Description:
The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards.
Security Fix(es):
* mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
* encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
* net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
* net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
* html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
* crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| aarch64 |
grafana-pcp-5.1.1-18.el8_10.aarch64.rpm |
9f6457919132a319647a79b5b5caa683858981aa2e11ad385a05e13ae319e4f6 |
| ppc64le |
grafana-pcp-5.1.1-18.el8_10.ppc64le.rpm |
5ad9f64655eccc5fb5fe7925e0a251517ba83e80c367526e0ff4e979fd92af89 |
| s390x |
grafana-pcp-5.1.1-18.el8_10.s390x.rpm |
97ad5cd1d3f1a092c6ad1d16ec9137f2e8cc2ed8fe5972f6100720f75f4533eb |
| x86_64 |
grafana-pcp-5.1.1-18.el8_10.x86_64.rpm |
420e13d7a1e225ea0ce5b661d6714b31f053daa3eb76bda0d1c8c31c9889b8b1 |