{"id":"CLSA-2026-1772041183","summary":"grafana: Fix of 3 CVEs","details":"- rebuild with newer golang version 1.22.9-1.el9_2.tuxcare.els5 to fix the following CVE's\n  - CVE-2025-61726: limit parsed URL query parameters to mitigate excessive memory\n    consumption during form parsing\n  - CVE-2025-61728: fix denial-of-service in archive/zip by replacing super-linear\n    index construction with an efficient algorithm\n  - CVE-2025-61729: fix excessive resource consumption when constructing hostname\n    error messages for certificates with many SANs","modified":"2026-05-27T11:16:58.853781734Z","published":"2026-02-25T17:39:48Z","upstream":["CVE-2025-61726","CVE-2025-61728","CVE-2025-61729"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/almalinux9.2esu/CLSA-2026-1772041183.html"}],"affected":[{"package":{"name":"grafana","ecosystem":"TuxCare:AlmaLinux:9.2","purl":"pkg:rpm/tuxcare/grafana?distro=almalinux-9.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.0.9-4.el9_2.alma.1.tuxcare.els12"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1772041183.json"}}],"schema_version":"1.7.5"}