Red Hat Security Advisory: Kiali 2.22.8 for Red Hat OpenShift Service Mesh 3.3
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-49978 — dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-59873 — tar: node-tar: Denial of Service via crafted gzip bomb CVE-2026-59874 — tar: Node-tar: Denial of Service via malformed tar archive header CVE-2026-59877 — protobufjs: protobufjs: Denial of Service via crafted .proto schema
🎯 Affected products9
- Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:0afd0142183f5b43b618e3db4fc16efd5fd6c5db688ad7eb22ec7a315247bf92_s390x as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:0f51052c03d6eaab0b26601649e73846ca9b97439079fe8d25fbe64b694a58d4_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:3e8e9ef6e034abcbcf92a85f5e8e918f9a34f3df743259eb4f61918321ad16f3_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:66eb06b628f7457fbb95e2f488de438837c6a9a69c62cb54bc3068583aa8344d_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:62c9b369b8246774dabe497aa6c884ee97ac6fb53a6ac4324f21fbc02a243ff0_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:7ffec264b9fdeb23d8d7c62b69e36369e34f46e1b4fb506a6946316790113234_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:91c72b08312e6cfe597e9e111d6a2b7d5f433f8af6e5f66a335f5ffdf60f789d_s390x as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:a9893771653783a12a8603eecc5c981617e55ae01fd6d064880b5b86f08cb823_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
✅ Remediation
See Kiali 2.22.8 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.3/html/observability/kiali-operator-provided-by-red-hat Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Applications that only encode or decode protobuf messages using trusted schemas are not directly affected. Until patched protobufjs packages (7.6.5 / 8.6.6) are available, do not parse .proto schema text from untrusted sources via parse, Root.load, or Root.loadSync. Where untrusted schema input cannot be avoided, isolate .proto parsing in a dedicated worker thread or subprocess and enforce an explicit timeout so a non-returning parse cannot block the main event loop. Optional process-manager controls (for example systemd restart-on-failure, or CPU/cgroup limits) may reduce host-level impact or aid recovery for supervised services, but they do not fix the parser bug and are not a substitute for input isolation or applying the update.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:49680
- externalhttps://access.redhat.com/security/cve/CVE-2026-49978
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-59873
- externalhttps://access.redhat.com/security/cve/CVE-2026-59874
- externalhttps://access.redhat.com/security/cve/CVE-2026-59877
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_49680.json