RHSA-2026:37297HighCVSS 7.4

Red Hat Security Advisory: Kiali 2.11.14 for Red Hat OpenShift Service Mesh 3.1

Published
July 9, 2026
Last Modified
August 2, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-42264 — axios: Axios: Prototype pollution allows information disclosure and request manipulation

🎯 Affected products9

  • Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:3b5444e5ee0c54e96827ea1f96b69a73b8a5f1312e14ccf0b23484313c576648_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:5f52116acbe2991873f7cc905975a5fde548bb6d0ea9bf7219864852b559b63c_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:8698cd63a4eb630234c12e4330e07b811a87765c5890b0cbdc2e40e7567fb7e5_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:d8ed06e285098dd01770b442ec325f4e94dd4b19757fad29631e8d4fb94fb43d_s390x as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:3ebf3ef54040d664adface8ab5738f3f6ca601bef651c3cf19029c89db0b9d40_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:6c41fba6599d39c3a823b01d7647bfd5fb315f1d34331ccfaba31f29724a7e48_s390x as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:7a4921c99a5b0ae90e7aaf8c2298d5254ec1742576d1894aade55bcb38570808_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:bb6c49c2edc61441f4688f9bc43a46e6d80ebdaa50cd9f850156186776e551f8_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1

✅ Remediation

See Kiali 2.11.14 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.1/html/observability/kiali-operator-provided-by-red-hat Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (5)