RHSA-2026:65106HighCVSS 8.1

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.0.15

Published
September 8, 2026
Last Modified
September 17, 2026

🔗 CVE IDs covered (18)

CVE-2026-56853CVE-2026-33818CVE-2026-39825CVE-2026-56858CVE-2026-56860CVE-2026-73548 · pendingCVE-2026-73549 · pendingCVE-2026-73550 · pendingCVE-2026-73511 · pendingCVE-2026-73551 · pendingCVE-2026-73553 · pendingCVE-2026-50572 · pendingCVE-2026-56859CVE-2026-56862CVE-2026-73513 · pendingCVE-2026-73546 · pendingCVE-2026-73547 · pendingCVE-2026-73552 · pending

📋 Description

CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-39825 — net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls CVE-2026-50572 — envoy: envoy: ext_authz use-after-free after rejecting an HTTP request CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-73511 — envoy: envoy: path matching bypass via per-segment parameters not stripped by router CVE-2026-73513 — envoy: envoy: HTTP/2 trailers without END_STREAM in oghttp2 cause heap use-after-free CVE-2026-73546 — envoy: envoy: stored XSS through dynamically generated stat names in admin interface CVE-2026-73547 — envoy: envoy: ext_authz crash on CONNECT requests without :path pseudo-header CVE-2026-73548 — envoy: envoy: connection poisoning through generic non-WebSocket HTTP upgrade requests CVE-2026-73549 — envoy: envoy: scoped IPv6 handling crash for HTTP/3 clients in original DST clusters CVE-2026-73550 — envoy: envoy: HTTP/2 memory exhaustion via discarded Host headers not counted in limits CVE-2026-73551 — envoy: envoy: path normalization bypass via dot/dot-dot segments with parameters CVE-2026-73552 — envoy: envoy: RBAC safe_regex fails to match non-UTF-8 HTTP header values CVE-2026-73553 — envoy: envoy: RBAC authorization bypass when path-parameter stripping is enabled

🎯 Affected products26

  • Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:25e62cf6f61f23426447448409f44f70272d348787180983cd8fac84a1c2842b_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:64ea3accffb5aae6bba702135c7515e6cba4139a11e7c50d922466bf00702b07_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:ca3b0ad3adc6cb42dbb3c8e80b55649ef09a6f5b70c6d186cf00360d84dff99c_s390x as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:d25e53e05618055b4817703c27611f7eb36a5862efa21f88b1324414afed06ef_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:06c59127232704d22fc20bde68bef9ae8ae155ec1d90dd153a6f217f0ae77a88_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:0bcd21ad4d0dd9233972d0343a846343a7830fff981e77092ce0efd4c7dce056_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:114c2d8f805e20e2e1a49f4291b60c513e378f5360ca17d8303e58b2ef1ed9b4_s390x as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:1db604f1ae63096819cf93f270091d7d23308d152862d1c3121db6b9ed5e155a_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:0191fd74aab21fb7482f2bfdb57b08884910cd00c968f5f03df260bb3e137c6b_s390x as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:054c247a7d49d9d973d6f72fc4cfe1c7742f2243d87b4b518b7b04789a4a24d9_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:7a14702627ed430ec8fd688eaaace7648fc08e2e8277b8ae4a18a9fff94bb5c2_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:abd08e5193631af6fce57869a8bf19bc46f501146fe1260e6cb616811783f1a5_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:2f20ef03d500268455dda62e017d1aaddcf1ab5bce3e08163afae51e3d9c236b_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:6fc69b6b7c9929c3acf00d8ab06a4c1f4f916a8eba1ee22adac376ba3fcf5635_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:8ac0f5ce78617bab61539255e97f182f2a1b1d8491adcae9d27d1757f02c3849_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:c839fa764645c52fd3f40989d231706ef05f63ade536ccb312c4e9718a934c40_s390x as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:0b21488cd868210ed7e8cba745414e4daf40483e8cebe6058a34cbda83b11cfd_s390x as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:13c0b9cb79e8475fdc40865ba1b68997afdc03bc2ed0bc1e0ed67f581f63fb68_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:33fec0cbbd8c276d1db10f7461adf93f4cafbf6703c184532180dea8e76c4e77_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:d4344eb4b4c6ce9ac5219dbb2d556a3c54f82bc39358158ba8ca5d395e92457a_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:25e3039cd79737181a25ee29af17717e2faef25bde8f8bb02ae7efa808362746_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:4f3ddd104108a77c679f5c0097d9cd18cdc56b4b4ad3727334fe60cd2f054fae_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:7f1de9aea1dff65a8b1b3c5f8574a2fc6cce7d8ee1425118a34289d7ec109367_s390x as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:8d6ea9cb2913c606aceac872e41b40b2d2435eba77361995b95403721c03c633_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
  • registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:a539d099456345ff3d70c00305931a5e79066a84f9cf76c187d748a908848cae_amd64 as a component of Red Hat OpenShift Service Mesh 3.0

✅ Remediation

See Red Hat OpenShift Service Mesh 3.0.15 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.0 Workaround: Increase the maximum number of query parameters allowed by setting the GODEBUG environment variable `urlmaxqueryparams` to a higher value (e.g., `GODEBUG=urlmaxqueryparams=20000`), or validate and enforce security controls on query parameters at the backend service rather than relying solely on the ReverseProxy's Rewrite or Director function for security filtering. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (21)