RHSA-2026:5131HighCVSS 7.5
Red Hat Security Advisory: Kiali 2.11.8 for Red Hat OpenShift Service Mesh 3.1
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption
🎯 Affected products9
- Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:1454f58ab00a466be972c9fb8b25524a969e1a196d5770864e0d8a712ec5a13c_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:aa26823292475d756abc269fae2299e9efec5a00c723a6d556915839a7fb4b11_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:aa296799ebe885ac5d29aca2a1794204eb97cf6748a02cfe75632aae173ebe50_s390x as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:cb3b7b9f73df5e57ec9e56ba8aa3ab648331694855a3efab5db402cb74d17e34_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:110c2d89711dc09ef64ab194997710fa9fcb425ce98567366cedbec8385348d3_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:1ea4ceadb3c16b2819de87a361c2963ba5221eb487c383a38f571c2cb4621669_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:8a0cd7af8acc148468fe8ac718e0d80687e6c59372f0e3f87393a72482fc1277_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:e48de806d43e401584c78ae25691b9edf4a93396fa3ed459e403282f95564a56_s390x as a component of Red Hat OpenShift Service Mesh 3.1
✅ Remediation
See Kiali 2.11.8 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.1/html/observability/kiali-operator-provided-by-red-hat Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:5131
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-68121
- externalhttps://access.redhat.com/security/cve/cve-2025-61726
- externalhttps://access.redhat.com/security/cve/cve-2025-68121
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_5131.json