RHSA-2026:5129HighCVSS 7.5

Red Hat Security Advisory: Kiali 2.4.14 for Red Hat OpenShift Service Mesh 3.0

Published
March 19, 2026
Last Modified
September 2, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption

🎯 Affected products9

  • Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:31fcf6c64980c5f5aae31bcefefa390a06f9a9d78478c3768d1d29406cfaf2f9_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:868bee43c5aa1a6f1bd7679ee99f8a420bc55e448c74252342aa85d1719114be_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:91547f3f22d7b9ed334601ae056f2322e555633af9fb71da44b8102bbf7719ca_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:d0d96c1ff664e73bab184017898c7119481c00bab8ac98e971ba9677cf98c579_s390x as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:446cce7b07e107aeac66e4ac3e74e41e0f1e952f9de2fbf49069500899e4e533_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:541f3c997549509601e29a3baad7afdf189190f45f0da3543bd2c19763b801cd_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:6eb41fcb4690319f7f8433d1d83a00c75251d96124a249512e877f0b58b17b23_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:7727fa1a840330b7a24ba8f291924b3670a8ec7cac16a13e9268109f777a8150_s390x as a component of Red Hat OpenShift Service Mesh 3.0

✅ Remediation

See Kiali 2.4.14 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.0/html/observability/kiali-operator-provided-by-red-hat Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

🔗 References (8)