[ALSA-2026:62406] Important: grafana security update
Type:
security
Severity:
important
Release date:
2026-09-04
Description:
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 grafana-10.2.6-23.el9_8.3.aarch64.rpm 0b6d360ee11bad9c59359e613a947b87b94ee63b675f6a3b96d25e92e92feb7d
aarch64 grafana-selinux-10.2.6-23.el9_8.3.aarch64.rpm d81338b3fa76d194c1aa6eebc07a26bc397253ba6569b554bc68a4db4b0e36ff
ppc64le grafana-10.2.6-23.el9_8.3.ppc64le.rpm 2f8348a143d915d98c7e7218849831a6199fcf80905d326fb81f531c771d5885
ppc64le grafana-selinux-10.2.6-23.el9_8.3.ppc64le.rpm 600d258da0d0cbb881a1a18e248f11fecd0a516e7353c0ed05d5aa8c0be5a2e4
s390x grafana-10.2.6-23.el9_8.3.s390x.rpm 8ad4f4d1421c5f990224e2cf7d7ae4f7034e56606ddfb931b1ef26ec1b008786
s390x grafana-selinux-10.2.6-23.el9_8.3.s390x.rpm d8ee6bc0ff4505bbde6bb73bb3dbe07f6084ad1c7b7ab52e466e61fabb0a1a30
x86_64 grafana-10.2.6-23.el9_8.3.x86_64.rpm 2135c5e42cfb4a96dd020cf16055ecf015786a1e12e9744d5412c2f2830cd72f
x86_64 grafana-selinux-10.2.6-23.el9_8.3.x86_64.rpm 33edca33386c44bf97935360a87bd21bc7e6ff828b79e3e97f0bc7db9fe772e3
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.