Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.3.7
🔗 CVE IDs covered (18)
📋 Description
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-39825 — net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls CVE-2026-50572 — envoy: envoy: ext_authz use-after-free after rejecting an HTTP request CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-73511 — envoy: envoy: path matching bypass via per-segment parameters not stripped by router CVE-2026-73513 — envoy: envoy: HTTP/2 trailers without END_STREAM in oghttp2 cause heap use-after-free CVE-2026-73546 — envoy: envoy: stored XSS through dynamically generated stat names in admin interface CVE-2026-73547 — envoy: envoy: ext_authz crash on CONNECT requests without :path pseudo-header CVE-2026-73548 — envoy: envoy: connection poisoning through generic non-WebSocket HTTP upgrade requests CVE-2026-73549 — envoy: envoy: scoped IPv6 handling crash for HTTP/3 clients in original DST clusters CVE-2026-73550 — envoy: envoy: HTTP/2 memory exhaustion via discarded Host headers not counted in limits CVE-2026-73551 — envoy: envoy: path normalization bypass via dot/dot-dot segments with parameters CVE-2026-73552 — envoy: envoy: RBAC safe_regex fails to match non-UTF-8 HTTP header values CVE-2026-73553 — envoy: envoy: RBAC authorization bypass when path-parameter stripping is enabled
🎯 Affected products26
- Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:06d2290678383535a72adf45124b4ff4cd112e7488af5ff2b7ade0274e61958e_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:79ab7b6bcfcd078bc1d4b432b66c4556b9713d0185d1451c290e5fec0fc19147_s390x as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:a464c1950dbb8fd6671cd7c9a931da21d53ee2b4f0da2080811f480747d9c165_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:e3a308f371571e57ce3e1d06a9b82c8a5e6ea7a6a011ee9ab13c2a5a593ca2f3_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:7734ec145a1e150f724011f6ecdac20aedd59526add43e54826caf34671e439b_s390x as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:7ab3ebf0fdc1f2cd4eb1811d5f0d3d72551feb6b32bdc8129477d7f3bcd44dea_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:c91a30de947e1e8940733903af6bf278fdab15c4d46d7059fa7fe9b1c4f847fc_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:e89b769b9346ef32020497a817d7a6ee2f11d9c9e19a01e45bf59ee5bc39b74e_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:16eed6d7deb07c19d61d95047c7add6470c09294235a230c5dbd18984858986c_s390x as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:5adbe715c519ac65ef4f930b3ada2326e534684bedc495fd66edc861e113e6eb_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:6b3c9e21a907eec910e44f397781e4992e290ec4370428d8a85d829245667ef2_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:78b8134d45567565eb0eb365042b3c43414fed25e8d1b4b40d3029e864d9f72b_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:2231054be7e3cf53578c362ec677e2fecabf96e8516696b4e79710d5b6f875ac_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:5dd85b7b1238aef2ba8da10843bf368234b90e5b7df1b5d8025c4ba40464f14f_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:783b72559574075f713eaceea3bc428d7ec3274a2f9a475d7033d4b92f4575ba_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:c0b7d9fea706615ba973eb44c7c44eec4859d5037696e1b1c880fa4022f430d3_s390x as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:2a900ea36f46630f379d62ba6844b20f261f2ac259d663ccadc3cc4594b49653_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:4d2c5e711320b986bddfa52c72d292430fee0196a88fdc4af0f10a9cdcb03970_s390x as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:74e7228e6a477391e0223a3946d94483309e57eb4d4696b03ffa7342a9e3d2f4_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:769d18355f8955e68b6f91f282c63074b7253dfdc7a8937c4854318143df4fac_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:40ee95b790be644721ed77d2179ebf0cf539bce06a6f89d1f815be796f6c5133_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:6ae671c569cd553f9f48c8c3bf8d00a16db97178d0748f44ef3b6fb74c750038_s390x as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:adc34cb413d31fa5d8a4bd6c560588079c3c271ad9de961da5aced5f6954ec70_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:bf50a2807786e8be677017637355ce0db54d8aa60eb096543bfa4f787c4a4e1a_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
- registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:facaa199b4e2d33ddeef587b67227580e09a1725546608bc7e01b64d319995c4_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
✅ Remediation
See Red Hat OpenShift Service Mesh 3.3.7 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.3 Workaround: Increase the maximum number of query parameters allowed by setting the GODEBUG environment variable `urlmaxqueryparams` to a higher value (e.g., `GODEBUG=urlmaxqueryparams=20000`), or validate and enforce security controls on query parameters at the backend service rather than relying solely on the ReverseProxy's Rewrite or Director function for security filtering. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (21)
- selfhttps://access.redhat.com/errata/RHSA-2026:65115
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-39825
- externalhttps://access.redhat.com/security/cve/CVE-2026-50572
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-73511
- externalhttps://access.redhat.com/security/cve/CVE-2026-73513
- externalhttps://access.redhat.com/security/cve/CVE-2026-73546
- externalhttps://access.redhat.com/security/cve/CVE-2026-73547
- externalhttps://access.redhat.com/security/cve/CVE-2026-73548
- externalhttps://access.redhat.com/security/cve/CVE-2026-73549
- externalhttps://access.redhat.com/security/cve/CVE-2026-73550
- externalhttps://access.redhat.com/security/cve/CVE-2026-73551
- externalhttps://access.redhat.com/security/cve/CVE-2026-73552
- externalhttps://access.redhat.com/security/cve/CVE-2026-73553
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_65115.json