RHSA-2026:49765HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.3.6

Published
August 3, 2026
Last Modified
August 9, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-47204 — envoy: Envoy: Denial of Service via Connect protocol request CVE-2026-47221 — envoy: Envoy: Null pointer deref in internal redirects CVE-2026-48042 — envoy: Envoy: Denial of Service via deeply nested JSON objects CVE-2026-48044 — Envoy: Envoy: Denial of Service via specially crafted zstd payload CVE-2026-48706 — envoy: Envoy Heap Buffer Overflow in TcpStatsdSink CVE-2026-48743 — envoy: Envoy: Request desynchronization allows security policy bypass via HTTP/3 to HTTP/1 translation

🎯 Affected products26

  • Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:00d38604ec92065c2da6de5100eded9a3bd94429ef333ab30bffe9f4b88fa81a_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:30ec9e046bea82559e14663d660f5b0f2c3efa9919d7afe5b28710dd6e45d07b_s390x as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:68ddaeddb2e22ed94e0de9a0dc07fcae90265047280376bba562b39dccfd54ae_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:88e85b5bfe701c95ae5b52086c5916fec69f2df6a19148e1d1e818893453b4ca_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:4c3beafc255025f29b04c6e79f17944be5c697aa104bff48cd9b10c1510ecdd4_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:73d9ab206c3ede1747f17736d75df8cf90badfc92026e0c1d0014b9adb0ff8fd_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:7497ff1f09797032487b442cb1b96b154a1bd2267cd97443eca08cc5db209524_s390x as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:d4897d5dbd9bcf39e0777462c71fa8cceb47cb1131102901e94356fa60647186_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:5942a3782d861044c6ba7afc822b59a8fd25dd93c93cb6b8d615c5a2d3b2a7c4_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:75c04065e4a708a4ba4ccecca06bd7ba703405922181d466801c94a351d37ecf_s390x as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:ced221968e9eb8e9f9f7f073da99db9032c2677ee5c4342baf800d738befbee5_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:fe14d77cd8257197c8bb14ae4f3e85a3ba06e53b68627293be9686087dc129e9_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:09292f6545b2e6619bbbd267024fa4f9c6c8b760e53cfc2833eb54d9f453453e_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:2822039fd4beacdce9ba55663107db291846050ffae0a59c4a8059b81a2a99bd_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:4938aa51aff7c6cd248fa954e00bc414221f4236001fc4b032305b33ce3cfa12_s390x as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:9eba1d3fbc947bb0fe267818fc7a5e06bf403004a045e80c65b2592a7bd06da4_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:1a81558c67a5e3a62842ccf1ac5d686d9f83c448e693fe2ac83d46ec60c0f57d_s390x as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:821f4acfea78e5207952841ab3c153cb42d8e5a0e9c5f79b6ac947e919523c44_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:9b27c3c0ae1c827768f29ef1b5c411a8f725a04af6ad834c7e24a49835f2f13f_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:b3cac830d31372ec560fec29eddb344861b9cfd08bccb46a35b443e0997f8b6a_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:ed441b7161d15b4f1b1e5fba0b7e7c10fced1de39ff17b18cf4ffa552235e6b1_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:26d46e7ca66a08614de1e43b1b6a32ab6f56dd02408a93be317956db354df023_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:5722dd927b0b6f6ad167ffc995514aea1bd029f7b036cc3437041e53b49f103d_s390x as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:6aa03c09ea788efeacaf5e189aa0ad98d7fbe9f072f2a5c3cb5b109c18b1d6fe_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:723c1bb7a91e040f29bc78817b140adb6e6bb4863f0bf7c529e27c9bfda118d4_arm64 as a component of Red Hat OpenShift Service Mesh 3.3

✅ Remediation

See Red Hat OpenShift Service Mesh 3.3.6 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.3 Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (10)