[ALSA-2026:63136] Important: grafana-pcp security update
Type:
security
Severity:
important
Release date:
2026-09-08
Description:
The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards. Security Fix(es): * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 grafana-pcp-5.1.1-17.el9_8.1.aarch64.rpm ec42c7b9c0dd70bcc9fb298baa838ccc55eaa9aff140a29423d5f4fb120fe211
ppc64le grafana-pcp-5.1.1-17.el9_8.1.ppc64le.rpm 0182a76cf95619fc2f6207bae3b23f77a593056f6d115a8f0aa2330430114d0c
s390x grafana-pcp-5.1.1-17.el9_8.1.s390x.rpm 01d7585e7932ece1454a9b0be72d92735ad98937bb89489c2851cd4dfd37ea97
x86_64 grafana-pcp-5.1.1-17.el9_8.1.x86_64.rpm 00ab7bf988973722bbf5cb9e498648808e450626e31be42c9ad9376a1df9a8dd
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.