[CLSA-2026:1790972870] grafana: Fix of CVE-2026-14199
Type:
security
Severity:
Important
Release date:
2026-10-02 20:28:01 UTC
Description:
- CVE-2026-14199: auth proxy cache key collision in getProxyCacheKey() - Stop exporting GOEXPERIMENT=boringcrypto: golang 1.26.7-2.el9_8 defaults to GOFIPS140=certified and refuses the experiment
CVEs fixed:
Updated packages:
  • grafana-10.2.6-23.el9_8.3.tuxcare.els1.aarch64.rpm
    sha:01424e7deb51781c1a148bc0af18e5febcd7b74b89534be1e7cf9ebb313caf59
  • grafana-10.2.6-23.el9_8.3.tuxcare.els1.x86_64.rpm
    sha:20783034da359824856ca2cfc9d19bd88e26e9354c25170e4e1849297730ceb9
  • grafana-selinux-10.2.6-23.el9_8.3.tuxcare.els1.aarch64.rpm
    sha:1999a03084e481efc096b77c7ae9b3762e3f8cea52492d896991c583a491a252
  • grafana-selinux-10.2.6-23.el9_8.3.tuxcare.els1.x86_64.rpm
    sha:7660664d832cbbcbc172ddd7331dec8a97fc159ff0044619526dfcbcfde3b0a6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.