RHSA-2026:37288HighCVSS 7.4
Red Hat Security Advisory: Kiali 2.22.7 for Red Hat OpenShift Service Mesh 3.3
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-42264 — axios: Axios: Prototype pollution allows information disclosure and request manipulation
🎯 Affected products9
- Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:15ef69f48499bda3c3bb74a42eaac8767f2fb9c0f7bdc1b43fb3c93d4fce6b6a_s390x as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:a5c3b7b7679332402779eceef17fc357e32a8aaa5c6f53316629b024f9299732_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:a6f483b6fad07a7b795cb7a03ee207caa244095d4c7093a26429d9ed174f51d6_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:e8f19a67b677ac2887672fae9e3e5af0f16c43f39ebdb586d63dbf4952a0bdcf_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:44323f737e5387eadb4fabdf4d3714574d08c0406fac878e03ec72d4021d8015_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:4c48f07caf7bb446c29306426285a9cf7f13c0e09781d32bccd1d0b4c8e92746_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:8a763ae659fe26c606bae6975a407d23b1a59089296948564acedfa598556236_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:ef89917d4928382e942a7c6277d213736ddb10371e69ac39a1dd9c801ab6e68a_s390x as a component of Red Hat OpenShift Service Mesh 3.3
✅ Remediation
See Kiali 2.22.7 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.3/html/observability/kiali-operator-provided-by-red-hat Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:37288
- externalhttps://access.redhat.com/security/cve/CVE-2026-42264
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_37288.json