RHSA-2026:5130HighCVSS 7.5
Red Hat Security Advisory: Kiali 2.17.5 for Red Hat OpenShift Service Mesh 3.2
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption
🎯 Affected products9
- Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:4f0d6107986e9d5e938a7e91167d07101271d6888edaf928a2e3bb7f8fc1329c_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:55bae2098ea48527447b5c2ec1c7097be824c995efbe3965d8f0062df213f353_s390x as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:64455f263717b320daa11658c69fadf653dca717011bf99a311fc40f539909bc_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:90c9e53707dab0ab5d459c831c7261c44a34e30010a456f6b7d4aa941e945567_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:36b721aa3905d1968d59ac8c7b7a94452a789ec3b6421e42f0b9f02cac510a93_s390x as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:b12f2c95748fe15693f868f504c583fddd6a70eb158061b2f924d360ac5e2b34_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:bae8264c3e4095670361ed400dc82020782ba8117a58a738b09d21c49ec348d9_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:f7958a05b7f26028bea2790065f5acc00f28e13501919b5ab66074fabf3e04c1_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
✅ Remediation
See Kiali 2.17.5 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.2/html/observability/kiali-operator-provided-by-red-hat Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:5130
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/cve-2025-61726
- externalhttps://access.redhat.com/security/cve/cve-2025-68121
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5130.json