RHSA-2026:68690HighCVSS 7.5

Red Hat Security Advisory: Kiali 2.22.10 for Red Hat OpenShift Service Mesh 3.3

Published
September 17, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-45820 — fflate: fflate: Denial of Service via crafted ZIP archives CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-75838 — dompurify: DOMPurify: Cross-Site Scripting via IN_PLACE sanitization CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing

🎯 Affected products9

  • Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:5ad03378e442509d052ddab241ee1721922b0355e255ee1940fef1df60d12c27_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:769ed72348477103a7c40bb301dcb109b4a89b51ddce74b52faf154d9f444641_s390x as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:9215f07c2eec7b13b3410a9496ddffbb2d084e89fa7b07c27af65e0d6cd1965a_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:e417bbcd9d1aa32cc7e3ce82fe0cb6be4c01d8c72e0bf96e69076000314397b9_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:7bcb75d40c29cd74b4c472b31639ff3dff65009101c76523e478111e4258bebc_arm64 as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:7d891cde4a0da015fcd1f2792e2878ccee40b3e75deb968e3ded0ed99a716b48_ppc64le as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:b8394ab6e9e1697f68dba2695d2bfb973f8b7da3cdf47ecb37d8a90533baeeb9_amd64 as a component of Red Hat OpenShift Service Mesh 3.3
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:b86c32480d75d0f07dc9fc4a99eb19ad65e32629cc7f44f4cbcf682df8f42573_s390x as a component of Red Hat OpenShift Service Mesh 3.3

✅ Remediation

See Kiali 2.22.10 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.3/html/observability/kiali-operator-provided-by-red-hat Workaround: There is no available mitigation for this flaw other than updating the bundled fflate library to a fixed version (0.8.3 or later). Where the application controls the input, avoid passing untrusted ZIP archives to fflate's unzip()/unzipSync() APIs. Workaround: To mitigate this vulnerability, avoid using DOMPurify with a custom IN_PLACE sanitization configuration that includes an element-removal hook. Default DOMPurify configurations are not affected by this flaw.

🔗 References (10)