[ALSA-2026:63119] Important: grafana-pcp security update
Type:
security
Severity:
important
Release date:
2026-09-04
Description:
The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards. Security Fix(es): * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 grafana-pcp-5.3.0-8.el10_2.1.aarch64.rpm e0ab7c490c4806c3a937ffa5553df06e809921816ca8972325393458b356ae78
ppc64le grafana-pcp-5.3.0-8.el10_2.1.ppc64le.rpm 443da1199121e4ce3d7b36dc316887714f551595ba5a9dc1c044e8394f41c577
s390x grafana-pcp-5.3.0-8.el10_2.1.s390x.rpm 0c62413d1bfe1afbac1dac3e3fc3f59e4dbd22bbc935a3c1b2c9371051c8e849
x86_64 grafana-pcp-5.3.0-8.el10_2.1.x86_64.rpm 16e36c641aa867ee6968f3cebef1f99dd436044267a6771f780746ec8417b135
x86_64_v2 grafana-pcp-5.3.0-8.el10_2.1.x86_64_v2.rpm 631909a235b66efb2f5ba57d98a6d9a5c55b5c2b5215072d750273ecf885ead5
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.