RHSA-2026:59583HighCVSS 8.6

Red Hat Security Advisory: Kiali 2.27.3 for Red Hat OpenShift Service Mesh 3.4

Published
August 25, 2026
Last Modified
August 29, 2026

🔗 CVE IDs covered (20)

📋 Description

CVE-2026-14257 — brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-41178 — github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input CVE-2026-54272 — ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification CVE-2026-56852 — golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-67313 — axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON CVE-2026-67314 — axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth CVE-2026-67320 — axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter CVE-2026-67321 — axios: axios: Denial of Service via object serialization bypass CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass CVE-2026-73088 — browserslist: Browserslist: Prototype pollution leading to denial of service CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results

🎯 Affected products14

  • Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-operator-bundle@sha256:99ce58159389ee40323faa9a0fe5aac75ec89bf05b173448a6ee7133174a39ba_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:0fb23387faefdca92aa1407a399ddd6767e95f90ec7a344a192e6eaf841fe307_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:6ef4eb1ad50df9c37fe6308ca4566544ebe1d2dfc48aa3f49b80d86a5525930b_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:79838fa76f16fe44db043c968827e7d87f91b861edaf91ab01b623269d380352_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:b40fad37a5cd6728e0f3692e7e8b8319ab892cd7459f90d63a175e3fbe4e5b7b_arm64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9-operator@sha256:5b3d1441d5d53e6a3f814d65007b31f60e9f52d9581f4b057f7aa5dff0f94bd2_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9-operator@sha256:8c25f301074589750277a996a9f22a9802ab56f7185d622ef5ac2e521bc47d3d_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9-operator@sha256:8eb6025c068543c93c8a65f5bac687fec8714e9d21116add6f9695396ecc14fc_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9-operator@sha256:c73109306b6d0317ca53ac7bf6928ecdda3d26767e6fbe654d0013dfed5e8374_arm64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:153323fec32e89c72d25c5e791809ef1e2101a93bc10bc291ccbbeda8b0472c1_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:18380df413ccfe56b2342aeb7811e5f1cadb3574d7b791c8de5cd234cf016004_arm64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:aa4479c9cefa462ebd06f5be23decc5ea618d3417d0719e30acf4a5e2139a81f_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:c49297779447cba6baaf1df86091d01fac23f9d3a5af745304f2e9b4abb9ba28_amd64 as a component of Red Hat OpenShift Service Mesh 3.4

✅ Remediation

See Kiali 2.27.3 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.4/html/observability/kiali-operator-provided-by-red-hat Workaround: Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely. Workaround: To reduce exposure, ensure that the `browserslist` tool processes only trusted `browserslist-stats.json`, `opts.stats`, and CLI `--stats` data. Avoid using the tool with untrusted input sources in development or build environments. If `browserslist` is integrated into automated pipelines, validate all input data originates from trusted sources.

🔗 References (24)