RHSA-2026:20457MediumCVSS 5.9
Red Hat Security Advisory: Kiali 2.11.11 for Red Hat OpenShift Service Mesh 3.1
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
🎯 Affected products9
- Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:9874be237b24e860768f2d7ea9074ee225e64c363181b1cfd8c9cc37cca018f3_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:cb2642232c7b80ff411b2ff03b3e1ad05f01bd073587ebdd2bb6561a7757bfbe_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:ccd47034fb55a8ff312039213bf137e10f38449f935040679ac13f7d78f2e142_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:f177998fa5c4abaa2edc2caac1d4a8f5f0777b48ff3eaf6ac61bebecc3370a42_s390x as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:7206679dbbf3986f2fbb728e69ecd61da448e5c3c3b2e4dcd97ea1bd4fc6e5fa_s390x as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:862990dfcd46dc345215fc27a1d0b9670b8f31c83fe9e2b19d8ed813a9338d31_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:918dc1bb66e24f9c8a56e32c6dfb4dabbd596565ca6025c1e0306ec9a1353912_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:e8f30f6ec276865a6ef570eb9a2f96cc9589518aff5e254f39a79229fa61f52a_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
✅ Remediation
See Kiali 2.11.11 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.1/html/observability/kiali-operator-provided-by-red-hat Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:20457
- externalhttps://access.redhat.com/security/cve/CVE-2026-32281
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_20457.json