RHSA-2026:65116: Important: opentelemetry
Synopsis
Important: opentelemetry-collector security update
Type/Severity
Security Advisory: Important
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
An update for opentelemetry-collector is now available for Red Hat Enterprise Linux 10.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
Collector with the supported components for a Red Hat build of OpenTelemetry
Security Fix(es):
- net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
- net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)
- mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
- github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178)
- encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
- net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
- net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
- html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
- crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
- encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
-
Red Hat Enterprise Linux for x86_64 10 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64
-
Red Hat Enterprise Linux for IBM z Systems 10 s390x
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x
-
Red Hat Enterprise Linux for Power, little endian 10 ppc64le
-
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le
-
Red Hat Enterprise Linux for ARM 64 10 aarch64
-
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64
-
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64
-
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x
-
Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le
-
Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64
-
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64
-
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le
-
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x
Fixes
-
BZ - 2467809
- CVE-2026-42499 net/mail: golang: net/mail: Denial of Service via pathological email address parsing
-
BZ - 2467820
- CVE-2026-39820 net/mail: golang: Go net/mail: Denial of Service via crafted email inputs
-
BZ - 2484204
- CVE-2026-42504 mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header
-
BZ - 2484830
- CVE-2026-41178 github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers
-
BZ - 2515815
- CVE-2026-33818 encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal
-
BZ - 2515820
- CVE-2026-56860 net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution
-
BZ - 2515827
- CVE-2026-56853 net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service
-
BZ - 2515838
- CVE-2026-56858 html/template: golang: Go html/template: Cross-Site Scripting via pathological input
-
BZ - 2515839
- CVE-2026-56862 crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages
-
BZ - 2515840
- CVE-2026-56859 encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux for x86_64 10
| SRPM |
|
opentelemetry-collector-0.152.1-2.el10_2.src.rpm
|
SHA-256: 24b0fd58b56af196824b67b77e17ec6f414c2c1e048ad037fcb0bd6c7409f4b2 |
| x86_64 |
|
opentelemetry-collector-0.152.1-2.el10_2.x86_64.rpm
|
SHA-256: 984cb2124a10255971c38165502c25c03e194703569af3fe882565ce855a3bb3 |
Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2
| SRPM |
|
opentelemetry-collector-0.152.1-2.el10_2.src.rpm
|
SHA-256: 24b0fd58b56af196824b67b77e17ec6f414c2c1e048ad037fcb0bd6c7409f4b2 |
| x86_64 |
|
opentelemetry-collector-0.152.1-2.el10_2.x86_64.rpm
|
SHA-256: 984cb2124a10255971c38165502c25c03e194703569af3fe882565ce855a3bb3 |
Red Hat Enterprise Linux for IBM z Systems 10
| SRPM |
|
opentelemetry-collector-0.152.1-2.el10_2.src.rpm
|
SHA-256: 24b0fd58b56af196824b67b77e17ec6f414c2c1e048ad037fcb0bd6c7409f4b2 |
| s390x |
|
opentelemetry-collector-0.152.1-2.el10_2.s390x.rpm
|
SHA-256: 832a99938d54152c4e83455ccafbb18c1d484d6a4d043c738bf28ed40302f177 |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2
| SRPM |
|
opentelemetry-collector-0.152.1-2.el10_2.src.rpm
|
SHA-256: 24b0fd58b56af196824b67b77e17ec6f414c2c1e048ad037fcb0bd6c7409f4b2 |
| s390x |
|
opentelemetry-collector-0.152.1-2.el10_2.s390x.rpm
|
SHA-256: 832a99938d54152c4e83455ccafbb18c1d484d6a4d043c738bf28ed40302f177 |
Red Hat Enterprise Linux for Power, little endian 10
| SRPM |
|
opentelemetry-collector-0.152.1-2.el10_2.src.rpm
|
SHA-256: 24b0fd58b56af196824b67b77e17ec6f414c2c1e048ad037fcb0bd6c7409f4b2 |
| ppc64le |
|
opentelemetry-collector-0.152.1-2.el10_2.ppc64le.rpm
|
SHA-256: 23cd0d97c0e12c8ce0109f7cfa4b36c31768a5d7249c0c46e2d400b1521d5973 |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2
| SRPM |
|
opentelemetry-collector-0.152.1-2.el10_2.src.rpm
|
SHA-256: 24b0fd58b56af196824b67b77e17ec6f414c2c1e048ad037fcb0bd6c7409f4b2 |
| ppc64le |
|
opentelemetry-collector-0.152.1-2.el10_2.ppc64le.rpm
|
SHA-256: 23cd0d97c0e12c8ce0109f7cfa4b36c31768a5d7249c0c46e2d400b1521d5973 |
Red Hat Enterprise Linux for ARM 64 10
| SRPM |
|
opentelemetry-collector-0.152.1-2.el10_2.src.rpm
|
SHA-256: 24b0fd58b56af196824b67b77e17ec6f414c2c1e048ad037fcb0bd6c7409f4b2 |
| aarch64 |
|
opentelemetry-collector-0.152.1-2.el10_2.aarch64.rpm
|
SHA-256: 41b36719c029110634d7d7826583b42538e98b6982f55f34b18731abbb82ba58 |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2
| SRPM |
|
opentelemetry-collector-0.152.1-2.el10_2.src.rpm
|
SHA-256: 24b0fd58b56af196824b67b77e17ec6f414c2c1e048ad037fcb0bd6c7409f4b2 |
| aarch64 |
|
opentelemetry-collector-0.152.1-2.el10_2.aarch64.rpm
|
SHA-256: 41b36719c029110634d7d7826583b42538e98b6982f55f34b18731abbb82ba58 |
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2
| SRPM |
|
opentelemetry-collector-0.152.1-2.el10_2.src.rpm
|
SHA-256: 24b0fd58b56af196824b67b77e17ec6f414c2c1e048ad037fcb0bd6c7409f4b2 |
| aarch64 |
|
opentelemetry-collector-0.152.1-2.el10_2.aarch64.rpm
|
SHA-256: 41b36719c029110634d7d7826583b42538e98b6982f55f34b18731abbb82ba58 |
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2
| SRPM |
|
opentelemetry-collector-0.152.1-2.el10_2.src.rpm
|
SHA-256: 24b0fd58b56af196824b67b77e17ec6f414c2c1e048ad037fcb0bd6c7409f4b2 |
| s390x |
|
opentelemetry-collector-0.152.1-2.el10_2.s390x.rpm
|
SHA-256: 832a99938d54152c4e83455ccafbb18c1d484d6a4d043c738bf28ed40302f177 |
Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2
| SRPM |
|
opentelemetry-collector-0.152.1-2.el10_2.src.rpm
|
SHA-256: 24b0fd58b56af196824b67b77e17ec6f414c2c1e048ad037fcb0bd6c7409f4b2 |
| ppc64le |
|
opentelemetry-collector-0.152.1-2.el10_2.ppc64le.rpm
|
SHA-256: 23cd0d97c0e12c8ce0109f7cfa4b36c31768a5d7249c0c46e2d400b1521d5973 |
Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2
| SRPM |
|
opentelemetry-collector-0.152.1-2.el10_2.src.rpm
|
SHA-256: 24b0fd58b56af196824b67b77e17ec6f414c2c1e048ad037fcb0bd6c7409f4b2 |
| x86_64 |
|
opentelemetry-collector-0.152.1-2.el10_2.x86_64.rpm
|
SHA-256: 984cb2124a10255971c38165502c25c03e194703569af3fe882565ce855a3bb3 |
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2
| SRPM |
|
opentelemetry-collector-0.152.1-2.el10_2.src.rpm
|
SHA-256: 24b0fd58b56af196824b67b77e17ec6f414c2c1e048ad037fcb0bd6c7409f4b2 |
| x86_64 |
|
opentelemetry-collector-0.152.1-2.el10_2.x86_64.rpm
|
SHA-256: 984cb2124a10255971c38165502c25c03e194703569af3fe882565ce855a3bb3 |
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2
| SRPM |
|
opentelemetry-collector-0.152.1-2.el10_2.src.rpm
|
SHA-256: 24b0fd58b56af196824b67b77e17ec6f414c2c1e048ad037fcb0bd6c7409f4b2 |
| aarch64 |
|
opentelemetry-collector-0.152.1-2.el10_2.aarch64.rpm
|
SHA-256: 41b36719c029110634d7d7826583b42538e98b6982f55f34b18731abbb82ba58 |
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2
| SRPM |
|
opentelemetry-collector-0.152.1-2.el10_2.src.rpm
|
SHA-256: 24b0fd58b56af196824b67b77e17ec6f414c2c1e048ad037fcb0bd6c7409f4b2 |
| ppc64le |
|
opentelemetry-collector-0.152.1-2.el10_2.ppc64le.rpm
|
SHA-256: 23cd0d97c0e12c8ce0109f7cfa4b36c31768a5d7249c0c46e2d400b1521d5973 |
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2
| SRPM |
|
opentelemetry-collector-0.152.1-2.el10_2.src.rpm
|
SHA-256: 24b0fd58b56af196824b67b77e17ec6f414c2c1e048ad037fcb0bd6c7409f4b2 |
| s390x |
|
opentelemetry-collector-0.152.1-2.el10_2.s390x.rpm
|
SHA-256: 832a99938d54152c4e83455ccafbb18c1d484d6a4d043c738bf28ed40302f177 |
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.