Red Hat Security Advisory: Kiali 2.4.21 for Red Hat OpenShift Service Mesh 3.0
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-59873 — tar: node-tar: Denial of Service via crafted gzip bomb CVE-2026-59874 — tar: Node-tar: Denial of Service via malformed tar archive header
🎯 Affected products9
- Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:4621e29182691b4968319d414ad7fcda8c625c73e9cd91bc9a1fc3e3c8fc438f_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:51feeac02b8bf0caac1f4a809f51c1111396f4043549b944c63ce4c2db7a5744_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:7d0c0ad5c4baacca0d1b6d112a1267c462afa6660a7ae562865335def1e783a9_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:cdd16e57692b07c6a5cbf5907774ccc3a0c0900825c62a807ece8caa874002d8_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:10dad14e7d92479983edac608b4871423f4d34f658f4eb810cde96ce45e497f7_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:30ad4488a7a75695c8377fc92d8b96426a368602bf2a19fe807afa33e6a0079a_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:3b7357afee7f60478f6d62f7f85d49600ebe372a5945c67542554d3a7b3be2a0_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:b672cd8391ff79a4b9be089d2a908bf51076d0a8f2345973d298ee4c53228992_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
✅ Remediation
See Kiali 2.4.21 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.0/html/observability/kiali-operator-provided-by-red-hat Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:49687
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-59873
- externalhttps://access.redhat.com/security/cve/CVE-2026-59874
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_49687.json