{"id":"RHSA-2026:68778","summary":"Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update","modified":"2026-09-24T10:42:30.324478811Z","published":"2026-09-22T10:19:31Z","upstream":["CVE-2026-28374","CVE-2026-28376","CVE-2026-28379","CVE-2026-28380","CVE-2026-28383","CVE-2026-33376","CVE-2026-33377","CVE-2026-33378","CVE-2026-33380","CVE-2026-33381","CVE-2026-42127","CVE-2026-81871","CVE-2026-81872","CVE-2026-92599"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:68778"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-81871"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/"},{"type":"ARTICLE","url":"https://images.redhat.com/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-33380"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-33378"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-28374"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-33377"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-28380"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-33381"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-28376"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-28379"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-33376"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-28383"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-81872"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-92599"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-42127"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68778.json"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477253"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-28374"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28374"},{"type":"ARTICLE","url":"https://grafana.com/security/security-advisories/cve-2026-28374"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477259"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-28376"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28376"},{"type":"ARTICLE","url":"https://grafana.com/security/security-advisories/cve-2026-28376"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477264"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-28379"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28379"},{"type":"ARTICLE","url":"https://grafana.com/security/security-advisories/cve-2026-28379"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477240"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-28380"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28380"},{"type":"ARTICLE","url":"https://grafana.com/security/security-advisories/cve-2026-28380"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477255"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-28383"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28383"},{"type":"ARTICLE","url":"https://grafana.com/security/security-advisories/cve-2026-28383"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477262"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-33376"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33376"},{"type":"ARTICLE","url":"https://grafana.com/security/security-advisories/cve-2026-33376"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477246"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-33377"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33377"},{"type":"ARTICLE","url":"https://grafana.com/security/security-advisories/cve-2026-33377"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477269"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-33378"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33378"},{"type":"ARTICLE","url":"https://grafana.com/security/security-advisories/cve-2026-33378"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477248"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-33380"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33380"},{"type":"ARTICLE","url":"https://grafana.com/security/security-advisories/cve-2026-33380"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477239"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-33381"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33381"},{"type":"ARTICLE","url":"https://grafana.com/security/security-advisories/cve-2026-33381"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491449"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-42127"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42127"},{"type":"ARTICLE","url":"https://grafana.com/security/security-advisories/cve-2026-42127"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2535725"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-81871"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81871"},{"type":"ARTICLE","url":"https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c"},{"type":"ARTICLE","url":"https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/otlp/otlplog/otlploggrpc/v0.21.0"},{"type":"ARTICLE","url":"https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w34q-cm8f-9c5x"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2535727"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-81872"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81872"},{"type":"ARTICLE","url":"https://github.com/open-telemetry/opentelemetry-go/commit/ba71b09e6ed272e93a669aeaec1e98b1df4cc582"},{"type":"ARTICLE","url":"https://github.com/open-telemetry/opentelemetry-go/issues/6797"},{"type":"ARTICLE","url":"https://github.com/open-telemetry/opentelemetry-go/pull/8620"},{"type":"ARTICLE","url":"https://github.com/open-telemetry/opentelemetry-go/releases/tag/sdk/log/v0.21.0"},{"type":"ARTICLE","url":"https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-hjf4-fphr-2h65"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2538354"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-92599"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92599"},{"type":"ARTICLE","url":"https://github.com/hapijs/joi/security/advisories/GHSA-6h2x-m376-mqjq"},{"type":"ARTICLE","url":"https://www.vulncheck.com/advisories/joi-before-17.13.7-and-18.2.6-redos-via-isodate"}],"affected":[{"package":{"name":"grafana13.2","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/grafana13.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:13.2.1-0.5.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:68778.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}