RHSA-2026:20455MediumCVSS 5.9
Red Hat Security Advisory: Kiali 2.17.8 for Red Hat OpenShift Service Mesh 3.2
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
🎯 Affected products9
- Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:849f91f2cb0d582e1cc5497f491ff6549ed40ad9edb58f3b17cea5674a3e51cd_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:904b844d6a7fae4f41543d8700a0a53959aab343aa0016bc3ad9cdd867888fb4_s390x as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:97108094c210987dd296c844f823a0c5c80d14c5a06dac046ca9d4496b90977c_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:ca0320cd135ea6bb92c923c58c84b17ae4f121a5fd0145062a9008f339dadace_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:37054f2e44514d5419af8381123d7ae81000e7e34fdb99472e965f843340c427_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:482cbad61e21f9ef5ccc074b798ad422f341ae17f1f7281947721f7280c0d9a7_s390x as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:7852143b4d381db16057dd3e440e5ae9c4e10995753618472e5e42baa7f1586c_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:af88ffb1e47738702d8e84c0111ada77697f06d8b5baca25dbfda806add3c1f7_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
✅ Remediation
See Kiali 2.17.8 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.2/html/observability/kiali-operator-provided-by-red-hat Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:20455
- externalhttps://access.redhat.com/security/cve/CVE-2026-32281
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_20455.json