Third-Party Package Updates in Splunk Enterprise - August 2026

Advisory ID: SVD-2026-0802

CVE ID: 

Published: 2026-08-19

Last Update: 2026-08-19

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk Enterprise versions 10.4.2, 10.2.6, 10.0.9, 9.4.14, and higher.

PackageRemediationCVESeverity
github.com/golang/go1Upgraded golang to Go compiler version 1.26.3MultipleCritical
github.com/go-jose/go-jose/v42Upgraded go-jose in the ipc-broker binary to version 4.1.4CVE-2026-34986High
go.opentelemetry.io/otel3Upgraded opentelemetry/otel in ipc-broker to version 1.44.0CVE-2026-29181High
go.opentelemetry.io/otel/sdk4Upgraded opentelemetry/otel/sdk in ipc-broker to version 1.44.0CVE-2026-39883High
github.com/go-jose/go-jose/v45Upgraded go-jose in the splunk-topology sidecar to version 4.1.4CVE-2026-34986High
go.opentelemetry.io/otel6Upgraded opentelemetry/otel in splunk-topology to version 1.44.0CVE-2026-29181High
go.opentelemetry.io/otel/sdk7Upgraded opentelemetry/otel/sdk in splunk-topology to version 1.44.0CVE-2026-39883High
golang-go8Upgraded golang to Go compiler version 1.26.3 in the postgres sidecarMultipleCritical
github.com/golang/go9Upgraded golang-go in the opamp-svc binary to version 1.25.11MultipleCritical
github.com/go-jose/go-jose/v410Upgraded go-jose in the opamp-svc binary to version 4.1.4CVE-2026-34986High
go.opentelemetry.io/otel11Upgraded opentelemetry/otel in opamp-svc to version 1.43.0CVE-2026-29181High
go.opentelemetry.io/otel/sdk12Upgraded opentelemetry/otel/sdk in opamp-svc to version 1.43.0CVE-2026-39883High
google.golang.org/grpc13Upgraded golang-grpc in opamp-svc to version 1.80.0CVE-2026-33186Critical
libcurl14Upgraded libcurl to version 8.20.0MultipleMedium
idna15Upgraded idna to version 3.18CVE-2026-45409Medium
PostgreSQL16Upgraded PostgreSQL to version 17.10MultipleHigh
OpenSSL17Upgraded OpenSSL to versions 1.0.2zq and 3.5.7MultipleHigh
MongoDB18Upgraded MongoDB 7.0.34 to version 7.0.37 and MongoDB 8.0.23 to version 8.0.26CVE-2024-35255Medium

1 Upgraded golang to Go 1.26.3 to remedy CVE-2026-25679, CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-2026-32281, CVE-2026-32283, and CVE-2026-33810 at /opt/packages/ipc_broker-v1.9.5-36253eb8-20260309t135542.tar.gz/ipc_broker.

2 Upgraded go-jose in the ipc-broker binary to version 4.1.4 to remedy CVE-2026-34986 at /opt/packages/ipc_broker-v1.9.5-36253eb8-20260309t135542.tar.gz/ipc_broker.

3 Upgraded opentelemetry/otel in the ipc-broker binary to version 1.44.0 to remedy CVE-2026-29181 at /opt/packages/ipc_broker-v1.9.5-36253eb8-20260309t135542.tar.gz/ipc_broker.

4 Upgraded opentelemetry/otel/sdk in the ipc-broker binary to version 1.44.0 to remedy CVE-2026-39883 at /opt/packages/ipc_broker-v1.9.5-36253eb8-20260309t135542.tar.gz/ipc_broker.

5 Upgraded go-jose in the splunk-topology sidecar to version 4.1.4 to remedy CVE-2026-34986 at /opt/splunk/var/run/supervisor/pkg-run/pkg-topology1037764223/splunk-topology.

6 Upgraded opentelemetry/otel in the splunk-topology sidecar to version 1.44.0 to remedy CVE-2026-29181 at /opt/splunk/var/run/supervisor/pkg-run/pkg-topology1037764223/splunk-topology.

7 Upgraded opentelemetry/otel/sdk in the splunk-topology sidecar to version 1.44.0 to remedy CVE-2026-39883 at /opt/splunk/var/run/supervisor/pkg-run/pkg-topology1037764223/splunk-topology.

8 Upgraded golang to Go 1.26.3 in the postgres sidecar to remedy CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-2026-32281, and CVE-2026-32283 at /opt/splunk/bin/postgres.

9 Upgraded golang-go in the opamp-svc binary to version 1.25.11 to remedy CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-2026-32281, and CVE-2026-32283 at /opt/packages/opamp-svc-v1.0.0-999c884a-20251217t220529.tar.gz/opamp-svc in Splunk Enterprise versions 10.0.9, 10.2.6, and 10.4.2. Splunk Enterprise versions 9.x do not have the opamp-svc binary.

10 Upgraded go-jose in the opamp-svc binary to version 4.1.4 to remedy CVE-2026-34986 at /opt/packages/opamp-svc-v1.0.0-999c884a-20251217t220529.tar.gz/opamp-svc in Splunk Enterprise versions 10.0.9, 10.2.6, and 10.4.2. Splunk Enterprise versions 9.x do not have the opamp-svc binary.

11 Upgraded opentelemetry/otel in the opamp-svc binary to version 1.43.0 to remedy CVE-2026-29181 at /opt/packages/opamp-svc-v1.0.0-999c884a-20251217t220529.tar.gz/opamp-svc in Splunk Enterprise versions 10.0.9, 10.2.6, and 10.4.2. Splunk Enterprise versions 9.x do not have the opamp-svc binary.

12 Upgraded opentelemetry/otel/sdk in the opamp-svc binary to version 1.43.0 to remedy CVE-2026-39883 at /opt/packages/opamp-svc-v1.0.0-999c884a-20251217t220529.tar.gz/opamp-svc in Splunk Enterprise versions 10.0.9, 10.2.6, and 10.4.2. Splunk Enterprise versions 9.x do not have the opamp-svc binary.

13 Upgraded golang-grpc in the opamp-svc binary to version 1.80.0 to remedy CVE-2026-33186 at /opt/packages/opamp-svc-v1.0.0-999c884a-20251217t220529.tar.gz/opamp-svc in Splunk Enterprise versions 10.0.9, 10.2.6, and 10.4.2. Splunk Enterprise versions 9.x do not have the opamp-svc binary.

14 Upgraded libcurl to version 8.20.0 to remedy CVE-2026-7168, CVE-2026-6429, CVE-2026-6276, CVE-2025-14819, and CVE-2025-14017 at /opt/splunk/opt/mongo/lib/libcurl.so.4.8.0 in Splunk Enterprise version 10.4.2.

15 Upgraded idna to version 3.18 to remedy CVE-2026-45409 at /opt/splunk/etc/apps/splunk_secure_gateway/lib/idna-3.18.dist-info/METADATA.

16 Upgraded PostgreSQL to version 17.10 to remedy CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-6638, and CVE-2026-6637 at /opt/splunk/bin/postgres in Splunk Enterprise versions 10.4.2, 10.2.6, and 10.0.9. Splunk Enterprise versions 9.x do not include PostgreSQL.

17 For Splunk Enterprise version 10.4.x, Splunk Enterprise upgraded OpenSSL 1.0.2zp to version 1.0.2zq at /opt/splunk/opt/openssl1/bin/openssl, /opt/splunk/lib/libssl.so.1.0.0, and /opt/splunk/lib/libcrypto.so.1.0.0, and upgraded OpenSSL 3.5.6 to version 3.5.7 at /opt/splunk/lib/libssl.so.3, /opt/splunk/lib/libcrypto.so.3, /opt/splunk/lib/libssl.so, and /opt/splunk/lib/libcrypto.so to remedy CVE-2026-45447, CVE-2026-7383, CVE-2026-9076, CVE-2026-34180, and CVE-2026-42766. For Splunk Enterprise versions 10.2.x, 10.1.x, and 10.0.x, Splunk Enterprise upgraded OpenSSL 1.0.2zp to version 1.0.2zq at /opt/splunk/opt/openssl1/bin/openssl, /opt/splunk/lib/libssl.so.1.0.0, and /opt/splunk/lib/libcrypto.so.1.0.0, and upgraded OpenSSL 3.0.20 to version 3.0.21 at /opt/splunk/lib/libssl.so.3, /opt/splunk/lib/libcrypto.so.3, /opt/splunk/lib/libssl.so, and /opt/splunk/lib/libcrypto.so to remedy CVE-2026-45447, CVE-2026-7383, CVE-2026-9076, CVE-2026-34180, and CVE-2026-42766. For Splunk Enterprise versions 9.4.x and 9.3.x, Splunk Enterprise upgraded OpenSSL 1.0.2zp to version 1.0.2zq at /opt/splunk/opt/openssl1/bin/openssl, /opt/splunk/lib/libssl.so.1.0.0, and /opt/splunk/lib/libcrypto.so.1.0.0 to remedy CVE-2026-45447, CVE-2026-7383, CVE-2026-9076, CVE-2026-34180, and CVE-2026-42766.

18 For Splunk Enterprise versions 9.4.14 and 10.0.9 for Linux and Windows, Splunk Enterprise upgraded MongoDB 7.0 from version 7.0.34 to version 7.0.37 at $SPLUNK_HOME/bin/mongod to remediate CVE-2024-35255. For Splunk Enterprise version 10.2.6 for Linux, Windows, and macOS, Splunk Enterprise upgraded MongoDB 8.0 from version 8.0.23 to version 8.0.26 and MongoDB 7.0 from version 7.0.34 to version 7.0.37 at $SPLUNK_HOME/bin/mongod to remediate CVE-2024-35255. For Splunk Enterprise version 10.4.2 for Linux, Windows, and macOS, Splunk Enterprise upgraded MongoDB 7.0 from version 7.0.34 to version 7.0.37 and MongoDB 8.0 from version 8.0.23 to version 8.0.26 at $SPLUNK_HOME/bin/mongod to remediate CVE-2024-35255.

Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, 9.4.14, or higher.

Product Status

ProductBase VersionAffected VersionFix Version
Splunk Enterprise10.410.4.0 to 10.4.110.4.2
Splunk Enterprise10.210.2.0 to 10.2.510.2.6
Splunk Enterprise10.010.0.0 to 10.0.810.0.9
Splunk Enterprise9.49.4.0 to 9.4.139.4.14

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.