RHSA-2026:27114HighCVSS 7.5
Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.6.17
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-47774 — envoy: envoy: HTTP/2 Remote Denial of Service via HPACK compression bomb and Slowloris-style attack CVE-2026-49975 — httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack
🎯 Affected products9
- Red Hat OpenShift Service Mesh 2.6
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:1bf99621bc043feba08bbe087a69887c3318930d7c12ad2d04bd219b3d1ebd25_ppc64le as a component of Red Hat OpenShift Service Mesh 2.6
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:b046372098950aabce69b6bb45e38d4402d8f6c13450c1736ea7af78eddf8566_s390x as a component of Red Hat OpenShift Service Mesh 2.6
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:e6a6c65408f58c269bff76aced6bef45ee8547bd817f45146769109513992274_amd64 as a component of Red Hat OpenShift Service Mesh 2.6
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:f1ad157e27640f2e6d12fd706902de424d79577f812543822dfcbea1a0f15e7d_arm64 as a component of Red Hat OpenShift Service Mesh 2.6
- registry.redhat.io/openshift-service-mesh/proxyv2-rhel9@sha256:91ad18ecf0b3277175592fa95d0a7f748d165dab358f7ab16e3d37e34a96e5bd_amd64 as a component of Red Hat OpenShift Service Mesh 2.6
- registry.redhat.io/openshift-service-mesh/proxyv2-rhel9@sha256:9c7e1c1c0a00c97dfc7caf9a29c395b245ef5e2303c1d23974c4e11284cd538c_ppc64le as a component of Red Hat OpenShift Service Mesh 2.6
- registry.redhat.io/openshift-service-mesh/proxyv2-rhel9@sha256:aeba5bf4d034bc85965e98bc6cdd87abac40d6bf569eb35ae79dcb0491fafeae_s390x as a component of Red Hat OpenShift Service Mesh 2.6
- registry.redhat.io/openshift-service-mesh/proxyv2-rhel9@sha256:ff751cd7ab92db923c233be8d26e0b4e35e01fbb2e5f4b507aa7669d90024efa_arm64 as a component of Red Hat OpenShift Service Mesh 2.6
✅ Remediation
See Red Hat OpenShift Service Mesh 2.6.17 documentation at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/service_mesh/service-mesh-2-x Workaround: See the security bulletin for a detailed mitigation procedure.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:27114
- externalhttps://access.redhat.com/security/cve/CVE-2026-47774
- externalhttps://access.redhat.com/security/cve/CVE-2026-49975
- externalhttps://access.redhat.com/security/cve/cve-2026-47774
- externalhttps://access.redhat.com/security/cve/cve-2026-49975
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_27114.json