[CLSA-2026:1772041183] grafana: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-02-25 17:39:48 UTC
Description:
- rebuild with newer golang version 1.22.9-1.el9_2.tuxcare.els5 to fix the following CVE's - CVE-2025-61726: limit parsed URL query parameters to mitigate excessive memory consumption during form parsing - CVE-2025-61728: fix denial-of-service in archive/zip by replacing super-linear index construction with an efficient algorithm - CVE-2025-61729: fix excessive resource consumption when constructing hostname error messages for certificates with many SANs
Updated packages:
  • grafana-9.0.9-4.el9_2.alma.1.tuxcare.els12.x86_64.rpm
    sha:c3c74f4958608d6eec274baba1bc669ca91ba8dbf82f6b87327e94baa7c3726f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.