Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.1.12
🔗 CVE IDs covered (18)
📋 Description
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-39825 — net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls CVE-2026-50572 — envoy: envoy: ext_authz use-after-free after rejecting an HTTP request CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-73511 — envoy: envoy: path matching bypass via per-segment parameters not stripped by router CVE-2026-73513 — envoy: envoy: HTTP/2 trailers without END_STREAM in oghttp2 cause heap use-after-free CVE-2026-73546 — envoy: envoy: stored XSS through dynamically generated stat names in admin interface CVE-2026-73547 — envoy: envoy: ext_authz crash on CONNECT requests without :path pseudo-header CVE-2026-73548 — envoy: envoy: connection poisoning through generic non-WebSocket HTTP upgrade requests CVE-2026-73549 — envoy: envoy: scoped IPv6 handling crash for HTTP/3 clients in original DST clusters CVE-2026-73550 — envoy: envoy: HTTP/2 memory exhaustion via discarded Host headers not counted in limits CVE-2026-73551 — envoy: envoy: path normalization bypass via dot/dot-dot segments with parameters CVE-2026-73552 — envoy: envoy: RBAC safe_regex fails to match non-UTF-8 HTTP header values CVE-2026-73553 — envoy: envoy: RBAC authorization bypass when path-parameter stripping is enabled
🎯 Affected products26
- Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh-tech-preview/istio-ztunnel-rhel9@sha256:083d716a65d38c594834ef23c1f58d82db2dadb53839b0592634642f07056898_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh-tech-preview/istio-ztunnel-rhel9@sha256:0ddd440ad576a9386df1c297f40cbe441abe1c2bdc7e135b4e380f3391dd42d1_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh-tech-preview/istio-ztunnel-rhel9@sha256:b82183a582c81d027eb2dff9edde6d251f27ce73338b93dff3cb9c0d0121cbd1_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh-tech-preview/istio-ztunnel-rhel9@sha256:eaa07bac206415d869c11c6b0ae35b9e69c3c5096194da011c4e59afce88576c_s390x as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:3310ef15ec51db6d42424b59003810ef82433bb4f216bf62c5ac06198bdf8ab8_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:5fd2d9c600ae46b86402bc06496006cb13642e2a9661d90c8ab23cea9fed15ba_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:675c59668d6b8813125d25a1fda99536c841b4e8ba050d9bd1209fea886e59ac_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:f27e53966a538e5c9be9136fda6ee939b1e1ae178f50aff7225805642cf272f6_s390x as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:12a379e721bd69f730550f7f2b68a2515e5da29ec3d309d2268acf245a89f81c_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:495a5267e462a1a7f41dbc8d21fa712d874624b2dacbaafd039ea23db35b4f26_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:eda102599f89ca316c194b296e90d0924043e6e7cc3df11f66bac84e26708a3d_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:fa6d9be050907e80d859e8ede390156bb7db72c3ffeb5b046172addb96ef9b52_s390x as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:4271a3a1815a544168990b0c49e5b297e302c8f2ebab42a4e1347ac944d8cfe5_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:6aaf6ae8457377dcb522c882d41ce528e97cb9dbc657ec006782bc0afaa0bb10_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:a6f3b2871050d1d49a5a1e7acbc391d0b3d05f80be8275501bfa9a7ba277993e_s390x as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:dd1ff3d2e08595ea5ee1c077e5b049c54c0115ef02e3b5ae00203727ef4ad496_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:005a5f7c0d8dfba971609b6cffe7ff4d20ea1271ed4b7b5a99161f46d9c0f779_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:24f10dd378af1f1cb935734efd57064881899d1d7f37333f6e7cc275b1e3a5de_s390x as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:7cf632f4760c7a97847ca2cc8fc7bbe9d5285ff2ca3ea23bd49c834542d98d68_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:ce2ff7eed3f4692e611ada5b5a7a7e927b400618a75c38d8bfa2baecb1a9d34e_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:43fedbb46995785fa9a85914f3fe56dab9f73f87f436477eb02490c21f5b4034_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:505d5d1b2c6415b390ee39ee7242c6671befddc8cddbf8345904ae95c0599256_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:636782d2a4dc01982b448268751ebf752cd3b7aa789ad9bbc16d091111f3f71a_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:b3f3ac266130fc78dbeebec1b1d31473a98d826a9b45911620952a83de313286_s390x as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:1fc184f8a69ecfac1d9567f273dd1d37268fd7c9c8978782ae91fe5ce9d72904_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
✅ Remediation
See Red Hat OpenShift Service Mesh 3.1.12 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.1 Workaround: Increase the maximum number of query parameters allowed by setting the GODEBUG environment variable `urlmaxqueryparams` to a higher value (e.g., `GODEBUG=urlmaxqueryparams=20000`), or validate and enforce security controls on query parameters at the backend service rather than relying solely on the ReverseProxy's Rewrite or Director function for security filtering. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (21)
- selfhttps://access.redhat.com/errata/RHSA-2026:65112
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-39825
- externalhttps://access.redhat.com/security/cve/CVE-2026-50572
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-73511
- externalhttps://access.redhat.com/security/cve/CVE-2026-73513
- externalhttps://access.redhat.com/security/cve/CVE-2026-73546
- externalhttps://access.redhat.com/security/cve/CVE-2026-73547
- externalhttps://access.redhat.com/security/cve/CVE-2026-73548
- externalhttps://access.redhat.com/security/cve/CVE-2026-73549
- externalhttps://access.redhat.com/security/cve/CVE-2026-73550
- externalhttps://access.redhat.com/security/cve/CVE-2026-73551
- externalhttps://access.redhat.com/security/cve/CVE-2026-73552
- externalhttps://access.redhat.com/security/cve/CVE-2026-73553
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_65112.json