{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "rebuild with newer golang version 1.22.9-1.el9_2.tuxcare.els26 to fix the\n  following Go standard-library CVE's tracked for this package\n  - CVE-2026-33818: fix encoding/asn1 stack exhaustion by enforcing a recursion\n    depth limit in Unmarshal when parsing deeply nested structures\n  - CVE-2026-56858: fix html/template XSS where pathological input could close an\n    unescaped '/' early and inject attacker-controlled content\n  - CVE-2026-56860: fix net/url quadratic complexity when resolving relative paths\n    containing many '..' parent-directory segments\n  - CVE-2026-56862: fix crypto/tls denial of service from post-handshake KeyUpdate\n    messages forcing unbounded key-derivation work\n- the same golang rebuild also carries CVE-2026-56859 (encoding/xml unmarshal\n  depth-limit bypass via a custom UnmarshalXML), which is not tracked by these\n  tickets",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1788885695",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1788885695"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/almalinux9.2esu/advisories/2026/clsa-2026_1788885695.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-08T16:42:31Z",
      "generator": {
        "date": "2026-09-08T16:42:31Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1788885695",
      "initial_release_date": "2026-09-08T16:42:31Z",
      "revision_history": [
        {
          "date": "2026-09-08T16:42:31Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "grafana-pcp: Fix of 4 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "AlmaLinux 9.2",
                "product": {
                  "name": "AlmaLinux 9.2",
                  "product_id": "AlmaLinux-9.2",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:almalinux:almalinux:9.2:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "AlmaLinux"
          }
        ],
        "category": "vendor",
        "name": "AlmaLinux OS Foundation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els5.x86_64",
                "product": {
                  "name": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els5.x86_64",
                  "product_id": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els5.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/grafana-pcp@5.1.1-1.el9_2.tuxcare.els5?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els4.x86_64",
                "product": {
                  "name": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els4.x86_64",
                  "product_id": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/grafana-pcp@5.1.1-1.el9_2.tuxcare.els4?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els3.x86_64",
                "product": {
                  "name": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els3.x86_64",
                  "product_id": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els3.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/grafana-pcp@5.1.1-1.el9_2.tuxcare.els3?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els2.x86_64",
                "product": {
                  "name": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els2.x86_64",
                  "product_id": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/grafana-pcp@5.1.1-1.el9_2.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els1.x86_64",
                "product": {
                  "name": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els1.x86_64",
                  "product_id": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/grafana-pcp@5.1.1-1.el9_2.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els5.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els5.x86_64"
        },
        "product_reference": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els5.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els4.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els4.x86_64"
        },
        "product_reference": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els4.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els3.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els3.x86_64"
        },
        "product_reference": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els3.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els2.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els2.x86_64"
        },
        "product_reference": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els2.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els1.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els1.x86_64"
        },
        "product_reference": "grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els1.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-33818",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els5.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els2.x86_64",
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-33818"
        },
        {
          "category": "external",
          "summary": "https://go.dev/cl/814980",
          "url": "https://go.dev/cl/814980"
        },
        {
          "category": "external",
          "summary": "https://go.dev/issue/80405",
          "url": "https://go.dev/issue/80405"
        },
        {
          "category": "external",
          "summary": "https://groups.google.com/g/golang-announce/c/94pEornpRlI",
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "category": "external",
          "summary": "https://pkg.go.dev/vuln/GO-2026-5972",
          "url": "https://pkg.go.dev/vuln/GO-2026-5972"
        }
      ],
      "release_date": "2026-08-13T22:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-08T16:41:37.956174Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1788885695",
          "product_ids": [
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els5.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1788885695"
        },
        {
          "category": "none_available",
          "date": "2026-08-13T22:17:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els2.x86_64",
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els4.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-56862",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "notes": [
        {
          "category": "description",
          "text": "Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els5.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els2.x86_64",
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-56862"
        },
        {
          "category": "external",
          "summary": "https://go.dev/cl/804261",
          "url": "https://go.dev/cl/804261"
        },
        {
          "category": "external",
          "summary": "https://go.dev/issue/80528",
          "url": "https://go.dev/issue/80528"
        },
        {
          "category": "external",
          "summary": "https://groups.google.com/g/golang-announce/c/94pEornpRlI",
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "category": "external",
          "summary": "https://pkg.go.dev/vuln/GO-2026-6090",
          "url": "https://pkg.go.dev/vuln/GO-2026-6090"
        }
      ],
      "release_date": "2026-08-13T22:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-08T16:41:37.956174Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1788885695",
          "product_ids": [
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els5.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1788885695"
        },
        {
          "category": "none_available",
          "date": "2026-08-13T22:17:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els2.x86_64",
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els4.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-56860",
      "cwe": {
        "id": "CWE-407",
        "name": "Inefficient Algorithmic Complexity"
      },
      "notes": [
        {
          "category": "description",
          "text": "Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els5.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els2.x86_64",
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-56860"
        },
        {
          "category": "external",
          "summary": "https://go.dev/cl/803681",
          "url": "https://go.dev/cl/803681"
        },
        {
          "category": "external",
          "summary": "https://go.dev/issue/80494",
          "url": "https://go.dev/issue/80494"
        },
        {
          "category": "external",
          "summary": "https://groups.google.com/g/golang-announce/c/94pEornpRlI",
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "category": "external",
          "summary": "https://pkg.go.dev/vuln/GO-2026-6218",
          "url": "https://pkg.go.dev/vuln/GO-2026-6218"
        }
      ],
      "release_date": "2026-08-13T22:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-08T16:41:37.956174Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1788885695",
          "product_ids": [
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els5.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1788885695"
        },
        {
          "category": "none_available",
          "date": "2026-08-13T22:17:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els2.x86_64",
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els4.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-56858",
      "cwe": {
        "id": "CWE-79",
        "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
      },
      "notes": [
        {
          "category": "description",
          "text": "Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els5.x86_64"
        ],
        "known_affected": [
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els2.x86_64",
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els3.x86_64",
          "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els4.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-56858"
        },
        {
          "category": "external",
          "summary": "https://go.dev/cl/807100",
          "url": "https://go.dev/cl/807100"
        },
        {
          "category": "external",
          "summary": "https://go.dev/issue/80435",
          "url": "https://go.dev/issue/80435"
        },
        {
          "category": "external",
          "summary": "https://groups.google.com/g/golang-announce/c/94pEornpRlI",
          "url": "https://groups.google.com/g/golang-announce/c/94pEornpRlI"
        },
        {
          "category": "external",
          "summary": "https://pkg.go.dev/vuln/GO-2026-6091",
          "url": "https://pkg.go.dev/vuln/GO-2026-6091"
        }
      ],
      "release_date": "2026-08-13T22:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-08T16:41:37.956174Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1788885695",
          "product_ids": [
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els5.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1788885695"
        },
        {
          "category": "none_available",
          "date": "2026-08-13T22:17:00Z",
          "details": "Affected",
          "product_ids": [
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els2.x86_64",
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els3.x86_64",
            "AlmaLinux-9.2:grafana-pcp-0:5.1.1-1.el9_2.tuxcare.els4.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}