RHSA-2026:49729HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.1.11

Published
August 3, 2026
Last Modified
August 10, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-47204 — envoy: Envoy: Denial of Service via Connect protocol request CVE-2026-47221 — envoy: Envoy: Null pointer deref in internal redirects CVE-2026-48042 — envoy: Envoy: Denial of Service via deeply nested JSON objects CVE-2026-48044 — Envoy: Envoy: Denial of Service via specially crafted zstd payload CVE-2026-48706 — envoy: Envoy Heap Buffer Overflow in TcpStatsdSink

🎯 Affected products26

  • Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh-tech-preview/istio-ztunnel-rhel9@sha256:44492274183650ac57f13c65284269f5852c0e21b0d1e8e2d4d465fb3812d64d_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh-tech-preview/istio-ztunnel-rhel9@sha256:59456cf33807186ca41a881644e72da5f906f7b7c686cb84e94316e5de06b3cf_s390x as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh-tech-preview/istio-ztunnel-rhel9@sha256:7af77e67f9a4c81c8627fb8f21a1cfcc4a36b1b30da189ef244f84520d16b1b8_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh-tech-preview/istio-ztunnel-rhel9@sha256:e23e614b8207b039a3b5780b27b9aa7a433a0423a602381ca5923a2ac2e798c9_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:0fc899d7a731fad940179d669451455eefdbe2b6a94969af7f6a42db761114f9_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:668e8e14e773882aa4e896face7de0a3893e61fcbeda0d94392397e7d83822dc_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:e57b13920b3c526310b4eda0ce05ba79436190273608d37f31bc65dad2532f21_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:f9cc2daac79e68462ca7426ad485586823c1035e18422b0861fdb19520610a7b_s390x as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:157962811e87e4b0bf8af48bb4bccb785c124866b93ca6bc1339ff5c78352b99_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:5d8647ae7f86875c2100a5f9b422f4378b2c4a207ea676e8ef1fb30458792d65_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:6d9656677bc51b62ae4266e33d3597873a29d5408fd062ad6374ad6d4523e9b6_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:a80914528f63045b7a13b86ad0baa0a27ede93ad28dd395709fb0d8c459deb0b_s390x as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:32ca9ff0afb7188c605bc5e1d8b0aea718f11dabb47fec1a65e646a3a683abba_s390x as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:508fa203f347a89f10da5d9321dcbe6b7108da54fd75577f5fc3c42b2b47e341_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:c1f56cd35e045f83e9587837ac0dcbe953cfeaccd0876d17b8cb3b54aa0d1dd1_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:eb030eaf3626ca662d7d03e0ecd30effcf713cb68d1ee1dea3222bf745e40323_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:94921265f210e84d79eeba8821c4527e81c36bfc7ce98f0cc8d64b44cbeef7a0_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:aac19045406a2c70e71543728fd4f31df14ad9cd6836ffacbeb3218ad3d96e0c_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:b4e81569b945540d729d2d35519eff01bbc865afdbe2343a692dedabca14f84f_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:d287bfac8a2858a046ef4f19dad906e158292843d445b94da70513112098e327_s390x as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:229de9a08d9f98c65a28f9cb8523712f55b107350cb85bda55baabad8f754dbb_s390x as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:940320a6a77fb2905b08f89ec3746abc1703c093e000c8ac85dab924448d065b_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:df8b65603948247391e9142589254608e376749be45ffcf99b2af34745263b6a_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:e2d4311058f8e49525fc611f0972463542bd2b12bb3a7118d6ae2ca8ccc27ae9_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:f9b3bf5727289419610d6c3dbfb019a914f7b1d680822ee05725f4225b2cfdac_amd64 as a component of Red Hat OpenShift Service Mesh 3.1

✅ Remediation

See Red Hat OpenShift Service Mesh 3.1.11 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.1 Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (9)