Red Hat Security Advisory: Kiali 2.17.12 for Red Hat OpenShift Service Mesh 3.2
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-59873 — tar: node-tar: Denial of Service via crafted gzip bomb CVE-2026-59874 — tar: Node-tar: Denial of Service via malformed tar archive header
🎯 Affected products9
- Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:75b1c9d084f5cfd18aeced0d801bdff647bce79b83cfa27d3e2ba7954515ced0_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:7afedef5bd22487488160bdd97fbe1b0bf8648367bb47b255bf6c6834e62355e_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:b037f3f76e9c0c3c957eed7e07a156dd48c9e4a85cf5e8c73ea58ab4dcd43f23_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:bba1360a424f5aac9beffc5542cc8b465e0e820bf045bf74e6604455c52ce833_s390x as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:504dc6ba7a0458296699f5807a27fab2ad8d32dbf22596dd8f1429d22f547f31_s390x as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:7a49cfc03fd384d8cedb3b7324bff485138fc6bcb99c608d61215248ade5b10b_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:9cd865290c175e0d49596f1995ea071ac9531205bf54799e67c5840154cb23a9_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:e35a7f1774bd5005171c9e1fb717eb73a9d11e8c1aa4e2f606fbd1331e147805_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
✅ Remediation
See Kiali 2.17.12 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.2/html/observability/kiali-operator-provided-by-red-hat Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:49681
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-59873
- externalhttps://access.redhat.com/security/cve/CVE-2026-59874
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_49681.json