{
  "document" : {
    "aggregate_severity" : {
      "namespace" : "https://access.redhat.com/security/updates/classification/",
      "text" : "Important"
    },
    "category" : "csaf_security_advisory",
    "csaf_version" : "2.0",
    "distribution" : {
      "text" : "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp" : {
        "label" : "WHITE",
        "url" : "https://www.first.org/tlp/"
      }
    },
    "lang" : "en",
    "notes" : [ {
      "category" : "summary",
      "text" : "An update for Red Hat Hardened Images RPMs is now available.",
      "title" : "Topic"
    }, {
      "category" : "general",
      "text" : "This update includes the following RPMs:\n\ngrafana12.4:\n  * grafana12.4-12.4.8-0.1.1.hum1 (aarch64, x86_64)\n  * grafana12.4-12.4.8-0.1.1.hum1.src (src)\n\nSecurity Fix(es):\n\ngrafana12.4:\n  * CVE-2026-73086\n  * CVE-2026-73088\n  * CVE-2026-73089",
      "title" : "Details"
    }, {
      "category" : "legal_disclaimer",
      "text" : "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
      "title" : "Terms of Use"
    } ],
    "publisher" : {
      "category" : "vendor",
      "contact_details" : "https://access.redhat.com/security/team/contact/",
      "issuing_authority" : "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name" : "Red Hat Product Security",
      "namespace" : "https://www.redhat.com"
    },
    "references" : [ {
      "category" : "self",
      "summary" : "https://access.redhat.com/errata/RHSA-2026:54518",
      "url" : "https://access.redhat.com/errata/RHSA-2026:54518"
    }, {
      "category" : "external",
      "summary" : "https://access.redhat.com/security/cve/CVE-2026-73086",
      "url" : "https://access.redhat.com/security/cve/CVE-2026-73086"
    }, {
      "category" : "external",
      "summary" : "https://access.redhat.com/security/cve/CVE-2026-73088",
      "url" : "https://access.redhat.com/security/cve/CVE-2026-73088"
    }, {
      "category" : "external",
      "summary" : "https://access.redhat.com/security/cve/CVE-2026-73089",
      "url" : "https://access.redhat.com/security/cve/CVE-2026-73089"
    }, {
      "category" : "external",
      "summary" : "https://access.redhat.com/security/updates/classification/",
      "url" : "https://access.redhat.com/security/updates/classification/"
    }, {
      "category" : "external",
      "summary" : "https://images.redhat.com/",
      "url" : "https://images.redhat.com/"
    }, {
      "category" : "external",
      "summary" : "https://access.redhat.com/security/cve/CVE-2026-45819",
      "url" : "https://access.redhat.com/security/cve/CVE-2026-45819"
    }, {
      "category" : "external",
      "summary" : "https://access.redhat.com/security/cve/CVE-2026-16221",
      "url" : "https://access.redhat.com/security/cve/CVE-2026-16221"
    }, {
      "category" : "self",
      "summary" : "Canonical URL",
      "url" : "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54518.json"
    } ],
    "title" : "Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update",
    "tracking" : {
      "current_release_date" : "2026-08-28T19:33:05+00:00",
      "generator" : {
        "date" : "2026-08-28T19:33:05+00:00",
        "engine" : {
          "name" : "Red Hat SDEngine",
          "version" : "5.3.16"
        }
      },
      "id" : "RHSA-2026:54518",
      "initial_release_date" : "2026-08-13T10:01:03+00:00",
      "revision_history" : [ {
        "date" : "2026-08-13T10:01:03+00:00",
        "number" : "1",
        "summary" : "Initial version"
      }, {
        "date" : "2026-08-22T06:15:42+00:00",
        "number" : "2",
        "summary" : "Last updated version"
      }, {
        "date" : "2026-08-28T19:33:05+00:00",
        "number" : "3",
        "summary" : "Last generated version"
      } ],
      "status" : "final",
      "version" : "3"
    }
  },
  "product_tree" : {
    "branches" : [ {
      "branches" : [ {
        "branches" : [ {
          "category" : "product_name",
          "name" : "Red Hat Hardened Images",
          "product" : {
            "name" : "Red Hat Hardened Images",
            "product_id" : "Red Hat Hardened Images",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:redhat:hummingbird:1"
            }
          }
        } ],
        "category" : "product_family",
        "name" : "Red Hat Hardened Images"
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "grafana12-4-main@aarch64",
          "product" : {
            "name" : "grafana12-4-main@aarch64",
            "product_id" : "grafana12-4-main@aarch64",
            "product_identification_helper" : {
              "purl" : "pkg:rpm/redhat/grafana12.4@12.4.8-0.1.1.hum1?arch=aarch64&distro=hummingbird-20251124&repository_id=public-hummingbird-aarch64-rpms"
            }
          }
        } ],
        "category" : "architecture",
        "name" : "aarch64"
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "grafana12-4-main@src",
          "product" : {
            "name" : "grafana12-4-main@src",
            "product_id" : "grafana12-4-main@src",
            "product_identification_helper" : {
              "purl" : "pkg:rpm/redhat/grafana12.4@12.4.8-0.1.1.hum1?arch=src&distro=hummingbird-20251124&repository_id=public-hummingbird-source-rpms"
            }
          }
        } ],
        "category" : "architecture",
        "name" : "src"
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "grafana12-4-main@x86_64",
          "product" : {
            "name" : "grafana12-4-main@x86_64",
            "product_id" : "grafana12-4-main@x86_64",
            "product_identification_helper" : {
              "purl" : "pkg:rpm/redhat/grafana12.4@12.4.8-0.1.1.hum1?arch=x86_64&distro=hummingbird-20251124&repository_id=public-hummingbird-x86_64-rpms"
            }
          }
        } ],
        "category" : "architecture",
        "name" : "x86_64"
      } ],
      "category" : "vendor",
      "name" : "Red Hat"
    } ],
    "relationships" : [ {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "grafana12-4-main@aarch64 as a component of Red Hat Hardened Images",
        "product_id" : "Red Hat Hardened Images:grafana12-4-main@aarch64"
      },
      "product_reference" : "grafana12-4-main@aarch64",
      "relates_to_product_reference" : "Red Hat Hardened Images"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "grafana12-4-main@src as a component of Red Hat Hardened Images",
        "product_id" : "Red Hat Hardened Images:grafana12-4-main@src"
      },
      "product_reference" : "grafana12-4-main@src",
      "relates_to_product_reference" : "Red Hat Hardened Images"
    }, {
      "category" : "default_component_of",
      "full_product_name" : {
        "name" : "grafana12-4-main@x86_64 as a component of Red Hat Hardened Images",
        "product_id" : "Red Hat Hardened Images:grafana12-4-main@x86_64"
      },
      "product_reference" : "grafana12-4-main@x86_64",
      "relates_to_product_reference" : "Red Hat Hardened Images"
    } ]
  },
  "vulnerabilities" : [ {
    "cve" : "CVE-2026-16221",
    "cwe" : {
      "id" : "CWE-807",
      "name" : "Reliance on Untrusted Inputs in a Security Decision"
    },
    "discovery_date" : "2026-07-19T15:02:40.167601+00:00",
    "ids" : [ {
      "system_name" : "Red Hat Bugzilla ID",
      "text" : "2502307"
    } ],
    "notes" : [ {
      "category" : "description",
      "text" : "A flaw was found in fast-uri. This vulnerability arises because fast-uri does not correctly interpret backslash characters as authority delimiters in Uniform Resource Locators (URLs), unlike Node.js's native WHATWG URL parser. This discrepancy can cause applications that use fast-uri for security policy enforcement, such as allowlists or Server-Side Request Forgery (SSRF) filtering, to misidentify the intended host. Consequently, an attacker could bypass these security policies, potentially redirecting traffic to unintended internal or sensitive network destinations.",
      "title" : "Vulnerability description"
    }, {
      "category" : "summary",
      "text" : "fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency",
      "title" : "Vulnerability summary"
    }, {
      "category" : "other",
      "text" : "Important: This flaw in fast-uri allows for a security policy bypass due to inconsistent URL parsing between fast-uri and Node.js's native WHATWG URL parser. Applications within Red Hat Hardened Images that rely on fast-uri for host-based policy enforcement, such as allowlists or Server-Side Request Forgery (SSRF) filtering, can be misled by specially crafted URLs. This could enable an attacker to redirect traffic to unintended internal or sensitive network destinations.",
      "title" : "Statement"
    }, {
      "category" : "general",
      "text" : "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
      "title" : "CVSS score applicability"
    } ],
    "product_status" : {
      "fixed" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ]
    },
    "references" : [ {
      "category" : "self",
      "summary" : "Canonical URL",
      "url" : "https://access.redhat.com/security/cve/CVE-2026-16221"
    }, {
      "category" : "external",
      "summary" : "RHBZ#2502307",
      "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2502307"
    }, {
      "category" : "external",
      "summary" : "https://www.cve.org/CVERecord?id=CVE-2026-16221",
      "url" : "https://www.cve.org/CVERecord?id=CVE-2026-16221"
    }, {
      "category" : "external",
      "summary" : "https://nvd.nist.gov/vuln/detail/CVE-2026-16221",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-16221"
    }, {
      "category" : "external",
      "summary" : "https://cna.openjsf.org/security-advisories.html",
      "url" : "https://cna.openjsf.org/security-advisories.html"
    }, {
      "category" : "external",
      "summary" : "https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx",
      "url" : "https://github.com/fastify/fast-uri/security/advisories/GHSA-v2hh-gcrm-f6hx"
    } ],
    "release_date" : "2026-07-19T14:08:32.993000+00:00",
    "remediations" : [ {
      "category" : "vendor_fix",
      "date" : "2026-08-13T10:01:03+00:00",
      "details" : "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
      "product_ids" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ],
      "restart_required" : {
        "category" : "none"
      },
      "url" : "https://access.redhat.com/errata/RHSA-2026:54518"
    }, {
      "category" : "workaround",
      "details" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "product_ids" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ]
    } ],
    "scores" : [ {
      "cvss_v3" : {
        "attackComplexity" : "LOW",
        "attackVector" : "NETWORK",
        "availabilityImpact" : "NONE",
        "baseScore" : 7.5,
        "baseSeverity" : "HIGH",
        "confidentialityImpact" : "NONE",
        "integrityImpact" : "HIGH",
        "privilegesRequired" : "NONE",
        "scope" : "UNCHANGED",
        "userInteraction" : "NONE",
        "vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
        "version" : "3.1"
      },
      "products" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ]
    } ],
    "threats" : [ {
      "category" : "impact",
      "details" : "Important"
    } ],
    "title" : "fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency"
  }, {
    "cve" : "CVE-2026-45819",
    "cwe" : {
      "id" : "CWE-617",
      "name" : "Reachable Assertion"
    },
    "discovery_date" : "2026-08-13T11:30:54.323606+00:00",
    "ids" : [ {
      "system_name" : "Red Hat Bugzilla ID",
      "text" : "2515240"
    } ],
    "notes" : [ {
      "category" : "description",
      "text" : "A flaw was found in baseline-browser-mapping. This vulnerability allows an attacker to cause a denial of service by providing invalid or conflicting input parameters. The affected component improperly terminates the process instead of handling the input error gracefully, leading to immediate service disruption.",
      "title" : "Vulnerability description"
    }, {
      "category" : "summary",
      "text" : "baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling",
      "title" : "Vulnerability summary"
    }, {
      "category" : "other",
      "text" : "Important: This flaw in the 'baseline-browser-mapping' library can result in a denial of service. Applications utilizing this library may unexpectedly terminate if they process invalid or conflicting input parameters, potentially disrupting services.",
      "title" : "Statement"
    }, {
      "category" : "general",
      "text" : "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
      "title" : "CVSS score applicability"
    } ],
    "product_status" : {
      "fixed" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ]
    },
    "references" : [ {
      "category" : "self",
      "summary" : "Canonical URL",
      "url" : "https://access.redhat.com/security/cve/CVE-2026-45819"
    }, {
      "category" : "external",
      "summary" : "RHBZ#2515240",
      "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2515240"
    }, {
      "category" : "external",
      "summary" : "https://www.cve.org/CVERecord?id=CVE-2026-45819",
      "url" : "https://www.cve.org/CVERecord?id=CVE-2026-45819"
    }, {
      "category" : "external",
      "summary" : "https://nvd.nist.gov/vuln/detail/CVE-2026-45819",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-45819"
    }, {
      "category" : "external",
      "summary" : "https://github.com/web-platform-dx/baseline-browser-mapping/blob/b7881aa61c8a057e24468ab5ee18c5ecedbbf691/src/index.ts#L142",
      "url" : "https://github.com/web-platform-dx/baseline-browser-mapping/blob/b7881aa61c8a057e24468ab5ee18c5ecedbbf691/src/index.ts#L142"
    }, {
      "category" : "external",
      "summary" : "https://github.com/web-platform-dx/baseline-browser-mapping/pull/137/changes#diff-7ae45ad102eab3b6d7e7896acd08c427a9b25b346470d7bc6507b6481575d519",
      "url" : "https://github.com/web-platform-dx/baseline-browser-mapping/pull/137/changes#diff-7ae45ad102eab3b6d7e7896acd08c427a9b25b346470d7bc6507b6481575d519"
    }, {
      "category" : "external",
      "summary" : "https://www.npmjs.com/package/baseline-browser-mapping",
      "url" : "https://www.npmjs.com/package/baseline-browser-mapping"
    } ],
    "release_date" : "2026-08-13T11:03:42.504000+00:00",
    "remediations" : [ {
      "category" : "vendor_fix",
      "date" : "2026-08-13T10:01:03+00:00",
      "details" : "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
      "product_ids" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ],
      "restart_required" : {
        "category" : "none"
      },
      "url" : "https://access.redhat.com/errata/RHSA-2026:54518"
    }, {
      "category" : "workaround",
      "details" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "product_ids" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ]
    } ],
    "scores" : [ {
      "cvss_v3" : {
        "attackComplexity" : "LOW",
        "attackVector" : "NETWORK",
        "availabilityImpact" : "HIGH",
        "baseScore" : 7.5,
        "baseSeverity" : "HIGH",
        "confidentialityImpact" : "NONE",
        "integrityImpact" : "NONE",
        "privilegesRequired" : "NONE",
        "scope" : "UNCHANGED",
        "userInteraction" : "NONE",
        "vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
        "version" : "3.1"
      },
      "products" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ]
    } ],
    "threats" : [ {
      "category" : "impact",
      "details" : "Important"
    } ],
    "title" : "baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling"
  }, {
    "cve" : "CVE-2026-73086",
    "cwe" : {
      "id" : "CWE-1241",
      "name" : "Use of Predictable Algorithm in Random Number Generator"
    },
    "discovery_date" : "2026-08-11T17:11:45.607696+00:00",
    "ids" : [ {
      "system_name" : "Red Hat Bugzilla ID",
      "text" : "2514175"
    } ],
    "notes" : [ {
      "category" : "description",
      "text" : "A flaw was found in nanoid, a JavaScript library for generating unique string IDs. A remote attacker could exploit an integer overflow vulnerability by providing a specific input to the `nanoid(size)` function. This issue causes the internal random number generator to become predictable, leading to the generation of identical identifiers for session tokens, security tokens (Cross-Site Request Forgery (CSRF) tokens), and API keys. Such predictability could allow an attacker to bypass security measures that rely on unique and random identifiers.",
      "title" : "Vulnerability description"
    }, {
      "category" : "summary",
      "text" : "nanoid: nanoid: Predictable ID generation due to integer overflow",
      "title" : "Vulnerability summary"
    }, {
      "category" : "other",
      "text" : "Important: This flaw in the nanoid JavaScript library allows a remote attacker to cause predictable ID generation by exploiting an integer overflow in the `nanoid(size)` function. This can lead to the compromise of session tokens, CSRF tokens, and API keys, bypassing security mechanisms. The attack requires specific conditions, contributing to its Important severity rather than Critical.",
      "title" : "Statement"
    }, {
      "category" : "general",
      "text" : "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
      "title" : "CVSS score applicability"
    } ],
    "product_status" : {
      "fixed" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ]
    },
    "references" : [ {
      "category" : "self",
      "summary" : "Canonical URL",
      "url" : "https://access.redhat.com/security/cve/CVE-2026-73086"
    }, {
      "category" : "external",
      "summary" : "RHBZ#2514175",
      "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2514175"
    }, {
      "category" : "external",
      "summary" : "https://www.cve.org/CVERecord?id=CVE-2026-73086",
      "url" : "https://www.cve.org/CVERecord?id=CVE-2026-73086"
    }, {
      "category" : "external",
      "summary" : "https://nvd.nist.gov/vuln/detail/CVE-2026-73086",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-73086"
    }, {
      "category" : "external",
      "summary" : "https://github.com/ai/nanoid/commit/7087969281cab8ba8ae3babf1894e819068b3bb4",
      "url" : "https://github.com/ai/nanoid/commit/7087969281cab8ba8ae3babf1894e819068b3bb4"
    }, {
      "category" : "external",
      "summary" : "https://github.com/ai/nanoid/commit/821dfed7b5db7f88e92f56c60eef32c8135077c3",
      "url" : "https://github.com/ai/nanoid/commit/821dfed7b5db7f88e92f56c60eef32c8135077c3"
    }, {
      "category" : "external",
      "summary" : "https://github.com/ai/nanoid/commit/b0036ed60dc9facd7f1191a50dfb3076500202ac",
      "url" : "https://github.com/ai/nanoid/commit/b0036ed60dc9facd7f1191a50dfb3076500202ac"
    }, {
      "category" : "external",
      "summary" : "https://github.com/ai/nanoid/releases/tag/3.3.12",
      "url" : "https://github.com/ai/nanoid/releases/tag/3.3.12"
    }, {
      "category" : "external",
      "summary" : "https://github.com/ai/nanoid/releases/tag/5.1.11",
      "url" : "https://github.com/ai/nanoid/releases/tag/5.1.11"
    }, {
      "category" : "external",
      "summary" : "https://github.com/ai/nanoid/security/advisories/GHSA-xwg4-73v4-xw9w",
      "url" : "https://github.com/ai/nanoid/security/advisories/GHSA-xwg4-73v4-xw9w"
    } ],
    "release_date" : "2026-08-11T16:46:23.024000+00:00",
    "remediations" : [ {
      "category" : "vendor_fix",
      "date" : "2026-08-13T10:01:03+00:00",
      "details" : "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
      "product_ids" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ],
      "restart_required" : {
        "category" : "none"
      },
      "url" : "https://access.redhat.com/errata/RHSA-2026:54518"
    }, {
      "category" : "workaround",
      "details" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "product_ids" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ]
    } ],
    "scores" : [ {
      "cvss_v3" : {
        "attackComplexity" : "HIGH",
        "attackVector" : "NETWORK",
        "availabilityImpact" : "NONE",
        "baseScore" : 7.4,
        "baseSeverity" : "HIGH",
        "confidentialityImpact" : "HIGH",
        "integrityImpact" : "HIGH",
        "privilegesRequired" : "NONE",
        "scope" : "UNCHANGED",
        "userInteraction" : "NONE",
        "vectorString" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
        "version" : "3.1"
      },
      "products" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ]
    } ],
    "threats" : [ {
      "category" : "impact",
      "details" : "Important"
    } ],
    "title" : "nanoid: nanoid: Predictable ID generation due to integer overflow"
  }, {
    "cve" : "CVE-2026-73088",
    "cwe" : {
      "id" : "CWE-915",
      "name" : "Improperly Controlled Modification of Dynamically-Determined Object Attributes"
    },
    "discovery_date" : "2026-08-11T17:11:53.228719+00:00",
    "ids" : [ {
      "system_name" : "Red Hat Bugzilla ID",
      "text" : "2514177"
    } ],
    "notes" : [ {
      "category" : "description",
      "text" : "A flaw was found in Browserslist, a tool for sharing browser and Node.js versions. An attacker could provide specially crafted statistics data, which the tool processes without proper validation. This improper handling of untrusted data can lead to prototype pollution, potentially causing the application to crash and resulting in a denial of service.",
      "title" : "Vulnerability description"
    }, {
      "category" : "summary",
      "text" : "browserslist: Browserslist: Prototype pollution leading to denial of service",
      "title" : "Vulnerability summary"
    }, {
      "category" : "other",
      "text" : "This is an Important vulnerability. The browserslist package, a front-end development tool, is vulnerable to prototype pollution when processing untrusted statistics data. This flaw can lead to a denial of service, as malicious input can crash applications that use the affected library. The impact is considered Important due to the potential for remote exploitation without authentication or user interaction, directly affecting service availability.",
      "title" : "Statement"
    }, {
      "category" : "general",
      "text" : "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
      "title" : "CVSS score applicability"
    } ],
    "product_status" : {
      "fixed" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ]
    },
    "references" : [ {
      "category" : "self",
      "summary" : "Canonical URL",
      "url" : "https://access.redhat.com/security/cve/CVE-2026-73088"
    }, {
      "category" : "external",
      "summary" : "RHBZ#2514177",
      "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2514177"
    }, {
      "category" : "external",
      "summary" : "https://www.cve.org/CVERecord?id=CVE-2026-73088",
      "url" : "https://www.cve.org/CVERecord?id=CVE-2026-73088"
    }, {
      "category" : "external",
      "summary" : "https://nvd.nist.gov/vuln/detail/CVE-2026-73088",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-73088"
    }, {
      "category" : "external",
      "summary" : "https://github.com/browserslist/browserslist/commit/f9914ad9effc865ccc27d816255625890b31ca51",
      "url" : "https://github.com/browserslist/browserslist/commit/f9914ad9effc865ccc27d816255625890b31ca51"
    }, {
      "category" : "external",
      "summary" : "https://github.com/browserslist/browserslist/releases/tag/4.28.7",
      "url" : "https://github.com/browserslist/browserslist/releases/tag/4.28.7"
    }, {
      "category" : "external",
      "summary" : "https://github.com/browserslist/browserslist/security/advisories/GHSA-73wf-gq98-2v4g",
      "url" : "https://github.com/browserslist/browserslist/security/advisories/GHSA-73wf-gq98-2v4g"
    } ],
    "release_date" : "2026-08-11T17:00:05.869000+00:00",
    "remediations" : [ {
      "category" : "vendor_fix",
      "date" : "2026-08-13T10:01:03+00:00",
      "details" : "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
      "product_ids" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ],
      "restart_required" : {
        "category" : "none"
      },
      "url" : "https://access.redhat.com/errata/RHSA-2026:54518"
    }, {
      "category" : "workaround",
      "details" : "To reduce exposure, ensure that the `browserslist` tool processes only trusted `browserslist-stats.json`, `opts.stats`, and CLI `--stats` data. Avoid using the tool with untrusted input sources in development or build environments. If `browserslist` is integrated into automated pipelines, validate all input data originates from trusted sources.",
      "product_ids" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ]
    } ],
    "scores" : [ {
      "cvss_v3" : {
        "attackComplexity" : "LOW",
        "attackVector" : "NETWORK",
        "availabilityImpact" : "HIGH",
        "baseScore" : 7.5,
        "baseSeverity" : "HIGH",
        "confidentialityImpact" : "NONE",
        "integrityImpact" : "NONE",
        "privilegesRequired" : "NONE",
        "scope" : "UNCHANGED",
        "userInteraction" : "NONE",
        "vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
        "version" : "3.1"
      },
      "products" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ]
    } ],
    "threats" : [ {
      "category" : "impact",
      "details" : "Important"
    } ],
    "title" : "browserslist: Browserslist: Prototype pollution leading to denial of service"
  }, {
    "cve" : "CVE-2026-73089",
    "cwe" : {
      "id" : "CWE-770",
      "name" : "Allocation of Resources Without Limits or Throttling"
    },
    "discovery_date" : "2026-08-11T17:12:48.012036+00:00",
    "ids" : [ {
      "system_name" : "Red Hat Bugzilla ID",
      "text" : "2514195"
    } ],
    "notes" : [ {
      "category" : "description",
      "text" : "A flaw was found in Browserslist, a configuration tool for front-end development. An attacker can exploit this vulnerability by influencing repeated query values, leading to unbounded memory growth. This issue can cause the application to consume excessive memory, resulting in an out-of-memory process crash and a Denial of Service (DoS) for affected systems.",
      "title" : "Vulnerability description"
    }, {
      "category" : "summary",
      "text" : "browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results",
      "title" : "Vulnerability summary"
    }, {
      "category" : "other",
      "text" : "This is an Important denial of service vulnerability in the `browserslist` library, which is used across several Red Hat products and services. The flaw allows an attacker to trigger unbounded memory growth by influencing query values, potentially leading to an out-of-memory crash and service unavailability. This is considered Important due to the potential for remote exploitation and significant impact on service stability.",
      "title" : "Statement"
    }, {
      "category" : "general",
      "text" : "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
      "title" : "CVSS score applicability"
    } ],
    "product_status" : {
      "fixed" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ]
    },
    "references" : [ {
      "category" : "self",
      "summary" : "Canonical URL",
      "url" : "https://access.redhat.com/security/cve/CVE-2026-73089"
    }, {
      "category" : "external",
      "summary" : "RHBZ#2514195",
      "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2514195"
    }, {
      "category" : "external",
      "summary" : "https://www.cve.org/CVERecord?id=CVE-2026-73089",
      "url" : "https://www.cve.org/CVERecord?id=CVE-2026-73089"
    }, {
      "category" : "external",
      "summary" : "https://nvd.nist.gov/vuln/detail/CVE-2026-73089",
      "url" : "https://nvd.nist.gov/vuln/detail/CVE-2026-73089"
    }, {
      "category" : "external",
      "summary" : "https://github.com/browserslist/browserslist/commit/f2931a3ff2a3a31abf84ef01a7400b270aad6405",
      "url" : "https://github.com/browserslist/browserslist/commit/f2931a3ff2a3a31abf84ef01a7400b270aad6405"
    }, {
      "category" : "external",
      "summary" : "https://github.com/browserslist/browserslist/releases/tag/4.28.7",
      "url" : "https://github.com/browserslist/browserslist/releases/tag/4.28.7"
    }, {
      "category" : "external",
      "summary" : "https://github.com/browserslist/browserslist/security/advisories/GHSA-c83g-rgw3-j3cx",
      "url" : "https://github.com/browserslist/browserslist/security/advisories/GHSA-c83g-rgw3-j3cx"
    } ],
    "release_date" : "2026-08-11T17:05:38.760000+00:00",
    "remediations" : [ {
      "category" : "vendor_fix",
      "date" : "2026-08-13T10:01:03+00:00",
      "details" : "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
      "product_ids" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ],
      "restart_required" : {
        "category" : "none"
      },
      "url" : "https://access.redhat.com/errata/RHSA-2026:54518"
    }, {
      "category" : "workaround",
      "details" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
      "product_ids" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ]
    } ],
    "scores" : [ {
      "cvss_v3" : {
        "attackComplexity" : "LOW",
        "attackVector" : "NETWORK",
        "availabilityImpact" : "HIGH",
        "baseScore" : 7.5,
        "baseSeverity" : "HIGH",
        "confidentialityImpact" : "NONE",
        "integrityImpact" : "NONE",
        "privilegesRequired" : "NONE",
        "scope" : "UNCHANGED",
        "userInteraction" : "NONE",
        "vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
        "version" : "3.1"
      },
      "products" : [ "Red Hat Hardened Images:grafana12-4-main@aarch64", "Red Hat Hardened Images:grafana12-4-main@src", "Red Hat Hardened Images:grafana12-4-main@x86_64" ]
    } ],
    "threats" : [ {
      "category" : "impact",
      "details" : "Important"
    } ],
    "title" : "browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results"
  } ]
}