[ALSA-2026:63022] Important: grafana security update
Type:
security
Severity:
important
Release date:
2026-09-04
Description:
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 grafana-selinux-10.2.6-28.el10_2.5.aarch64.rpm 7f196888ac72fba3281b39d9f563f4d7e032f4263ec060fb2b762187f5d5b5ed
aarch64 grafana-10.2.6-28.el10_2.5.aarch64.rpm 90dbee124f568b825f0c76fa3af854360f8e307313962d083bffb693e6a97be4
ppc64le grafana-10.2.6-28.el10_2.5.ppc64le.rpm bf6cd86ddaae915eac81cc434f940622df5ba6c6e153c3b2b699ebc75f577257
ppc64le grafana-selinux-10.2.6-28.el10_2.5.ppc64le.rpm d6c1ead704d4e9a539490855107e15ea10585f9ea7c782917ecfee933e4565cd
s390x grafana-selinux-10.2.6-28.el10_2.5.s390x.rpm 1b3bf0f55eeeafe18b361a56f713909074402c490822d28268b1d795217c8b15
s390x grafana-10.2.6-28.el10_2.5.s390x.rpm a88a2cb85f2fc7d07fe5d73b3e309a3f4ddf6e061c74ca2158f948fdfc1359e6
x86_64 grafana-selinux-10.2.6-28.el10_2.5.x86_64.rpm 4bb69e7d7f3a939bfe6c072210b288eef2c413cf1fcc12890f8052c0ee2c6e4c
x86_64 grafana-10.2.6-28.el10_2.5.x86_64.rpm ce286716719c3207341351138103803c02a89d831f2ebd339ea2f16d61fff0b6
x86_64_v2 grafana-selinux-10.2.6-28.el10_2.5.x86_64_v2.rpm 784505e71a9a19a2ece531afe2604f4137169e25ded4964a7c955dda7d86aa67
x86_64_v2 grafana-10.2.6-28.el10_2.5.x86_64_v2.rpm 9b58891106e4b6b72aacf4babac72cc860581dca726fa96db8e5cce3bd3f854d
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.