[ALSA-2026:63124] Important: grafana-pcp security update
Type:
security
Severity:
important
Release date:
2026-09-04
Description:
The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards. Security Fix(es): * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 grafana-pcp-5.1.1-18.el8_10.aarch64.rpm 9f6457919132a319647a79b5b5caa683858981aa2e11ad385a05e13ae319e4f6
ppc64le grafana-pcp-5.1.1-18.el8_10.ppc64le.rpm 5ad9f64655eccc5fb5fe7925e0a251517ba83e80c367526e0ff4e979fd92af89
s390x grafana-pcp-5.1.1-18.el8_10.s390x.rpm 97ad5cd1d3f1a092c6ad1d16ec9137f2e8cc2ed8fe5972f6100720f75f4533eb
x86_64 grafana-pcp-5.1.1-18.el8_10.x86_64.rpm 420e13d7a1e225ea0ce5b661d6714b31f053daa3eb76bda0d1c8c31c9889b8b1
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.