RHSA-2026:1845: Important: Red Hat build of Cryostat security update
An update is now available for the Red Hat build of Cryostat 4 on RHEL 9.Security Fix(es): lodash: prototype pollution in .unset and .omit functions (CVE-2025-13465) crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: Red Hat build of Cryostat security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What security issues are addressed in RHSA-2026:1845?
RHSA-2026:1845 addresses prototype pollution vulnerabilities in lodash and a Denial of Service issue in Go's x509 package.
How can I mitigate the vulnerabilities described in RHSA-2026:1845?
You can mitigate the vulnerabilities by updating to the latest version of the Red Hat build of Cryostat.
What versions of Cryostat are affected by RHSA-2026:1845?
The RHSA-2026:1845 advisory affects the Red Hat build of Cryostat 4 on RHEL 9.
Are there any known exploits for the vulnerabilities fixed in RHSA-2026:1845?
As of now, there are no publicly disclosed exploits specifically targeting the vulnerabilities fixed in RHSA-2026:1845.
What is the impact of not addressing the vulnerabilities in RHSA-2026:1845?
Failing to address the vulnerabilities in RHSA-2026:1845 could lead to attacks leveraging prototype pollution and potential Denial of Service.