- Issued:
- 2026-06-15
- Updated:
- 2026-06-15
RHSA-2026:26010 - Security Advisory
Synopsis
Cluster Observability Operator 1.5.0
Type/Severity
Security Advisory: Important
Topic
The Cluster Observability Operator (COO) is a Red Hat OpenShift Container Platform Operator that you can deploy to manage observability component stacks by using custom resource descriptions (CRDs).
Description
The 1.5 release of COO.
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
Affected Products
- Cluster Observability Operator
Fixes
- COO-1493 - Prometheus and alertmanager pod failed to be created when monitoringstack with createClusterRoleBindings: NoClusterRoleBindings
- COO-1548 - Add a controller to watch the API server configuration
- COO-1614 - COO UIPlugin monitoring should support OTEL semantic convention naming in dashboards for Perses
- COO-1690 - Monitoringstack reconciler error: Precondition failed: UID in precondition in logs
- COO-1735 - Controller panic when creating PersesDatasource v1alpha2
- COO-1739 - Enable strictfipsruntime and CGO for COO Go images
- COO-1740 - Distributed Tracing console plugin shows shared module version mismatch warnings on OCP 4.22
- COO-1741 - perses-operator exceeds memory reservation in large environments
- COO-1742 - monitoringstack crd is techpreview which should be GA
- COO-1840 - Add stable and fast channel layout for FBC catalogs
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.