Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:34359

Опубликовано: 05 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: opentelemetry-collector security update

Collector with the supported components for a Rocky Enterprise Software Foundation build of OpenTelemetry

Security Fix(es):

  • github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint (CVE-2026-42154)

  • github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API (CVE-2026-42151)

  • net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)

  • golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)

  • golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)

  • crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
opentelemetry-collectorx86_641.el9_8opentelemetry-collector-0.152.1-1.el9_8.x86_64.rpm

Показывать по

Связанные уязвимости

rocky
24 дня назад

Important: opentelemetry-collector security update

CVSS3: 6.1
ubuntu
2 месяца назад

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS3: 8.1
redhat
2 месяца назад

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS3: 6.1
nvd
2 месяца назад

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

CVSS3: 6.1
msrc
2 месяца назад

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html