RHSA-2026:20454HighCVSS 7.4
Red Hat Security Advisory: Kiali 1.73.31 for Red Hat OpenShift Service Mesh 2.6
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-42044 — axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:20454
- externalhttps://access.redhat.com/security/cve/CVE-2026-32281
- externalhttps://access.redhat.com/security/cve/CVE-2026-42044
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_20454.json