RHSA-2026:48151: Important: Red Hat build of Cryostat security update
An update is now available for the Red Hat build of Cryostat 4 on RHEL 9.Security Fix(es): netty-handler: Denial of Service due to eager buffer allocation in TLS handshake (CVE-2026-45416) netty-resolver-dns: Information disclosure and data manipulation due to improper CNAME record validation (CVE-2026-45674) netty-handler: Improper trust manager handling leads to hostname verification bypass (CVE-2026-50010) io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records (CVE-2026-47691) netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers (CVE-2026-48059) netty-codec-http2: Denial of Service due to resource leak (CVE-2026-48043) netty-codec-haproxy: Denial of Service via malformed HAProxy message (CVE-2026-44893) netty-handler: IPv6 subnet rule bypass due to incorrect masking operation (CVE-2026-44249) io.quarkus/quarkus-vertx-http: Authorization bypass in HTTP path-based policies via encoded characters (CVE-2026-50559) jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513) eclipse-vertx/vert.x: Denial of Service via TLS handshake with wildcard server name (CVE-2026-6860) golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation (CVE-2026-46595) golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829) golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions (CVE-2026-39828) golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835) golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830) golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136) golang.org/x/net/html: Cross-Site Scripting allowing arbitrary code execution (CVE-2026-25681) golang.org/x/image/tiff: Denial of Service via crafted PackBits-compressed data (CVE-2026-46599) github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: Integer Overflow in Avro Decoder (CVE-2026-46384) github.com/hamba/avro/v2: github.com/linkedin/goavro/v2: CPU Exhaustion in Avro Decoder via Unbounded Block-Count Iteration (CVE-2026-46385) net: golang: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) mime: golang: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) form-data: Form field override via CRLF injection (CVE-2026-12143) ws: Denial of Service via memory exhaustion from small WebSocket fragments (CVE-2026-48779) ws: Uninitialized memory disclosure via websocket.close() with TypedArray (CVE-2026-45736) undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151) undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697) undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734) js-cookie: Cookie attribute manipulation via prototype pollution (CVE-2026-46625) brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149) protobufjs: Denial of Service via crafted schema (CVE-2026-44290) protobufjs: Data integrity impact due to prototype pollution (CVE-2026-44292) protobufjs: Denial of Service via crafted JSON descriptors (CVE-2026-45740) protobufjs: Arbitrary Code Execution via prototype pollution (CVE-2026-44291) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: Red Hat build of Cryostat security update
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:48151?
The severity of RHSA-2026:48151 is categorized as high with a score of 7.
What vulnerabilities are addressed in RHSA-2026:48151?
RHSA-2026:48151 addresses CVE-2026-45416 related to a Denial of Service and improper CNAME record validation.
How do I fix RHSA-2026:48151?
To fix RHSA-2026:48151, update your Red Hat build of Cryostat according to the provided security update instructions.
What software is affected by RHSA-2026:48151?
RHSA-2026:48151 affects the Red Hat build of Cryostat on RHEL 9.
What are the potential impacts of the vulnerabilities in RHSA-2026:48151?
The potential impacts include Denial of Service and information disclosure due to improper validation.