VDB
RHSA-2026%3A22423
RHSA-2026%3A22423
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in Tempo. A remote attacker can exploit this vulnerability by sending large queries to the Tempo service. This can lead to excessive memory allocations, potentially causing a Denial of Service (DoS) by impacting the availability of the service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:031c9b259f062e07131ae61ad1b354b9362e768fe14bdd1794754e83424f4a20_amd64 as a component of Multicluster Global Hub 1.3.4 | *, *, * |
| Red Hat | registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:d5ebd2285f925a5d6efb9bf712ee41aa45dc4cce7ff50a0aca83da5155d4aa8c_arm64 as a component of Multicluster Global Hub 1.3.4 | *, *, * |
| Red Hat | registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:2b952d5fb1960f40a3f05b351f958829b3a61a31fce495a3af751a063929889d_arm64 as a component of Multicluster Global Hub 1.3.4 | *, *, * |
| Red Hat | multicluster-globalhub | |
| Red Hat | registry.redhat.io/multicluster-globalhub/multicluster-globalhub-operator-bundle@sha256:a1d22f270c8e8b6fdb8324bf13b116382c0364058f28ba043128b93772ff33d3_amd64 as a component of Multicluster Global Hub 1.3.4 | *, *, * |
| Red Hat | registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:9db7d9dc19cb6cf1392ea70441d1eb98535f9cfeb478230156ab11f556657b02_amd64 as a component of Multicluster Global Hub 1.3.4 | *, *, * |
| Red Hat | registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:7a1cd2f61dfac63ccec20638eed4ad39b8a3a0d5d78bd68345885af030a1af0b_s390x as a component of Multicluster Global Hub 1.3.4 | *, *, * |
| golang | Go | |
| Red Hat | registry.redhat.io/multicluster-globalhub/multicluster-globalhub-rhel9-operator@sha256:debed0fd65dfd3106368fbdad8a3730888c73ffca97a009054a0f2a64bd6ef8c_amd64 as a component of Multicluster Global Hub 1.3.4 | *, *, * |
| Red Hat | registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:9438798cc9dfaf0d93675dd5a6cf1162ff8025f49ab162374e74dffa67f4c1ee_amd64 as a component of Multicluster Global Hub 1.3.4 | |
| Red Hat | registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:823597446afec693451e47ebf73fd61d625e6fc327970340d4226b26a71f4707_s390x as a component of Multicluster Global Hub 1.3.4 | *, *, * |
| Red Hat | registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:2e19aabfe25fff53230af0e6236eb19ca44004f47e1ebfe9add5acf9ba3ba525_ppc64le as a component of Multicluster Global Hub 1.3.4 | *, *, * |
| Red Hat | registry.redhat.io/multicluster-globalhub/multicluster-globalhub-manager-rhel9@sha256:7b3abb4db8da02cb6c51b78fa7b8ee19cf0f9640902a5925a7bc2c41d6d25d69_arm64 as a component of Multicluster Global Hub 1.3.4 | *, *, * |
| golang | go | |
| Red Hat | registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:6fb8506afd2e5f295305dc044e86a3059c1c91052715079388f2ea54a746fb38_ppc64le as a component of Multicluster Global Hub 1.3.4 | *, *, * |
| Red Hat | registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:03b18d051be128024f03df408069e5ad2346a2799115a4e13ad7cb394daabe3b_arm64 as a component of Multicluster Global Hub 1.3.4 | *, *, * |
| Go | ||
| Red Hat | registry.redhat.io/multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9@sha256:9438798cc9dfaf0d93675dd5a6cf1162ff8025f49ab162374e74dffa67f4c1ee_amd64 as a component of Multicluster Global Hub 1.3.4 | *, *, * |
…and 10 more
Timeline
- Jun 2, 2026 CVE Published
- Jun 2, 2026 Distribution Patch
- Jun 2, 2026 Distribution Patch
- Jun 2, 2026 Security Advisory
- Jun 2, 2026 Security Advisory
- Jun 2, 2026 Security Advisory
- Jun 2, 2026 Security Advisory
- Jun 2, 2026 Security Advisory
- Jun 2, 2026 Security Advisory
- Jun 2, 2026 Security Advisory
- Jun 2, 2026 Security Advisory
- Jun 2, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2026:22423 advisory
- https://access.redhat.com/security/cve/CVE-2026-21728 advisory
- https://access.redhat.com/security/cve/CVE-2026-25679 advisory
- https://access.redhat.com/security/cve/CVE-2026-27137 advisory
- https://access.redhat.com/security/cve/CVE-2026-32282 advisory
- https://access.redhat.com/security/cve/CVE-2026-32283 advisory
- https://access.redhat.com/security/cve/CVE-2026-32285 advisory
- https://access.redhat.com/security/cve/CVE-2026-32286 advisory
- https://access.redhat.com/security/cve/CVE-2026-33186 advisory
- https://access.redhat.com/security/cve/CVE-2026-33487 advisory
- https://access.redhat.com/security/cve/CVE-2026-33815 advisory
- https://access.redhat.com/security/cve/CVE-2026-33816 advisory
- https://access.redhat.com/security/cve/CVE-2026-34986 advisory
- https://access.redhat.com/security/cve/CVE-2026-41602 advisory
- https://access.redhat.com/security/cve/CVE-2026-41603 advisory
- https://access.redhat.com/security/cve/CVE-2026-41604 advisory
- https://access.redhat.com/security/cve/CVE-2026-41605 advisory
- https://access.redhat.com/security/cve/CVE-2026-41606 advisory
- https://access.redhat.com/security/cve/CVE-2026-41607 advisory
- https://access.redhat.com/security/cve/CVE-2026-41636 advisory
…and 99 more