{"id":"CLSA-2026-1772448804","summary":"grafana-pcp: Fix of 3 CVEs","details":"- Rebuild against recent Go compiler\n- CVE-2025-61726: fix net/url excessive memory consumption when parsing large\n  forms with many unique query parameters\n- CVE-2025-61729: fix crypto/x509 certificate verification allowing excessive\n  resource consumption via HostnameError.Error()\n- CVE-2025-68121: fix crypto/tls session resumption succeeding when it should\n  fail due to mutated ClientCAs or RootCAs between handshakes","modified":"2026-05-27T11:17:49.120955564Z","published":"2026-03-02T10:53:28Z","upstream":["CVE-2025-61726","CVE-2025-61729","CVE-2025-68121"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/tuxcare9.6esu/CLSA-2026-1772448804.html"}],"affected":[{"package":{"name":"grafana-pcp","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/grafana-pcp?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1.1-11.el9_6.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1772448804.json"}}],"schema_version":"1.7.5"}