Red Hat Security Advisory: Kiali 2.22.6 for Red Hat OpenShift Service Mesh 3.3
🔗 CVE IDs covered (12)
📋 Description
CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-42338 — ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name CVE-2026-46625 — js-cookie: JavaScript Cookie: Cookie attribute manipulation via prototype pollution CVE-2026-48779 — ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments
🎯 Affected products14
- Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-operator-bundle@sha256:69ba86f602d01541695b2ab5e5a9db8ea6c6062af70de40d9b75b3d9b67a8abd_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:2031ccb4f6cc24c036fae7f291ecb59b05e6c0a49a0abfaea39eb444f7f7b6bc_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:50584bc28d045ff5db77e4973c70e59bae2f33a2cc87c400c17bd6eafd7466ba_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:577b284ce810c91c5f9a44f9be5aad96e77e0546f61b6dce376013c7ebf480be_s390x as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:ea66e2eb93ef01b30b2f4758e043a5c4a889df27a26a63334549fca91a8abd4b_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9-operator@sha256:64851d8db25a79dbab207e3b14599c7486f8bdc8fe0b16e6e614164228c2b405_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9-operator@sha256:9a8266a9c08cc1df3374ec3d0431c52b10275923e19cb767ee7633f71307ef73_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9-operator@sha256:a9e71a818f5bb5afc979df2dd3d9cc6a32a624155bac4a7672789bd2da2394e2_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9-operator@sha256:e68a0fd8f0a8ba0ccf8c0f973c7e739300a30169ad0def2eaa2fa944fc29ee4b_s390x as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:4c3c63c71a4a2c1f28827c1270a2f74f251097296e348f8191ec560b33e42943_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:6759b5f712098d890c6a5124fb513097050f70b54e7e3723df4e74a36a40c3f3_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:b2c57e67cd87fe061679de42f24c4d4d7ed7dbb0c07eb228db95b2eb6147d9f9_s390x as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:bea80650e9959da730b4fcde63752caa549f98759d2dc16009e7f8f44a2501d7_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
✅ Remediation
See Kiali 2.22.6 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.3/html/observability/kiali-operator-provided-by-red-hat Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2026:33183
- externalhttps://access.redhat.com/security/cve/CVE-2026-12143
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-42338
- externalhttps://access.redhat.com/security/cve/CVE-2026-44486
- externalhttps://access.redhat.com/security/cve/CVE-2026-44487
- externalhttps://access.redhat.com/security/cve/CVE-2026-44488
- externalhttps://access.redhat.com/security/cve/CVE-2026-44492
- externalhttps://access.redhat.com/security/cve/CVE-2026-44494
- externalhttps://access.redhat.com/security/cve/CVE-2026-44495
- externalhttps://access.redhat.com/security/cve/CVE-2026-44496
- externalhttps://access.redhat.com/security/cve/CVE-2026-46625
- externalhttps://access.redhat.com/security/cve/CVE-2026-48779
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_33183.json