grafana-10.2.6-23.el9_8.3

エラータID: AXSA:2026-1777:26

Release date: 
Monday, September 7, 2026 - 20:45
Subject: 
grafana-10.2.6-23.el9_8.3
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.

Security Fix(es):

* net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
* net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)
* encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
* net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
* net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
* html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
* crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
* encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-33818
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
CVE-2026-39820
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
CVE-2026-42499
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
CVE-2026-56853
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
CVE-2026-56858
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
CVE-2026-56859
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
CVE-2026-56860
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.
CVE-2026-56862
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. grafana-10.2.6-23.el9_8.3.src.rpm
    MD5: 6fe51cc27c5a1a5a2054ca8d3fa70e65
    SHA-256: 8ea823a0f969535f5daec4b1ae6eaf611bd0dc99eb40a1c3e25b133e0b07c7fe
    Size: 336.14 MB

Asianux Server 9 for x86_64
  1. grafana-10.2.6-23.el9_8.3.x86_64.rpm
    MD5: 66ab15c227227ab62babbc269748bd84
    SHA-256: d73759da13d3731f638e57560631ed751d7c2d5ecfec6d7cbfeedc7c96459563
    Size: 113.95 MB
  2. grafana-selinux-10.2.6-23.el9_8.3.x86_64.rpm
    MD5: 531d9081ab7431fd81c34f0dc8dedaf6
    SHA-256: b443a86442849a83c672b0903228683513ccf77629a1e64da37bb50ae6d84bba
    Size: 23.42 kB