RHSA-2026:28010: Important: Red Hat build of Cryostat security update
An update is now available for the Red Hat build of Cryostat 4 on RHEL 9.Security Fix(es): DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization (CVE-2026-41240) crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) shell-quote: Arbitrary code execution via command injection due to unescaped line terminators (CVE-2026-9277) Apache Thrift: Security bypass due to improper certificate validation (CVE-2026-43869) Netty: High integrity impact due to improper DNS domain name constraint enforcement (CVE-2026-42579) Netty: Incorrect HTTP response parsing leads to data confusion (CVE-2026-42584) Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers (CVE-2026-42581) Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation (CVE-2026-42578) Netty: Denial of Service via unbounded memory allocation in HTTP content decompression (CVE-2026-42587) Apache Thrift cglib: Denial of Service via specially crafted requests (CVE-2025-48431) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: Red Hat build of Cryostat security update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Red Hat build of Cryostat on RHEL 9to a version that resolves this vulnerability.Fixed in 4 - Operational
Before applying this update, make sure all previously released errata relevant to your system have been applied.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:28010?
The severity of RHSA-2026:28010 is rated as high with a score of 7.
How do I fix RHSA-2026:28010?
To fix RHSA-2026:28010, apply the latest security update for the Red Hat build of Cryostat 4 on RHEL 9.
What vulnerabilities are addressed in RHSA-2026:28010?
RHSA-2026:28010 addresses vulnerabilities including Cross-Site Scripting (CVE-2026-41240) and Denial of Service (CVE-2026-32281).
What is the risk associated with RHSA-2026:28010?
The risk associated with RHSA-2026:28010 is classified as 33, indicating a significant potential impact.
What software is affected by RHSA-2026:28010?
The affected software by RHSA-2026:28010 is the Red Hat Cryostat.