RHSA-2026:68695HighCVSS 7.5

Red Hat Security Advisory: Kiali 2.27.4 for Red Hat OpenShift Service Mesh 3.4

Published
September 17, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-45820 — fflate: fflate: Denial of Service via crafted ZIP archives CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-75838 — dompurify: DOMPurify: Cross-Site Scripting via IN_PLACE sanitization CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing

🎯 Affected products14

  • Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-operator-bundle@sha256:896af31083024229cf6a374a8b7fb586a9fcba79ee1fec2994bf0ebe4f368714_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:b0f9a4cdc3003f1d82faf4130875ab160d7aa6e7a06ff0c9fa2957f2baead00e_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:c5f3b706c375afc44acf3132e8ceced3cc132ba2e6c9ca71f2992d0683c395b8_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:dbde9c2f66225ee98652e145d574136b0f61629ed347d1ea638e897852182ef8_arm64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:e92496baa0f7007348e0308fdc47183a8058b84f8ed7b66c636fa96892ebf428_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9-operator@sha256:001644cace33a253da0e1675f0f047b8852c355c32554a35b1b551cbe5d5e17c_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9-operator@sha256:881d2b4b54b3a79b3e4aa98f7150e6612508fd5b51937f04ed25f6a27dc88e2b_arm64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9-operator@sha256:92125431177aa557141e761939ad12955455dadf28988d21002c7e29e68892c6_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9-operator@sha256:add67996fb8f7a14ae9834d136061e03b343f5d4e3595e95860920f6af95b696_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:00a87e941c275ac2a82f410054c5730f24752969511b5c638d17d70a5703c7e7_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:53c7b293f6fec0462394128ca3a22b1e3124eb018bc419ee15f75686be891b6d_arm64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:8939fd2ca94680072b54512c807eb20783e815149be99c00dad2ac4c4c125c28_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:fc6d16528f4e7486eba432ad3614f976cecdf7a2e9bff4b06c1da6d317de991a_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4

✅ Remediation

See Kiali 2.27.4 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.4/html/observability/kiali-operator-provided-by-red-hat Workaround: There is no available mitigation for this flaw other than updating the bundled fflate library to a fixed version (0.8.3 or later). Where the application controls the input, avoid passing untrusted ZIP archives to fflate's unzip()/unzipSync() APIs. Workaround: To mitigate this vulnerability, avoid using DOMPurify with a custom IN_PLACE sanitization configuration that includes an element-removal hook. Default DOMPurify configurations are not affected by this flaw.

🔗 References (10)