RHSA-2026:20460MediumCVSS 5.9
Red Hat Security Advisory: Kiali 2.22.4 for Red Hat OpenShift Service Mesh 3.3
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation
🎯 Affected products14
- Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-operator-bundle@sha256:5f0d9c37da0df2e01de1965b121a0beffd3a4a61b29f317058eee3ed48a5411c_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:0cd332b82542de28dc6d2dd7e955924fe3de35a5206bc2e9f4d4e2bd9a591148_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:625caa76382f8236b0ae5c1c438008a61f64a7b1497f861fef475f7428da477c_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:6395e4a973d90ebb1250a4f7aa131ab812eb5d9d3bc5900ccb329e87b8f1c9ea_s390x as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:b5a4fd9b6ec6eef405c167cbe70fde3c2618f26fb7ce837bf1d56c36e6064e1f_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9-operator@sha256:5bc3aab90ba7a7b6c1971110f235b67bbc3e1bcfa5c312b7cc7cfcd81d25912c_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9-operator@sha256:b136ce6fcc852f6af963c35f1a39bfecb942b0189a26e22b9e404b5ceca0be13_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9-operator@sha256:daa5ce7c32434365161ed729a6fdb88587e658347e368e143b2338285bf44a29_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9-operator@sha256:f43ad850d505a0cd2ce61970413389c5ac2e23edba4891e3977e5d541a09b33b_s390x as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:801430f3d82d109bfecd3d1e1703200dc98a6c35eee0330b1c90d0fb4804ae11_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:a4dc7862130d17dd424af3b3e285850448a7c85bfcc191bce9afa42d9f5c71f7_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:e4e55c3b1e398a962cbde38dd30260c77514d97e558028e0991f4a57bcb8d0be_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:f588d5d77bb0b4efdfca01f1ca7414fcadc90a97b165628b8f99bdd4df80c8a7_s390x as a component of Red Hat OpenShift Service Mesh 3.3
✅ Remediation
See Kiali 2.22.4 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.3/html/observability/kiali-operator-provided-by-red-hat Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:20460
- externalhttps://access.redhat.com/security/cve/CVE-2026-32281
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_20460.json