Red Hat Lightspeed
Red Hat Lightspeed continuously analyzes platforms and applications to predict risk, recommend actions, and track costs so enterprises can better manage hybrid cloud environments.
Browse the latest documentation
User Access Configuration Guide for Role-based Access Control (RBAC)Configuration (RHEL)
Viewing and managing system inventoryInventory (RHEL)
Deploying and managing RHEL systems in hybrid cloudsContent and images (RHEL)
Latest security advisories
| Severity | Advisory/CVE | Synopsis | Date |
|---|---|---|---|
| Severity Important | Advisory/CVECVE-2026-56858 | Synopsis A flaw was found in the `html/template` component of Go (golang). Pathological inputs could prematurely close an unescaped forward slash ('/'), allowing an attacker to inject arbitrary content. This could lead to Cross-Site Scripting (XSS), where malicious scripts are executed in a user's browser, potentially compromising user data or actions. | Date |
| Severity Important | Advisory/CVECVE-2026-56862 | Synopsis A flaw was found in the `crypto/tls` package, part of `golang`. A malicious client can exploit this vulnerability by continuously sending KeyUpdate messages to a server. This forces the server to perform indefinite key derivation operations, leading to resource exhaustion and a Denial of Service (DoS) condition. | Date |
| Severity Important | Advisory/CVECVE-2026-56859 | Synopsis A flaw was found in the `encoding/xml` package of Go. The `DecodeElement` function failed to correctly track recursion depth, which could lead to stack exhaustion. A remote attacker could exploit this vulnerability by providing a specially crafted XML input, resulting in a Denial of Service (DoS) for the affected application. | Date |
| Severity Important | Advisory/CVECVE-2026-71235 | Synopsis A flaw was found in Magistrala's Rules Engine. An authenticated low-privileged user can exploit this vulnerability by creating rules with embedded Go or Lua scripts. These scripts are executed server-side without sufficient validation, allowing for arbitrary file read and write operations, access to internal databases, and Server-Side Request Forgery (SSRF) against internal microservices. This could lead to significant data compromise and unauthorized system access. | Date |
| Severity Important | Advisory/CVECVE-2026-41178 | Synopsis A flaw was found in OpenTelemetry-Go. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by sending oversized or invalid baggage headers. The `Parse` function, in affected versions, failed to reject raw-length inputs, leading to excessive processing and error logging when handling these large inputs. | Date |
Top resources
Get support
Support cases
Get answers quickly by opening a support case with us.
Live chat
Directly access our support engineers during weekday business hours.
Call or email
Speak directly with a Red Hat Support expert by phone or through email.