{
  "document" : {
    "aggregate_severity" : {
      "namespace" : "https://access.redhat.com/security/updates/classification/",
      "text" : "Important"
    },
    "category" : "csaf_security_advisory",
    "csaf_version" : "2.0",
    "distribution" : {
      "text" : "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp" : {
        "label" : "WHITE",
        "url" : "https://www.first.org/tlp/"
      }
    },
    "lang" : "en",
    "notes" : [ {
      "category" : "summary",
      "text" : "Red Hat OpenShift distributed tracing platform (Tempo) 3.10.0 has been released",
      "title" : "Topic"
    }, {
      "category" : "general",
      "text" : "This release of the Red Hat OpenShift distributed tracing platform (Tempo) provides new features, security improvements, and bug fixes.\n\n\nBreaking changes:\n\n* None.\n\n\nDeprecations:\n\n* None.\n\n\nTechnology Preview features:\n\n* None.\n\n\nEnhancements:\n\n* TempoStack support for the automatically injected CA bundle: The TempoStack custom resource supports the automatically injected CA bundle ca-bundle.crt for storage TLS configuration. This CA bundle is supported in addition to the service-ca.crt and ca.crt certificates. As a result, you can use the automatically injected CA bundle to simplify TLS configuration for storage for your TempoStack instances. For more information, see https://redhat.atlassian.net/browse/TRACING-6222.\n\n* Cluster TLS profile adherence: This update introduces support for cluster TLS profile adherence. The Operator uses the TLS configuration from the APIServer custom resource in all TLS communication in the Operator and its operands. As a result, you can configure the TLS cluster profile by using environment variables. For more information, see https://redhat.atlassian.net/browse/TRACING-5845.\n\n* Optional spec.size field provides predefined resource configurations: The TempoStack custom resource supports the optional spec.size field, which provides predefined, pre-tested resource configurations. The following sizes are available: 1x.demo, 1x.pico, 1x.extra-small, 1x.small, and 1x.medium. The selected size sets the resource requests and limits for the TempoStack components and a default replication factor if one is not explicitly specified. The default replication factor is 1 for 1x.demo and 2 for the other sizes. As a result, you can deploy a TempoStack instance without manually calculating resources for each component. For more information, see https://redhat.atlassian.net/browse/TRACING-5376.\n\n* Custom environment variables for TempoStack containers: The TempoStack custom resource supports the spec.env and spec.envFrom fields, which allow you to inject custom environment variables into all Tempo containers, including values sourced from a secret or config map. Combined with the spec.extraConfig field, you can reference these environment variables in the Tempo configuration by using the ${VAR_NAME} syntax. As a result, you can supply the password for a password-protected Redis cache from a secret instead of embedding it in the custom resource. For more information, see https://redhat.atlassian.net/browse/TRACING-5933.\n\n\nBug fixes:\n\n* The tempo-gateway-opa container starts in namespaces that enforce a LimitRange: Before this update, the tempo-gateway-opa container was created without default resource requests and limits when percentage-based resource calculation was used. As a consequence, the container could fail to start in namespaces that enforce a LimitRange resource. With this update, the Operator sets default resource requests and limits on the tempo-gateway-opa container. As a result, the tempo-gateway-opa container starts as expected. For more information, see https://redhat.atlassian.net/browse/TRACING-5716.\n\n* TempoStack and TempoMonolithic resources no longer get stuck in a terminating state: Previously, the certificate rotation controllers in the Tempo Operator updated certificate hash annotations without checking whether a resource had a deletion timestamp. When a TempoStack or TempoMonolithic resource was deleted, these annotation updates caused resource version conflicts that prevented the foreground deletion finalizer from being removed. As a result, resources remained stuck in a terminating state. With this update, the certificate rotation controllers skip annotation updates when a resource is being deleted. As a result, TempoStack and TempoMonolithic resources are deleted correctly without getting stuck in a terminating state. For more information, see https://redhat.atlassian.net/browse/TRACING-6138.\n\n* TempoStack gateway pods spread across nodes for high availability: Previously, the TempoStack gateway deployment did not set a pod anti-affinity rule. Other components such as the distributor, querier, query front end, and ingesters did set a pod anti-affinity rule. As a result, all gateway replicas could be scheduled on the same node, reducing high availability. With this update, the gateway and compactor deployments set pod anti-affinity rules. As a result, gateway replicas are spread across nodes, which can improve high availability. For more information, see https://redhat.atlassian.net/browse/TRACING-6148.\n\n* The gateway correctly forwards OTLP HTTP traffic over HTTPS for Tempo Monolithic: Before this update, when Tempo Monolithic was configured with 'multitenancy.enabled: true' and 'ingestion.otlp.http.tls.enabled: true', the gateway forwarded OTLP HTTP traffic to the Tempo receiver using plain HTTP instead of HTTPS. As a consequence, the connection failed with a 'connection reset by peer' error because the receiver expected TLS connections. With this update, the gateway forwards OTLP HTTP traffic over HTTPS when TLS is enabled. As a result, OTLP HTTP ingestion through the gateway works correctly when multitenancy and OTLP HTTP TLS are enabled. For more information, see https://issues.redhat.com/browse/TRACING-5973.\n\n\nKnown issues:",
      "title" : "Details"
    }, {
      "category" : "legal_disclaimer",
      "text" : "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
      "title" : "Terms of Use"
    } ],
    "publisher" : {
      "category" : "vendor",
      "contact_details" : "https://access.redhat.com/security/team/contact/",
      "issuing_authority" : "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name" : "Red Hat Product Security",
      "namespace" : "https://www.redhat.com"
    },
    "references" : [ {
      "category" : "self",
      "summary" : "https://access.redhat.com/errata/RHSA-2026:27126",
      "url" : "https://access.redhat.com/errata/RHSA-2026:27126"
    }, {
      "category" : "external",
      "summary" : "https://access.redhat.com/security/cve/CVE-2025-48431",
      "url" : "https://access.redhat.com/security/cve/CVE-2025-48431"
    }, {
      "category" : "external",
      "summary" : "https://access.redhat.com/security/cve/CVE-2026-32281",
      "url" : "https://access.redhat.com/security/cve/CVE-2026-32281"
    }, {
      "category" : "external",
      "summary" : "https://access.redhat.com/security/cve/CVE-2026-43869",
      "url" : "https://access.redhat.com/security/cve/CVE-2026-43869"
    }, {
      "category" : "external",
      "summary" : "https://access.redhat.com/security/updates/classification/",
      "url" : "https://access.redhat.com/security/updates/classification/"
    }, {
      "category" : "external",
      "summary" : "https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/distributed_tracing/distributed-tracing-platform-tempo",
      "url" : "https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/distributed_tracing/distributed-tracing-platform-tempo"
    }, {
      "category" : "self",
      "summary" : "Canonical URL",
      "url" : "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_27126.json"
    } ],
    "title" : "Red Hat Security Advisory: Red Hat OpenShift distributed tracing platform (Tempo) 3.10.0 release",
    "tracking" : {
      "current_release_date" : "2026-06-19T18:23:41+00:00",
      "generator" : {
        "date" : "2026-06-19T18:23:41+00:00",
        "engine" : {
          "name" : "Red Hat SDEngine",
          "version" : "5.0.0"
        }
      },
      "id" : "RHSA-2026:27126",
      "initial_release_date" : "2026-06-18T16:31:31+00:00",
      "revision_history" : [ {
        "date" : "2026-06-18T16:31:31+00:00",
        "number" : "1",
        "summary" : "Initial version"
      }, {
        "date" : "2026-06-18T16:31:39+00:00",
        "number" : "2",
        "summary" : "Last updated version"
      }, {
        "date" : "2026-06-19T18:23:41+00:00",
        "number" : "3",
        "summary" : "Last generated version"
      } ],
      "status" : "final",
      "version" : "3"
    }
  },
  "product_tree" : {
    "branches" : [ {
      "branches" : [ {
        "branches" : [ {
          "category" : "product_name",
          "name" : "Red Hat OpenShift distributed tracing 3.10.0",
          "product" : {
            "name" : "Red Hat OpenShift distributed tracing 3.10.0",
            "product_id" : "Red Hat OpenShift distributed tracing 3.10.0",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9"
            }
          }
        } ],
        "category" : "product_family",
        "name" : "Red Hat OpenShift distributed tracing"
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47_amd64",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47_amd64",
            "product_id" : "registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47_amd64",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-operator-bundle@sha256%3A03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47?arch=amd64&repository_url=registry.redhat.io/rhosdt/tempo-operator-bundle&tag=1781591522"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb_amd64",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb_amd64",
            "product_id" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb_amd64",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-gateway-rhel9@sha256%3A6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb?arch=amd64&repository_url=registry.redhat.io/rhosdt/tempo-gateway-rhel9&tag=1781589515"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354_amd64",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354_amd64",
            "product_id" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354_amd64",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-jaeger-query-rhel9@sha256%3A8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354?arch=amd64&repository_url=registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9&tag=1781589458"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c_amd64",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c_amd64",
            "product_id" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c_amd64",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-gateway-opa-rhel9@sha256%3A5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c?arch=amd64&repository_url=registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9&tag=1781589512"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:a72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912_amd64",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:a72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912_amd64",
            "product_id" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:a72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912_amd64",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-rhel9-operator@sha256%3Aa72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912?arch=amd64&repository_url=registry.redhat.io/rhosdt/tempo-rhel9-operator&tag=1781589394"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e_amd64",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e_amd64",
            "product_id" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e_amd64",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-query-rhel9@sha256%3A7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e?arch=amd64&repository_url=registry.redhat.io/rhosdt/tempo-query-rhel9&tag=1781587690"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe_amd64",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe_amd64",
            "product_id" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe_amd64",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-rhel9@sha256%3A49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe?arch=amd64&repository_url=registry.redhat.io/rhosdt/tempo-rhel9&tag=1781589494"
            }
          }
        } ],
        "category" : "architecture",
        "name" : "amd64"
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8_arm64",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8_arm64",
            "product_id" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8_arm64",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-gateway-rhel9@sha256%3A93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8?arch=arm64&repository_url=registry.redhat.io/rhosdt/tempo-gateway-rhel9&tag=1781589515"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b_arm64",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b_arm64",
            "product_id" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b_arm64",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-jaeger-query-rhel9@sha256%3A741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b?arch=arm64&repository_url=registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9&tag=1781589458"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:f889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a_arm64",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:f889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a_arm64",
            "product_id" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:f889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a_arm64",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-gateway-opa-rhel9@sha256%3Af889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a?arch=arm64&repository_url=registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9&tag=1781589512"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:bd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa_arm64",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:bd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa_arm64",
            "product_id" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:bd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa_arm64",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-rhel9-operator@sha256%3Abd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa?arch=arm64&repository_url=registry.redhat.io/rhosdt/tempo-rhel9-operator&tag=1781589394"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:fbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf_arm64",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:fbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf_arm64",
            "product_id" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:fbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf_arm64",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-query-rhel9@sha256%3Afbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf?arch=arm64&repository_url=registry.redhat.io/rhosdt/tempo-query-rhel9&tag=1781587690"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90_arm64",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90_arm64",
            "product_id" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90_arm64",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-rhel9@sha256%3A8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90?arch=arm64&repository_url=registry.redhat.io/rhosdt/tempo-rhel9&tag=1781589494"
            }
          }
        } ],
        "category" : "architecture",
        "name" : "arm64"
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593_ppc64le",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593_ppc64le",
            "product_id" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593_ppc64le",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-gateway-rhel9@sha256%3A964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593?arch=ppc64le&repository_url=registry.redhat.io/rhosdt/tempo-gateway-rhel9&tag=1781589515"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e_ppc64le",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e_ppc64le",
            "product_id" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e_ppc64le",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-jaeger-query-rhel9@sha256%3A6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e?arch=ppc64le&repository_url=registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9&tag=1781589458"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:e5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470_ppc64le",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:e5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470_ppc64le",
            "product_id" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:e5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470_ppc64le",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-gateway-opa-rhel9@sha256%3Ae5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470?arch=ppc64le&repository_url=registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9&tag=1781589512"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33_ppc64le",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33_ppc64le",
            "product_id" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33_ppc64le",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-rhel9-operator@sha256%3A72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33?arch=ppc64le&repository_url=registry.redhat.io/rhosdt/tempo-rhel9-operator&tag=1781589394"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:a13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a_ppc64le",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:a13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a_ppc64le",
            "product_id" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:a13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a_ppc64le",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-query-rhel9@sha256%3Aa13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a?arch=ppc64le&repository_url=registry.redhat.io/rhosdt/tempo-query-rhel9&tag=1781587690"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39_ppc64le",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39_ppc64le",
            "product_id" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39_ppc64le",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-rhel9@sha256%3A4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39?arch=ppc64le&repository_url=registry.redhat.io/rhosdt/tempo-rhel9&tag=1781589494"
            }
          }
        } ],
        "category" : "architecture",
        "name" : "ppc64le"
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:ed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c_s390x",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:ed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c_s390x",
            "product_id" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:ed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c_s390x",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-gateway-rhel9@sha256%3Aed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c?arch=s390x&repository_url=registry.redhat.io/rhosdt/tempo-gateway-rhel9&tag=1781589515"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0_s390x",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0_s390x",
            "product_id" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0_s390x",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-jaeger-query-rhel9@sha256%3A0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0?arch=s390x&repository_url=registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9&tag=1781589458"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff_s390x",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff_s390x",
            "product_id" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff_s390x",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-gateway-opa-rhel9@sha256%3A648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff?arch=s390x&repository_url=registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9&tag=1781589512"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f_s390x",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f_s390x",
            "product_id" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f_s390x",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-rhel9-operator@sha256%3A982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f?arch=s390x&repository_url=registry.redhat.io/rhosdt/tempo-rhel9-operator&tag=1781589394"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991_s390x",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991_s390x",
            "product_id" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991_s390x",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-query-rhel9@sha256%3A6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991?arch=s390x&repository_url=registry.redhat.io/rhosdt/tempo-query-rhel9&tag=1781587690"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:f1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052_s390x",
          "product" : {
            "name" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:f1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052_s390x",
            "product_id" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:f1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052_s390x",
            "product_identification_helper" : {
              "purl" : "pkg:oci/tempo-rhel9@sha256%3Af1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052?arch=s390x&repository_url=registry.redhat.io/rhosdt/tempo-rhel9&tag=1781589494"
            }
          }
        } ],
        "category" : "architecture",
        "name" : "s390x"
      } ],
      "category" : "vendor",
      "name" : "Red Hat"
    } ],
    "relationships" : [ {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c_amd64 as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c_amd64"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c_amd64",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff_s390x as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff_s390x"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff_s390x",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:e5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470_ppc64le as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:e5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470_ppc64le"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:e5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470_ppc64le",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:f889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a_arm64 as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:f889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a_arm64"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:f889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a_arm64",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb_amd64 as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb_amd64"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb_amd64",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8_arm64 as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8_arm64"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8_arm64",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593_ppc64le as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593_ppc64le"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593_ppc64le",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:ed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c_s390x as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:ed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c_s390x"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:ed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c_s390x",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0_s390x as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0_s390x"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0_s390x",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e_ppc64le as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e_ppc64le"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e_ppc64le",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b_arm64 as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b_arm64"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b_arm64",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354_amd64 as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354_amd64"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354_amd64",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47_amd64 as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47_amd64"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47_amd64",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991_s390x as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991_s390x"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991_s390x",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e_amd64 as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e_amd64"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e_amd64",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:a13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a_ppc64le as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:a13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a_ppc64le"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:a13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a_ppc64le",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:fbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf_arm64 as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:fbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf_arm64"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:fbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf_arm64",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33_ppc64le as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33_ppc64le"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33_ppc64le",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f_s390x as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f_s390x"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f_s390x",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:a72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912_amd64 as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:a72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912_amd64"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:a72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912_amd64",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:bd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa_arm64 as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:bd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa_arm64"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:bd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa_arm64",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe_amd64 as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe_amd64"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe_amd64",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39_ppc64le as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39_ppc64le"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39_ppc64le",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90_arm64 as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90_arm64"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90_arm64",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:f1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052_s390x as a component of Red Hat OpenShift distributed tracing 3.10.0",
        "product_id" : "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:f1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052_s390x"
      },
      "product_reference" : "registry.redhat.io/rhosdt/tempo-rhel9@sha256:f1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052_s390x",
      "relates_to_product_reference" : "Red Hat OpenShift distributed tracing 3.10.0"
    } ]
  },
  "vulnerabilities" : [ {
    "cve" : "CVE-2025-48431",
    "cwe" : {
      "id" : "CWE-763",
      "name" : "Release of Invalid Pointer or Reference"
    },
    "discovery_date" : "2026-04-28T10:01:26.612789+00:00",
    "flags" : [ {
      "label" : "vulnerable_code_not_present",
      "product_ids" : [ "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:e5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:f889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:ed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:a13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:fbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:a72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:bd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa_arm64" ]
    } ],
    "ids" : [ {
      "system_name" : "Red Hat Bugzilla ID",
      "text" : "2463410"
    } ],
    "notes" : [ {
      "category" : "description",
      "text" : "A flaw was found in Apache Thrift c_glib language bindings. A remote attacker could send specially crafted requests to a c_glib-based Thrift server, leading to a mismatched memory management routines vulnerability. This could cause the server to crash with a \"free(): invalid pointer\" error, resulting in a Denial of Service (DoS).",
      "title" : "Vulnerability description"
    }, {
      "category" : "summary",
      "text" : "Apache Thrift: c_glib: Apache Thrift c_glib: Denial of Service via specially crafted requests",
      "title" : "Vulnerability summary"
    }, {
      "category" : "general",
      "text" : "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
      "title" : "CVSS score applicability"
    } ],
    "product_status" : {
      "fixed" : [ "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:f1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052_s390x" ],
      "known_not_affected" : [ "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:e5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:f889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:ed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:a13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:fbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:a72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:bd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa_arm64" ]
    },
    "references" : [ {
      "category" : "self",
      "summary" : "Canonical URL",
      "url" : "https://access.redhat.com/security/cve/CVE-2025-48431"
    }, {
      "category" : "external",
      "summary" : "RHBZ#2463410",
      "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2463410"
    }, {
      "category" : "external",
      "summary" : "https://www.cve.org/CVERecord?id=CVE-2025-48431",
      "url" : "https://www.cve.org/CVERecord?id=CVE-2025-48431"
    }, {
      "category" : "external",
      "summary" : "https://nvd.nist.gov/vuln/detail/CVE-2025-48431",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2025-48431"
    }, {
      "category" : "external",
      "summary" : "http://www.openwall.com/lists/oss-security/2026/04/28/8",
      "url" : "http://www.openwall.com/lists/oss-security/2026/04/28/8"
    }, {
      "category" : "external",
      "summary" : "https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwql",
      "url" : "https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwql"
    } ],
    "release_date" : "2026-04-28T09:11:44.283000+00:00",
    "remediations" : [ {
      "category" : "vendor_fix",
      "date" : "2026-06-18T16:31:31+00:00",
      "details" : "For details on how to apply this update, refer to:\n\nhttps://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/operators/administrator-tasks#olm-upgrading-operators",
      "product_ids" : [ "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:f1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052_s390x" ],
      "restart_required" : {
        "category" : "none"
      },
      "url" : "https://access.redhat.com/errata/RHSA-2026:27126"
    } ],
    "scores" : [ {
      "cvss_v3" : {
        "attackComplexity" : "LOW",
        "attackVector" : "NETWORK",
        "availabilityImpact" : "HIGH",
        "baseScore" : 7.5,
        "baseSeverity" : "HIGH",
        "confidentialityImpact" : "NONE",
        "integrityImpact" : "NONE",
        "privilegesRequired" : "NONE",
        "scope" : "UNCHANGED",
        "userInteraction" : "NONE",
        "vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
        "version" : "3.1"
      },
      "products" : [ "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:e5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:f889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:ed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:a13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:fbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:a72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:bd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:f1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052_s390x" ]
    } ],
    "threats" : [ {
      "category" : "impact",
      "details" : "Important"
    } ],
    "title" : "Apache Thrift: c_glib: Apache Thrift c_glib: Denial of Service via specially crafted requests"
  }, {
    "cve" : "CVE-2026-32281",
    "cwe" : {
      "id" : "CWE-1050",
      "name" : "Excessive Platform Resource Consumption within a Loop"
    },
    "discovery_date" : "2026-04-08T02:01:00.930989+00:00",
    "flags" : [ {
      "label" : "vulnerable_code_not_present",
      "product_ids" : [ "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:e5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:f889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:ed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:a13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:fbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:a72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:bd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa_arm64" ]
    } ],
    "ids" : [ {
      "system_name" : "Red Hat Bugzilla ID",
      "text" : "2456333"
    } ],
    "notes" : [ {
      "category" : "description",
      "text" : "A flaw was found in Go's `crypto/x509` package. A remote attacker could exploit this by presenting a specially crafted certificate chain containing a large number of policy mappings. This inefficient validation process consumes excessive resources, which can lead to a denial of service (DoS) for applications or systems performing certificate validation.",
      "title" : "Vulnerability description"
    }, {
      "category" : "summary",
      "text" : "crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation",
      "title" : "Vulnerability summary"
    }, {
      "category" : "other",
      "text" : "This flaw occurs during the validation of otherwise trusted certificate chains that contain a large number of policy mappings, leading to excessive resource consumption. Exploitation requires an attacker to present a specially crafted, yet trusted, certificate chain which would require the attacker has already compromised a trusted certificate root. Red Hat continuously monitors certificate authorities and curates the set which is trusted by default for Red Hat products.",
      "title" : "Statement"
    }, {
      "category" : "general",
      "text" : "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
      "title" : "CVSS score applicability"
    } ],
    "product_status" : {
      "fixed" : [ "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:f1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052_s390x" ],
      "known_not_affected" : [ "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:e5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:f889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:ed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:a13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:fbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:a72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:bd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa_arm64" ]
    },
    "references" : [ {
      "category" : "self",
      "summary" : "Canonical URL",
      "url" : "https://access.redhat.com/security/cve/CVE-2026-32281"
    }, {
      "category" : "external",
      "summary" : "RHBZ#2456333",
      "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2456333"
    }, {
      "category" : "external",
      "summary" : "https://www.cve.org/CVERecord?id=CVE-2026-32281",
      "url" : "https://www.cve.org/CVERecord?id=CVE-2026-32281"
    }, {
      "category" : "external",
      "summary" : "https://nvd.nist.gov/vuln/detail/CVE-2026-32281",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-32281"
    }, {
      "category" : "external",
      "summary" : "https://go.dev/cl/758061",
      "url" : "https://go.dev/cl/758061"
    }, {
      "category" : "external",
      "summary" : "https://go.dev/issue/78281",
      "url" : "https://go.dev/issue/78281"
    }, {
      "category" : "external",
      "summary" : "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU",
      "url" : "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU"
    }, {
      "category" : "external",
      "summary" : "https://pkg.go.dev/vuln/GO-2026-4946",
      "url" : "https://pkg.go.dev/vuln/GO-2026-4946"
    } ],
    "release_date" : "2026-04-08T01:06:58.354000+00:00",
    "remediations" : [ {
      "category" : "vendor_fix",
      "date" : "2026-06-18T16:31:31+00:00",
      "details" : "For details on how to apply this update, refer to:\n\nhttps://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/operators/administrator-tasks#olm-upgrading-operators",
      "product_ids" : [ "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:f1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052_s390x" ],
      "restart_required" : {
        "category" : "none"
      },
      "url" : "https://access.redhat.com/errata/RHSA-2026:27126"
    }, {
      "category" : "workaround",
      "details" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
      "product_ids" : [ "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:e5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:f889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:ed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:a13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:fbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:a72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:bd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:f1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052_s390x" ]
    } ],
    "scores" : [ {
      "cvss_v3" : {
        "attackComplexity" : "HIGH",
        "attackVector" : "NETWORK",
        "availabilityImpact" : "HIGH",
        "baseScore" : 5.9,
        "baseSeverity" : "MEDIUM",
        "confidentialityImpact" : "NONE",
        "integrityImpact" : "NONE",
        "privilegesRequired" : "NONE",
        "scope" : "UNCHANGED",
        "userInteraction" : "NONE",
        "vectorString" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
        "version" : "3.1"
      },
      "products" : [ "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:e5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:f889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:ed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:a13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:fbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:a72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:bd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:f1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052_s390x" ]
    } ],
    "threats" : [ {
      "category" : "impact",
      "details" : "Moderate"
    } ],
    "title" : "crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation"
  }, {
    "cve" : "CVE-2026-43869",
    "cwe" : {
      "id" : "CWE-295",
      "name" : "Improper Certificate Validation"
    },
    "discovery_date" : "2026-05-05T08:00:56.417384+00:00",
    "flags" : [ {
      "label" : "vulnerable_code_not_present",
      "product_ids" : [ "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:e5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:f889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:ed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:a13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:fbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:a72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:bd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa_arm64" ]
    } ],
    "ids" : [ {
      "system_name" : "Red Hat Bugzilla ID",
      "text" : "2466660"
    } ],
    "notes" : [ {
      "category" : "description",
      "text" : "A flaw was found in Apache Thrift. This vulnerability involves improper validation of a certificate with a host mismatch, which could allow a remote attacker to bypass security checks. By presenting a specially crafted certificate, an attacker may impersonate a legitimate server or client. This could lead to a security bypass, potentially enabling unauthorized access or information disclosure.",
      "title" : "Vulnerability description"
    }, {
      "category" : "summary",
      "text" : "Apache Thrift: Apache Thrift: Security bypass due to improper certificate validation",
      "title" : "Vulnerability summary"
    }, {
      "category" : "general",
      "text" : "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
      "title" : "CVSS score applicability"
    } ],
    "product_status" : {
      "fixed" : [ "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:f1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052_s390x" ],
      "known_not_affected" : [ "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:e5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:f889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:ed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:a13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:fbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:a72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:bd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa_arm64" ]
    },
    "references" : [ {
      "category" : "self",
      "summary" : "Canonical URL",
      "url" : "https://access.redhat.com/security/cve/CVE-2026-43869"
    }, {
      "category" : "external",
      "summary" : "RHBZ#2466660",
      "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2466660"
    }, {
      "category" : "external",
      "summary" : "https://www.cve.org/CVERecord?id=CVE-2026-43869",
      "url" : "https://www.cve.org/CVERecord?id=CVE-2026-43869"
    }, {
      "category" : "external",
      "summary" : "https://nvd.nist.gov/vuln/detail/CVE-2026-43869",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-43869"
    }, {
      "category" : "external",
      "summary" : "https://lists.apache.org/thread/3hsgl1b69wzq3ry39scqbv2dhyl3j52r",
      "url" : "https://lists.apache.org/thread/3hsgl1b69wzq3ry39scqbv2dhyl3j52r"
    } ],
    "release_date" : "2026-05-05T07:25:48.611000+00:00",
    "remediations" : [ {
      "category" : "vendor_fix",
      "date" : "2026-06-18T16:31:31+00:00",
      "details" : "For details on how to apply this update, refer to:\n\nhttps://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/operators/administrator-tasks#olm-upgrading-operators",
      "product_ids" : [ "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:f1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052_s390x" ],
      "restart_required" : {
        "category" : "none"
      },
      "url" : "https://access.redhat.com/errata/RHSA-2026:27126"
    }, {
      "category" : "workaround",
      "details" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "product_ids" : [ "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:e5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:f889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:ed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:a13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:fbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:a72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:bd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:f1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052_s390x" ]
    } ],
    "scores" : [ {
      "cvss_v3" : {
        "attackComplexity" : "LOW",
        "attackVector" : "NETWORK",
        "availabilityImpact" : "LOW",
        "baseScore" : 7.3,
        "baseSeverity" : "HIGH",
        "confidentialityImpact" : "LOW",
        "integrityImpact" : "LOW",
        "privilegesRequired" : "NONE",
        "scope" : "UNCHANGED",
        "userInteraction" : "NONE",
        "vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
        "version" : "3.1"
      },
      "products" : [ "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:5cd85eb3e3db8bc1e9c6f4fabce36953900a458146b7ce708aa0855fcd7a0d8c_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:648a86d94ec347c50f841c2c29e42757c292dc524ab6846fcd5e8e042b62eaff_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:e5d2a94a4e349cc95a0e986b53ce84c465ab4db979ef744fa440b6c0c0e0d470_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:f889ac6aa2e58468186f26e23bbccb138a6a447812c5cd10f27abac59bbff66a_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:6d1a2f14570e24fdf67ead3be0f1009367de068cca2aabb52f208ab7de2f75cb_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:93d0e97f5a2e3a912b278e441ba0d5a12dfbaec7b5fbc74e0024370682835db8_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:964eb3aec90a5349573cf9051fd8216235f5df75df60cefa1be7169798405593_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-gateway-rhel9@sha256:ed07d775c269c34ade7d6542e767fecba8d8400e7b4dcf89ffd28dda78cab24c_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:0f3850087eaba5ed9eeb72d17daa80e9e54949ae8784b3188aab230f91972ba0_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:6ce0e7e216cd3ebde9e52aaefdb075be1b50a237ad0842b312f8ff57cc99bc0e_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:741666990f423912210682fd1f01ccff3443a1a9e7a364ee46fb6c72f0ed2c1b_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:8a117249236408257bf19cb9d600b03c851b94fa072acccef8ed1ebc18164354_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-operator-bundle@sha256:03cbea46e6fb4147cb6bcdccd049a1609d3f66901cb125363c52bb821a8ade47_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:6cbf17cad7cf17d49fa078900b19ef9cf4bc6465d259d75fb9137379445df991_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:7b3f78b81dd82c64012c2ef2b2c05dd9fbad2cb270f24fcdf592e606cdc4636e_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:a13fff512de7b06cce174b386e4f1804ea3a146e3a062a22f10e5dfc509daa7a_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-query-rhel9@sha256:fbe636335dbd0fac4680252d9240115207d8f0753c921d990df4aedbf9c0dbdf_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:72027f041985f99327ea415ee17139770d8d0bdcf7baf13b59591c60fb585b33_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:982cc78ad2616cbed77c2465d51fa61b78e54021ad84e8ecfd9b4aef80f6e39f_s390x", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:a72d0e29b18d3ef6cd8ec6fcfc047cbd51e7506ec8132530b6df89ea7c6fa912_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9-operator@sha256:bd369ccca53dc35702aad962ae86918076cbe113326d9e09589b2d3324e23bfa_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:49b701eaa9a8c0f97a4a2982b20ee510f294f0c7e06800890c953b98d3f1eebe_amd64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:4b79a6b2a5bd9cf17fe24da802779ae87710e522aeb3538007cf8c2326af2b39_ppc64le", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:8f3b20e29544cc58f8256df89322847fbbaca8e7292d1235da0be9b126d25a90_arm64", "Red Hat OpenShift distributed tracing 3.10.0:registry.redhat.io/rhosdt/tempo-rhel9@sha256:f1be50dfd7e9621bee928080a8f6f6fc0c9fb37e8c93931926faf4e5b50f1052_s390x" ]
    } ],
    "threats" : [ {
      "category" : "impact",
      "details" : "Important"
    } ],
    "title" : "Apache Thrift: Apache Thrift: Security bypass due to improper certificate validation"
  } ]
}