RHSA-2026:67517
Advisory lineage Upstream: 19 Downstream: 0
Published: 16 Sept 2026, 10:14
Last modified:19 Sept 2026, 10:13
Vulnerability Summary
Overall Risk (default)
medium
35/100 CVSS Score
8.8 HIGH
3.1 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
16 Sept 2026, 10:14
Published
Vulnerability first disclosed
19 Sept 2026, 10:13
Last Modified
Vulnerability information updated
Description
Red Hat Security Advisory: grafana security update
CVSS Metrics
- v3.1•HIGH•Score: 8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L
Affected Systems
- redhat•grafana
< 0:10.2.6-26.el10_0
- redhat•grafana-debuginfo
< 0:10.2.6-26.el10_0
- redhat•grafana-debugsource
< 0:10.2.6-26.el10_0
- redhat•grafana-selinux
< 0:10.2.6-26.el10_0
References (131)
- https://access.redhat.com/errata/RHSA-2026:67517
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2445345
- https://bugzilla.redhat.com/show_bug.cgi?id=2456335
- https://bugzilla.redhat.com/show_bug.cgi?id=2467809
- https://bugzilla.redhat.com/show_bug.cgi?id=2467820
- https://bugzilla.redhat.com/show_bug.cgi?id=2477246
- https://bugzilla.redhat.com/show_bug.cgi?id=2477262
- https://bugzilla.redhat.com/show_bug.cgi?id=2480756
- https://bugzilla.redhat.com/show_bug.cgi?id=2480757
- https://bugzilla.redhat.com/show_bug.cgi?id=2480761
- https://bugzilla.redhat.com/show_bug.cgi?id=2480762
- https://bugzilla.redhat.com/show_bug.cgi?id=2499061
- https://bugzilla.redhat.com/show_bug.cgi?id=2499062
- https://bugzilla.redhat.com/show_bug.cgi?id=2515815
- https://bugzilla.redhat.com/show_bug.cgi?id=2515820
- https://bugzilla.redhat.com/show_bug.cgi?id=2515827
- https://bugzilla.redhat.com/show_bug.cgi?id=2515838
- https://bugzilla.redhat.com/show_bug.cgi?id=2515839
- https://bugzilla.redhat.com/show_bug.cgi?id=2515840
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_67517.json
- https://access.redhat.com/security/cve/CVE-2026-8609
- https://www.cve.org/CVERecord?id=CVE-2026-8609
- https://nvd.nist.gov/vuln/detail/CVE-2026-8609
- https://grafana.com/security/security-advisories/cve-2026-8609
- https://access.redhat.com/security/cve/CVE-2026-25681
- https://www.cve.org/CVERecord?id=CVE-2026-25681
- https://nvd.nist.gov/vuln/detail/CVE-2026-25681
- https://go.dev/cl/781703
- https://go.dev/issue/79574
- https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
- https://pkg.go.dev/vuln/GO-2026-5029
- https://access.redhat.com/security/cve/CVE-2026-27136
- https://www.cve.org/CVERecord?id=CVE-2026-27136
- https://nvd.nist.gov/vuln/detail/CVE-2026-27136
- https://go.dev/cl/781685
- https://go.dev/issue/79575
- https://pkg.go.dev/vuln/GO-2026-5030
- https://access.redhat.com/security/cve/CVE-2026-27137
- https://www.cve.org/CVERecord?id=CVE-2026-27137
- https://nvd.nist.gov/vuln/detail/CVE-2026-27137
- https://go.dev/cl/752182
- https://go.dev/issue/77952
- https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk
- https://pkg.go.dev/vuln/GO-2026-4599
- https://access.redhat.com/security/cve/CVE-2026-33376
- https://www.cve.org/CVERecord?id=CVE-2026-33376
- https://nvd.nist.gov/vuln/detail/CVE-2026-33376
- https://grafana.com/security/security-advisories/cve-2026-33376
- https://access.redhat.com/security/cve/CVE-2026-33377
- https://www.cve.org/CVERecord?id=CVE-2026-33377
- https://nvd.nist.gov/vuln/detail/CVE-2026-33377
- https://grafana.com/security/security-advisories/cve-2026-33377
- https://access.redhat.com/security/cve/CVE-2026-33382
- https://www.cve.org/CVERecord?id=CVE-2026-33382
- https://nvd.nist.gov/vuln/detail/CVE-2026-33382
- https://grafana.com/security/security-advisories/cve-2026-33382
- https://access.redhat.com/security/cve/CVE-2026-33810
- https://www.cve.org/CVERecord?id=CVE-2026-33810
- https://nvd.nist.gov/vuln/detail/CVE-2026-33810
- https://go.dev/cl/763763
- https://go.dev/issue/78332
- https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU
- https://pkg.go.dev/vuln/GO-2026-4866
- https://access.redhat.com/security/cve/CVE-2026-33818
- https://www.cve.org/CVERecord?id=CVE-2026-33818
- https://nvd.nist.gov/vuln/detail/CVE-2026-33818
- https://go.dev/cl/814980
- https://go.dev/issue/80405
- https://groups.google.com/g/golang-announce/c/94pEornpRlI
- https://pkg.go.dev/vuln/GO-2026-5972
- https://access.redhat.com/security/cve/CVE-2026-39820
- https://www.cve.org/CVERecord?id=CVE-2026-39820
- https://nvd.nist.gov/vuln/detail/CVE-2026-39820
- https://go.dev/cl/759940
- https://go.dev/issue/78566
- https://groups.google.com/g/golang-announce/c/qcCIEXso47M
- https://pkg.go.dev/vuln/GO-2026-4986
- https://access.redhat.com/security/cve/CVE-2026-39821
- https://www.cve.org/CVERecord?id=CVE-2026-39821
- https://nvd.nist.gov/vuln/detail/CVE-2026-39821
- https://go.dev/cl/767220
- https://go.dev/issue/78760
- https://pkg.go.dev/vuln/GO-2026-5026
- https://access.redhat.com/security/cve/CVE-2026-42127
- https://bugzilla.redhat.com/show_bug.cgi?id=2491449
- https://www.cve.org/CVERecord?id=CVE-2026-42127
- https://nvd.nist.gov/vuln/detail/CVE-2026-42127
- https://grafana.com/security/security-advisories/cve-2026-42127
- https://access.redhat.com/security/cve/CVE-2026-42499
- https://www.cve.org/CVERecord?id=CVE-2026-42499
- https://nvd.nist.gov/vuln/detail/CVE-2026-42499
- https://go.dev/cl/771520
- https://go.dev/issue/78987
- https://pkg.go.dev/vuln/GO-2026-4977
- https://access.redhat.com/security/cve/CVE-2026-42502
- https://www.cve.org/CVERecord?id=CVE-2026-42502
- https://nvd.nist.gov/vuln/detail/CVE-2026-42502
- https://go.dev/cl/781701
- https://go.dev/issue/79572
- https://pkg.go.dev/vuln/GO-2026-5027
- https://access.redhat.com/security/cve/CVE-2026-56853
- https://www.cve.org/CVERecord?id=CVE-2026-56853
- https://nvd.nist.gov/vuln/detail/CVE-2026-56853
- https://go.dev/cl/795540
- https://go.dev/issue/80205
- https://pkg.go.dev/vuln/GO-2026-6089
- https://access.redhat.com/security/cve/CVE-2026-56858
- https://www.cve.org/CVERecord?id=CVE-2026-56858
- https://nvd.nist.gov/vuln/detail/CVE-2026-56858
- https://go.dev/cl/807100
- https://go.dev/issue/80435
- https://pkg.go.dev/vuln/GO-2026-6091
- https://access.redhat.com/security/cve/CVE-2026-56859
- https://www.cve.org/CVERecord?id=CVE-2026-56859
- https://nvd.nist.gov/vuln/detail/CVE-2026-56859
- https://go.dev/cl/803320
- https://go.dev/issue/80481
- https://pkg.go.dev/vuln/GO-2026-6088
- https://access.redhat.com/security/cve/CVE-2026-56860
- https://www.cve.org/CVERecord?id=CVE-2026-56860
- https://nvd.nist.gov/vuln/detail/CVE-2026-56860
- https://go.dev/cl/803681
- https://go.dev/issue/80494
- https://pkg.go.dev/vuln/GO-2026-6218
- https://access.redhat.com/security/cve/CVE-2026-56862
- https://www.cve.org/CVERecord?id=CVE-2026-56862
- https://nvd.nist.gov/vuln/detail/CVE-2026-56862
- https://go.dev/cl/804261
- https://go.dev/issue/80528
- https://pkg.go.dev/vuln/GO-2026-6090