RHSA-2026:5130HighCVSS 7.5

Red Hat Security Advisory: Kiali 2.17.5 for Red Hat OpenShift Service Mesh 3.2

Published
March 19, 2026
Last Modified
September 5, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption

🎯 Affected products9

  • Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:4f0d6107986e9d5e938a7e91167d07101271d6888edaf928a2e3bb7f8fc1329c_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:55bae2098ea48527447b5c2ec1c7097be824c995efbe3965d8f0062df213f353_s390x as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:64455f263717b320daa11658c69fadf653dca717011bf99a311fc40f539909bc_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:90c9e53707dab0ab5d459c831c7261c44a34e30010a456f6b7d4aa941e945567_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:36b721aa3905d1968d59ac8c7b7a94452a789ec3b6421e42f0b9f02cac510a93_s390x as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:b12f2c95748fe15693f868f504c583fddd6a70eb158061b2f924d360ac5e2b34_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:bae8264c3e4095670361ed400dc82020782ba8117a58a738b09d21c49ec348d9_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:f7958a05b7f26028bea2790065f5acc00f28e13501919b5ab66074fabf3e04c1_amd64 as a component of Red Hat OpenShift Service Mesh 3.2

✅ Remediation

See Kiali 2.17.5 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.2/html/observability/kiali-operator-provided-by-red-hat Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

🔗 References (8)