when applications parse attacker-controlled input. Red Hat had issued fixes across affected OpenShift, OpenShift Logging, Advanced Cluster Management, and Container Native Virtualization product streams.
Red Hat Product Security DevOps closed Bugzilla tracking bug 2064857 for CVE-2022-24921. The flaw in Go's regexp.Compile could allow deeply nested expressions to exhaust the stack and cause denial of service; Red Hat directed subsequent product-specific status to the CVE page.
Red Hat closed Bugzilla bug 2050742 for CVE-2022-21703, a Grafana cross-site request forgery flaw through which an anonymous attacker could trick an authenticated Editor or Administrator into inviting the attacker as a privileged user. Grafana fixed the issue in versions 7.5.15 and 8.3.5, and Red Hat had remediated it for RHEL 8 and RHEL 9.
Red Hat tracked CVE-2022-27191, a denial-of-service flaw that can crash a golang.org/x/crypto/ssh server when a configured ssh-rsa host-key Signer does not implement AlgorithmSigner. Red Hat created Fedora and EPEL tracking bugs for numerous affected packages and later directed product-specific remediation status to the CVE page.
Red Hat Product Security DevOps closed tracking bug 2163037 for CVE-2022-3064, a go-yaml/yaml flaw through which malicious or large YAML documents could exhaust CPU or memory. Red Hat had addressed the issue across supported OpenShift, OpenStack, and RHEL product versions, with subsequent product-specific updates to be reflected on the CVE page.
Red Hat issued Important advisory RHSA-2022:5799, updating go-toolset and golang packages for RHEL 9 to Go 1.17.12. The update remediated Transfer-Encoding and X-Forwarded-For handling flaws along with stack-exhaustion denial-of-service vulnerabilities in Go parsing, globbing, gzip, XML, and gob-decoding functions.
Red Hat issued Important advisory RHSA-2022:5775 for the go-toolset:rhel8 module, updating Go Toolset and Golang packages to version 1.17.12. The update remediated Transfer-Encoding sanitization, X-Forwarded-For handling, and multiple stack-exhaustion denial-of-service flaws in Go parsing, gzip, XML, gob decoding, and filesystem globbing functions.
Red Hat issued Important advisory RHSA-2022:5866 for go-toolset-1.17 and go-toolset-1.17-golang in Red Hat Developer Tools 1, providing Go 1.17.12-1.el7_9 packages for RHEL 7 architectures. The update remediated Transfer-Encoding and X-Forwarded-For handling flaws and multiple stack-exhaustion denial-of-service vulnerabilities in Go parsing, gzip, XML, filesystem globbing, and gob decoding.
Red Hat released Moderate-security-impact advisory RHSA-2022:0056 for OpenShift Container Platform 4.10.3, providing updated packages and container images for x86_64, s390x, and ppc64le. The update remediated vulnerabilities in gogo/protobuf, Grafana, Go net/http and syscall, and nodejs-axios, including authentication-bypass, directory-traversal, denial-of-service, and input-validation flaws.
Red Hat documented CVE-2021-31525, in which exceptionally large HTTP headers can cause an unrecoverable panic in Go net/http ReadRequest or ReadResponse processing. The flaw can let a malicious server crash vulnerable Go clients, while servers are affected only if Server.MaxHeaderBytes is raised above the default safe limit; Red Hat issued remediation advisories across OpenShift, RHEL, OpenStack, Gluster Storage, CNV, and Serverless products.
Red Hat tracked CVE-2021-33196, in which a malformed ZIP archive declaring a very large number of files can cause Go archive/zip's zip.NewReader to panic or exhaust memory because of a pre-allocation optimization. Red Hat assessed most identified OpenShift uses as low impact and issued remediation advisories for Developer Tools, RHEL 8, OpenShift products, OpenShift Jaeger, and Migration Toolkit for Containers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
50 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcedocs.openshift.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.