RHSA-2026:37287HighCVSS 7.4
Red Hat Security Advisory: Kiali 2.4.20 for Red Hat OpenShift Service Mesh 3.0
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-42264 — axios: Axios: Prototype pollution allows information disclosure and request manipulation
🎯 Affected products9
- Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:692395e99e4316e1855c61b026dd4718972ba792ca43c9f51e2dd96405fbdc4b_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:aa50b6bbdc7d57c3595b1d58e3e7d4a6896ad5a5abc4d27ad65e829be6fdabd9_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:ae795e3096955b766ae1fbb94cba49fea43a4965eb5c23df071fbfd806d65432_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:ebd311237bfc9d8f134765d3d581a29d3f5ce38010aab4a6af109cbad9cdcfbf_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:154a97fc2ad1d8276954bed43632695ba620f8576cee207ca88501dc68401087_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:52a06fe4ab1b625a64d9e61a485c69c0df13a45c28ecc82e8d618556079b6ebb_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:7fc19ce0a2953a917a0a4ff7aff3828a011e2edc5a207c864317dab4ad9ed307_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:9f00d5009bfe10e0e1a477e196322465edf77b75ad4dee9f30acebf9dada9057_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
✅ Remediation
See Kiali 2.4.20 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.0/html/observability/kiali-operator-provided-by-red-hat Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:37287
- externalhttps://access.redhat.com/security/cve/CVE-2026-42264
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_37287.json