Red Hat Security Advisory: Kiali 2.11.15 for Red Hat OpenShift Service Mesh 3.1
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-59873 — tar: node-tar: Denial of Service via crafted gzip bomb CVE-2026-59874 — tar: Node-tar: Denial of Service via malformed tar archive header
🎯 Affected products9
- Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:097bbedcb4141e9b58d790cf7bb4c6612df8b9aefa1bc90826bb3a8176740960_s390x as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:5d56d5714da216892e405ea630008801373937e3c476af186355874ec2740069_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:842a6a626eb127338e6e2a4fcb08fe899c7b3e65ec1b307680b7fb6ae70b9bd3_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:a5ae3e8a27760eabd49538e2f5128ac7fa7ea09643f357c22aa9ab4e7374025c_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:1f19328ce067d068b44fecb600d75c2155e9284dfa0dedfd41762aee2f56b09a_s390x as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:675f9d9ab94188937332f49dbf3e8262d3d66e7dab9087b39974ba0134c5a141_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:85dfae63baed87a20b4c1ccd4938d67d5406efd1959533c4ba958d6c6c293c58_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:fc2238b9db4f3567f0eb82bd2e5e422cd48ebc4327ca94d7177cdaebe1d7b20e_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
✅ Remediation
See Kiali 2.11.15 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.1/html/observability/kiali-operator-provided-by-red-hat Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:49689
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-59873
- externalhttps://access.redhat.com/security/cve/CVE-2026-59874
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_49689.json