RHSA-2026:5129HighCVSS 7.5
Red Hat Security Advisory: Kiali 2.4.14 for Red Hat OpenShift Service Mesh 3.0
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption
🎯 Affected products9
- Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:31fcf6c64980c5f5aae31bcefefa390a06f9a9d78478c3768d1d29406cfaf2f9_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:868bee43c5aa1a6f1bd7679ee99f8a420bc55e448c74252342aa85d1719114be_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:91547f3f22d7b9ed334601ae056f2322e555633af9fb71da44b8102bbf7719ca_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:d0d96c1ff664e73bab184017898c7119481c00bab8ac98e971ba9677cf98c579_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:446cce7b07e107aeac66e4ac3e74e41e0f1e952f9de2fbf49069500899e4e533_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:541f3c997549509601e29a3baad7afdf189190f45f0da3543bd2c19763b801cd_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:6eb41fcb4690319f7f8433d1d83a00c75251d96124a249512e877f0b58b17b23_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:7727fa1a840330b7a24ba8f291924b3670a8ec7cac16a13e9268109f777a8150_s390x as a component of Red Hat OpenShift Service Mesh 3.0
✅ Remediation
See Kiali 2.4.14 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.0/html/observability/kiali-operator-provided-by-red-hat Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:5129
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/cve-2025-61726
- externalhttps://access.redhat.com/security/cve/cve-2025-68121
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5129.json