RHSA-2026:27114HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.6.17

Published
June 18, 2026
Last Modified
August 18, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-47774 — envoy: envoy: HTTP/2 Remote Denial of Service via HPACK compression bomb and Slowloris-style attack CVE-2026-49975 — httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack

🎯 Affected products9

  • Red Hat OpenShift Service Mesh 2.6
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:1bf99621bc043feba08bbe087a69887c3318930d7c12ad2d04bd219b3d1ebd25_ppc64le as a component of Red Hat OpenShift Service Mesh 2.6
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:b046372098950aabce69b6bb45e38d4402d8f6c13450c1736ea7af78eddf8566_s390x as a component of Red Hat OpenShift Service Mesh 2.6
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:e6a6c65408f58c269bff76aced6bef45ee8547bd817f45146769109513992274_amd64 as a component of Red Hat OpenShift Service Mesh 2.6
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:f1ad157e27640f2e6d12fd706902de424d79577f812543822dfcbea1a0f15e7d_arm64 as a component of Red Hat OpenShift Service Mesh 2.6
  • registry.redhat.io/openshift-service-mesh/proxyv2-rhel9@sha256:91ad18ecf0b3277175592fa95d0a7f748d165dab358f7ab16e3d37e34a96e5bd_amd64 as a component of Red Hat OpenShift Service Mesh 2.6
  • registry.redhat.io/openshift-service-mesh/proxyv2-rhel9@sha256:9c7e1c1c0a00c97dfc7caf9a29c395b245ef5e2303c1d23974c4e11284cd538c_ppc64le as a component of Red Hat OpenShift Service Mesh 2.6
  • registry.redhat.io/openshift-service-mesh/proxyv2-rhel9@sha256:aeba5bf4d034bc85965e98bc6cdd87abac40d6bf569eb35ae79dcb0491fafeae_s390x as a component of Red Hat OpenShift Service Mesh 2.6
  • registry.redhat.io/openshift-service-mesh/proxyv2-rhel9@sha256:ff751cd7ab92db923c233be8d26e0b4e35e01fbb2e5f4b507aa7669d90024efa_arm64 as a component of Red Hat OpenShift Service Mesh 2.6

✅ Remediation

See Red Hat OpenShift Service Mesh 2.6.17 documentation at https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/service_mesh/service-mesh-2-x Workaround: See the security bulletin for a detailed mitigation procedure.

🔗 References (8)