RHSA-2026:20454HighCVSS 7.4

Red Hat Security Advisory: Kiali 1.73.31 for Red Hat OpenShift Service Mesh 2.6

Published
May 25, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-42044 — axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget

🎯 Affected products9

  • Red Hat OpenShift Service Mesh 2.6
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel8@sha256:1910b9dac1f597a06e08a56291ecf035a73a1bf50fdde8b1d59e7b335e10fd79_s390x as a component of Red Hat OpenShift Service Mesh 2.6
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel8@sha256:20b3d236fd4adfe4e9f6cf3a156e775efc6123fdfe83c79f1656dff9ea50b785_ppc64le as a component of Red Hat OpenShift Service Mesh 2.6
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel8@sha256:5de8052e33e34de10c7441e08d8a9a095a77f8714a82820e84edf80fb5711ed7_amd64 as a component of Red Hat OpenShift Service Mesh 2.6
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel8@sha256:887ae86218b2202438cdc88820b8530d4c85fe19d1c6b581e08364adb63a2b02_arm64 as a component of Red Hat OpenShift Service Mesh 2.6
  • registry.redhat.io/openshift-service-mesh/kiali-rhel8@sha256:2ad267b095e913752434847710a31f7371c72c93544e851e67416f63036197a3_amd64 as a component of Red Hat OpenShift Service Mesh 2.6
  • registry.redhat.io/openshift-service-mesh/kiali-rhel8@sha256:7ddfc26f3c2ba2f8087dbb101128c98e7b651f5daf793b6a6e8aea69af677213_ppc64le as a component of Red Hat OpenShift Service Mesh 2.6
  • registry.redhat.io/openshift-service-mesh/kiali-rhel8@sha256:fa92ccdfd2ce5f20b93f6a1c8b249bab10f2d4624c3c5203eb74aa45c034cb3d_arm64 as a component of Red Hat OpenShift Service Mesh 2.6
  • registry.redhat.io/openshift-service-mesh/kiali-rhel8@sha256:fba61b8ada52530ff0aadc5a33eb68fb05c0855413203b3981c7a0b914c71e00_s390x as a component of Red Hat OpenShift Service Mesh 2.6

✅ Remediation

See Kiali 1.73.31 documentation at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/service_mesh/service-mesh-2-x Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (6)