Red Hat Security Advisory: Kiali 2.11.17 for Red Hat OpenShift Service Mesh 3.1
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-59879 — immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing
🎯 Affected products9
- Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:102155c444c1caa56937cd741b772be1f70829d0a26732595a319b22d545ca0e_s390x as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:7429107a358e113a3317ab445f45b590f57be2ebf94aedba90530c6be1ed52b9_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:7d3ea5ea548b51358fa209b758f2bd62e0df0f55f9d41e6f1f049b416376bbae_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:ebaf6f2f52204561d85a18ae261693b4dbcd3f543e803a5bfa1ab68e2c86a101_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:005ae6799f222f44294f8183beae1d15feeba7b2557609752b27d239e1412bbb_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:1a4271b12d6ddc1ff878f96eaccbbde594ba10ba6b51286ffbc997016cdced2b_s390x as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:640c4985be9a2cb55d8e297f7139acb54b44b28fc723b3be8991511c9c80a0c3_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
- registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:86cf39acee952be3687dd69c6e3e7a8a3f86a648e482345eb62d58d38bf429db_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
✅ Remediation
See Kiali 2.11.17 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.1/html/observability/kiali-operator-provided-by-red-hat Workaround: To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2026:68689
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-59879
- externalhttps://access.redhat.com/security/cve/CVE-2026-84375
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68689.json