RHSA-2026:20456MediumCVSS 5.9
Red Hat Security Advisory: Kiali 2.4.17 for Red Hat OpenShift Service Mesh 3.0
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
🎯 Affected products9
- Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:4c1c113b5359d8bb7b99d26731156eb7523df3c3e46a301b37c638e821883a01_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:4ce77d0a83c4b01ac1638c372360be8d970fd5c667749d133c9437d30cb206b3_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:61fbdc44a87c1484e5081345e767000895801ea55a8c6e1344bded1836d44729_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:9368c09b14d1743451257f901ec8e4b5d50f7343a2bbaf723aa6a7f9cb586882_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:075ca2039b54596754e028706abc0b4e719cfb6a1adc7dd0a512f1cf06adc3d0_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:196394c3907ff6ed0849a8086256265708256a80c2f3b47029cf902f2ee801df_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:3aa2d2ff20f790e03eec33d5501552b0c874bf40097f1486282811f34fcf7139_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:ca9ef5694c6fb038a38b7f76f03501e5d094af381fad483d49518dd156a001d7_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
✅ Remediation
See Kiali 2.4.17 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.0/html/observability/kiali-operator-provided-by-red-hat Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:20456
- externalhttps://access.redhat.com/security/cve/CVE-2026-32281
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_20456.json