Red Hat Security Advisory: Kiali 2.4.23 for Red Hat OpenShift Service Mesh 3.0
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-59879 — immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing
🎯 Affected products9
- Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:4f3e00f4e2bea2e19b9526dadb6f38881ce9ce9cf8962e1725e724c7ccb25626_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:52f157c587f62188bb2816d76562ce5e0ae0751ac7d8b40e9497fa7b7858f576_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:8749c4826054a448ce5db47fc8c4ca6e297a096cc187513fb1fd20892715324c_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:b392a75159a261dcf85e3f1c5832cb6c3dcc91afce7b765e8d1a633936d294a5_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:36b34247561a75006a9884c1679be740c2e5c07d582868d451272de47251bac8_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:47b90abe445f781b5f7f47ea60fda1b19453cb518bf044584130f1dd80d0122a_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:cd22a01d85d4d1026b37cfdd62df0509c31be9871827a58716d66b61fa5be37c_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:d7940d2744313a17045a670db146235d11b43600db6a018e87127938ed3db011_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
✅ Remediation
See Kiali 2.4.23 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.0/html/observability/kiali-operator-provided-by-red-hat Workaround: To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:68687
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-59879
- externalhttps://access.redhat.com/security/cve/CVE-2026-84375
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68687.json