RHSA-2026:68691HighCVSS 7.5

Red Hat Security Advisory: Kiali 2.17.14 for Red Hat OpenShift Service Mesh 3.2

Published
September 17, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-59879 — immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing

🎯 Affected products9

  • Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:0d923dc90918be7f34251876dd5cfa4c4055485860cfc4842dbe34a46f811820_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:38f5d43c3e9ab30a6fc5f6ab6910d15fcac599c66982dd9a44b6f81efe097991_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:760e8d7b05c89e5f733f43542d08f94e5dc88d8ba1be05d720ca52c3275d8182_s390x as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:b80935ae6f349d032e44edc8e6597d3bd08a562fb8d6b8123ed876bec25de351_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:4558c1a9568a9aa31973d1b2bb70cbce1e10ac7a2e7afd8a3135059bd0a42e43_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:91ed80b181ec486dfedfba6862d1e5e3d4e4d6e516de36eb7b05ec2c07e2fb14_s390x as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:a2b2056215b10963dc9bdffab90a3481d9412bff8335c86ee463aabd60e33828_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:bafbb9ade590447759c1d9f080a0e6a2be02e436912ed8f2d482e99a1bc34825_amd64 as a component of Red Hat OpenShift Service Mesh 3.2

✅ Remediation

See Kiali 2.17.14 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.2/html/observability/kiali-operator-provided-by-red-hat Workaround: To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort.

🔗 References (9)