Synopsis
Important: opentelemetry-collector security update
Type/Severity
Security Advisory: Important
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
An update for opentelemetry-collector is now available for Red Hat Enterprise Linux 9.6 Extended Update Support.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
Collector with the supported components for a Red Hat build of OpenTelemetry
Security Fix(es):
- github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint (CVE-2026-42154)
- github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API (CVE-2026-42151)
- apache-thrift: Apache Thrift: Denial of Service via multiple vulnerabilities (CVE-2026-43870)
- net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
- golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
- golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136)
- golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)
- crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64
-
Red Hat Enterprise Linux Server - AUS 9.6 x86_64
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x
-
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le
-
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64
-
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le
-
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64
-
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64
-
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x
-
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64
-
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64
-
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le
-
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x
Fixes
-
BZ - 2466505
- CVE-2026-42154 github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint
-
BZ - 2466507
- CVE-2026-42151 github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API
-
BZ - 2466671
- CVE-2026-43870 apache-thrift: Apache Thrift: Denial of Service via multiple vulnerabilities
-
BZ - 2467822
- CVE-2026-33811 net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME
-
BZ - 2480756
- CVE-2026-39821 golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
-
BZ - 2480757
- CVE-2026-27136 golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
-
BZ - 2480761
- CVE-2026-25681 golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting
-
BZ - 2484207
- CVE-2026-27145 crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6
| SRPM |
|
opentelemetry-collector-0.152.1-1.el9_6.src.rpm
|
SHA-256: 47f1927b7a8d00fac08b8c025a23d550be665f063249637237f710ad6cde69ea |
| x86_64 |
|
opentelemetry-collector-0.152.1-1.el9_6.x86_64.rpm
|
SHA-256: bdc5241053b6bee0f9be1e7bf629edf499c4f26f1cffd5adf7fc57225d17ecac |
Red Hat Enterprise Linux Server - AUS 9.6
| SRPM |
|
opentelemetry-collector-0.152.1-1.el9_6.src.rpm
|
SHA-256: 47f1927b7a8d00fac08b8c025a23d550be665f063249637237f710ad6cde69ea |
| x86_64 |
|
opentelemetry-collector-0.152.1-1.el9_6.x86_64.rpm
|
SHA-256: bdc5241053b6bee0f9be1e7bf629edf499c4f26f1cffd5adf7fc57225d17ecac |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6
| SRPM |
|
opentelemetry-collector-0.152.1-1.el9_6.src.rpm
|
SHA-256: 47f1927b7a8d00fac08b8c025a23d550be665f063249637237f710ad6cde69ea |
| s390x |
|
opentelemetry-collector-0.152.1-1.el9_6.s390x.rpm
|
SHA-256: 35a1d5136cbf235d96f68a8129fe91891dd56429cb460460dbb899c6c049805f |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6
| SRPM |
|
opentelemetry-collector-0.152.1-1.el9_6.src.rpm
|
SHA-256: 47f1927b7a8d00fac08b8c025a23d550be665f063249637237f710ad6cde69ea |
| ppc64le |
|
opentelemetry-collector-0.152.1-1.el9_6.ppc64le.rpm
|
SHA-256: 540a7d9f6d95314ea5da44413c239cc1dc96f0a12a6b8d45b482b6ba543d75d0 |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6
| SRPM |
|
opentelemetry-collector-0.152.1-1.el9_6.src.rpm
|
SHA-256: 47f1927b7a8d00fac08b8c025a23d550be665f063249637237f710ad6cde69ea |
| aarch64 |
|
opentelemetry-collector-0.152.1-1.el9_6.aarch64.rpm
|
SHA-256: 8bba288276d84919d7494acfb5225d52eff470545a8bab3632d5afde5077cdae |
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6
| SRPM |
|
opentelemetry-collector-0.152.1-1.el9_6.src.rpm
|
SHA-256: 47f1927b7a8d00fac08b8c025a23d550be665f063249637237f710ad6cde69ea |
| ppc64le |
|
opentelemetry-collector-0.152.1-1.el9_6.ppc64le.rpm
|
SHA-256: 540a7d9f6d95314ea5da44413c239cc1dc96f0a12a6b8d45b482b6ba543d75d0 |
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6
| SRPM |
|
opentelemetry-collector-0.152.1-1.el9_6.src.rpm
|
SHA-256: 47f1927b7a8d00fac08b8c025a23d550be665f063249637237f710ad6cde69ea |
| x86_64 |
|
opentelemetry-collector-0.152.1-1.el9_6.x86_64.rpm
|
SHA-256: bdc5241053b6bee0f9be1e7bf629edf499c4f26f1cffd5adf7fc57225d17ecac |
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6
| SRPM |
|
opentelemetry-collector-0.152.1-1.el9_6.src.rpm
|
SHA-256: 47f1927b7a8d00fac08b8c025a23d550be665f063249637237f710ad6cde69ea |
| aarch64 |
|
opentelemetry-collector-0.152.1-1.el9_6.aarch64.rpm
|
SHA-256: 8bba288276d84919d7494acfb5225d52eff470545a8bab3632d5afde5077cdae |
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6
| SRPM |
|
opentelemetry-collector-0.152.1-1.el9_6.src.rpm
|
SHA-256: 47f1927b7a8d00fac08b8c025a23d550be665f063249637237f710ad6cde69ea |
| s390x |
|
opentelemetry-collector-0.152.1-1.el9_6.s390x.rpm
|
SHA-256: 35a1d5136cbf235d96f68a8129fe91891dd56429cb460460dbb899c6c049805f |
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6
| SRPM |
|
opentelemetry-collector-0.152.1-1.el9_6.src.rpm
|
SHA-256: 47f1927b7a8d00fac08b8c025a23d550be665f063249637237f710ad6cde69ea |
| x86_64 |
|
opentelemetry-collector-0.152.1-1.el9_6.x86_64.rpm
|
SHA-256: bdc5241053b6bee0f9be1e7bf629edf499c4f26f1cffd5adf7fc57225d17ecac |
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6
| SRPM |
|
opentelemetry-collector-0.152.1-1.el9_6.src.rpm
|
SHA-256: 47f1927b7a8d00fac08b8c025a23d550be665f063249637237f710ad6cde69ea |
| aarch64 |
|
opentelemetry-collector-0.152.1-1.el9_6.aarch64.rpm
|
SHA-256: 8bba288276d84919d7494acfb5225d52eff470545a8bab3632d5afde5077cdae |
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6
| SRPM |
|
opentelemetry-collector-0.152.1-1.el9_6.src.rpm
|
SHA-256: 47f1927b7a8d00fac08b8c025a23d550be665f063249637237f710ad6cde69ea |
| ppc64le |
|
opentelemetry-collector-0.152.1-1.el9_6.ppc64le.rpm
|
SHA-256: 540a7d9f6d95314ea5da44413c239cc1dc96f0a12a6b8d45b482b6ba543d75d0 |
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6
| SRPM |
|
opentelemetry-collector-0.152.1-1.el9_6.src.rpm
|
SHA-256: 47f1927b7a8d00fac08b8c025a23d550be665f063249637237f710ad6cde69ea |
| s390x |
|
opentelemetry-collector-0.152.1-1.el9_6.s390x.rpm
|
SHA-256: 35a1d5136cbf235d96f68a8129fe91891dd56429cb460460dbb899c6c049805f |
