Red Hat Product Errata RHSA-2026:35830 - Security Advisory Issued: 2026-07-06 Updated: 2026-07-06 RHSA-2026:35830 - Security Advisory Overview Updated Packages Synopsis Important: grafana security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for grafana is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVEs CVE-2026-39821 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM grafana-9.2.10-31.el8_10.src.rpm SHA-256: dc5ebb9e8446ffbb6109c2d0d3331c46bd46b272059c4727accd87b8fb6aed6f x86_64 grafana-9.2.10-31.el8_10.x86_64.rpm SHA-256: ac15679ba8fad8870dab3d1856495a741a216fd3937f97e31e52d4cb077f1803 grafana-debuginfo-9.2.10-31.el8_10.x86_64.rpm SHA-256: d28abe2bdedf034b4ba21388174a225db3cb13125d34025a5b3f1251af1bdbbf grafana-debugsource-9.2.10-31.el8_10.x86_64.rpm SHA-256: 16b9b8960390aeb5ed23b690dc60da9dcdcbc6380c43c49e6d891c6c30ffff9f grafana-selinux-9.2.10-31.el8_10.x86_64.rpm SHA-256: 38d311be56c5fada76334f654c809264f257763d3112515adf3f062d866487da Red Hat Enterprise Linux for IBM z Systems 8 SRPM grafana-9.2.10-31.el8_10.src.rpm SHA-256: dc5ebb9e8446ffbb6109c2d0d3331c46bd46b272059c4727accd87b8fb6aed6f s390x grafana-9.2.10-31.el8_10.s390x.rpm SHA-256: 7af933c236dd10c34ef66a59d4a377585153634418c378e5319b841d79104541 grafana-debuginfo-9.2.10-31.el8_10.s390x.rpm SHA-256: 4c7bf2023a35ec2e7a2707b8cc2ff1684e9660a139bcc484dae4b7b015894065 grafana-debugsource-9.2.10-31.el8_10.s390x.rpm SHA-256: 031d4b257e2eaff1de385aee3a084c7866a67cc50302bf63fb0fc8eaa6a96ebb grafana-selinux-9.2.10-31.el8_10.s390x.rpm SHA-256: 2d02cba195756f70bfb15107fa336969c5c6548ddfb90737b921b7fb83719e75 Red Hat Enterprise Linux for Power, little endian 8 SRPM grafana-9.2.10-31.el8_10.src.rpm SHA-256: dc5ebb9e8446ffbb6109c2d0d3331c46bd46b272059c4727accd87b8fb6aed6f ppc64le grafana-9.2.10-31.el8_10.ppc64le.rpm SHA-256: cd728a2fa7c0dc4aad5c17356d719c449c195538263022c7e3384e7caf0fc8d8 grafana-debuginfo-9.2.10-31.el8_10.ppc64le.rpm SHA-256: b6008b51d0240befa7f9569080d007ca4ba3a829124002316e3c09d95eb56af1 grafana-debugsource-9.2.10-31.el8_10.ppc64le.rpm SHA-256: add1e27e661ba30dedf80b7be1901bab1130ab694c638a4ff5ffe07ee1ae8f65 grafana-selinux-9.2.10-31.el8_10.ppc64le.rpm SHA-256: 34cd5534df6c338b384b385f4cb66b6723d5d56efbc84ad6616b3b013b173434 Red Hat Enterprise Linux for ARM 64 8 SRPM grafana-9.2.10-31.el8_10.src.rpm SHA-256: dc5ebb9e8446ffbb6109c2d0d3331c46bd46b272059c4727accd87b8fb6aed6f aarch64 grafana-9.2.10-31.el8_10.aarch64.rpm SHA-256: 284109c76acfabc5bc61c3fafd22e9275f7b4cb20575c994bdc4693724a59a32 grafana-debuginfo-9.2.10-31.el8_10.aarch64.rpm SHA-256: eb5447d70b9c9dafb64cd80afcebf5a7d1c2621b817e609f7168fcd2a37f3035 grafana-debugsource-9.2.10-31.el8_10.aarch64.rpm SHA-256: c209cf5b5102487bcd21c923bdc69ccf73f6a1141fa4e38df4fad91b92006849 grafana-selinux-9.2.10-31.el8_10.aarch64.rpm SHA-256: 41ae022446792d15a0d3523ad9b9d1c8455a4fa42a79d849c19c687dd20e95f6 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 SRPM grafana-9.2.10-31.el8_10.src.rpm SHA-256: dc5ebb9e8446ffbb6109c2d0d3331c46bd46b272059c4727accd87b8fb6aed6f x86_64 grafana-9.2.10-31.el8_10.x86_64.rpm SHA-256: ac15679ba8fad8870dab3d1856495a741a216fd3937f97e31e52d4cb077f1803 grafana-debuginfo-9.2.10-31.el8_10.x86_64.rpm SHA-256: d28abe2bdedf034b4ba21388174a225db3cb13125d34025a5b3f1251af1bdbbf grafana-debugsource-9.2.10-31.el8_10.x86_64.rpm SHA-256: 16b9b8960390aeb5ed23b690dc60da9dcdcbc6380c43c49e6d891c6c30ffff9f grafana-selinux-9.2.10-31.el8_10.x86_64.rpm SHA-256: 38d311be56c5fada76334f654c809264f257763d3112515adf3f062d866487da Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 SRPM grafana-9.2.10-31.el8_10.src.rpm SHA-256: dc5ebb9e8446ffbb6109c2d0d3331c46bd46b272059c4727accd87b8fb6aed6f aarch64 grafana-9.2.10-31.el8_10.aarch64.rpm SHA-256: 284109c76acfabc5bc61c3fafd22e9275f7b4cb20575c994bdc4693724a59a32 grafana-debuginfo-9.2.10-31.el8_10.aarch64.rpm SHA-256: eb5447d70b9c9dafb64cd80afcebf5a7d1c2621b817e609f7168fcd2a37f3035 grafana-debugsource-9.2.10-31.el8_10.aarch64.rpm SHA-256: c209cf5b5102487bcd21c923bdc69ccf73f6a1141fa4e38df4fad91b92006849 grafana-selinux-9.2.10-31.el8_10.aarch64.rpm SHA-256: 41ae022446792d15a0d3523ad9b9d1c8455a4fa42a79d849c19c687dd20e95f6 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 SRPM grafana-9.2.10-31.el8_10.src.rpm SHA-256: dc5ebb9e8446ffbb6109c2d0d3331c46bd46b272059c4727accd87b8fb6aed6f ppc64le grafana-9.2.10-31.el8_10.ppc64le.rpm SHA-256: cd728a2fa7c0dc4aad5c17356d719c449c195538263022c7e3384e7caf0fc8d8 grafana-debuginfo-9.2.10-31.el8_10.ppc64le.rpm SHA-256: b6008b51d0240befa7f9569080d007ca4ba3a829124002316e3c09d95eb56af1 grafana-debugsource-9.2.10-31.el8_10.ppc64le.rpm SHA-256: add1e27e661ba30dedf80b7be1901bab1130ab694c638a4ff5ffe07ee1ae8f65 grafana-selinux-9.2.10-31.el8_10.ppc64le.rpm SHA-256: 34cd5534df6c338b384b385f4cb66b6723d5d56efbc84ad6616b3b013b173434 Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 SRPM grafana-9.2.10-31.el8_10.src.rpm SHA-256: dc5ebb9e8446ffbb6109c2d0d3331c46bd46b272059c4727accd87b8fb6aed6f s390x grafana-9.2.10-31.el8_10.s390x.rpm SHA-256: 7af933c236dd10c34ef66a59d4a377585153634418c378e5319b841d79104541 grafana-debuginfo-9.2.10-31.el8_10.s390x.rpm SHA-256: 4c7bf2023a35ec2e7a2707b8cc2ff1684e9660a139bcc484dae4b7b015894065 grafana-debugsource-9.2.10-31.el8_10.s390x.rpm SHA-256: 031d4b257e2eaff1de385aee3a084c7866a67cc50302bf63fb0fc8eaa6a96ebb grafana-selinux-9.2.10-31.el8_10.s390x.rpm SHA-256: 2d02cba195756f70bfb15107fa336969c5c6548ddfb90737b921b7fb83719e75 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
A critical vulnerability (CVE-2026-39821, CVSS 9.6) in the golang.org/x/net/idna library allows privilege escalation via incorrect Punycode label processing. The flaw affects Grafana packages on RHEL 8, specifically those using a vulnerable version of the underlying Go net library prior to version 0.55.0. Red Hat has issued an Important security update to address this issue.