Skip to main content
EPSS 1.0%top 40%

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.2.6

0
High
Published: 06/16/2026 (06/16/2026, 09:27:21 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Service Mesh 3.2.6, which is based on the open source Istio project, addresses a variety of problems in a microservice architecture by creating a centralized point of control in an application. Security Fix(es): * openshift-service-mesh/istio-proxyv2-rhel9: envoy: HTTP/2 Remote Denial of Service via HPACK compression bomb and Slowloris-style attack (CVE-2026-47774)

Affected software

Affected versions
>=3.0.0 <3.2.6Red HatRed Hat OpenShift Service MeshRed Hat OpenShift Service Mesh 2.6amd64registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:e6a6c65408f58c269bff76aced6bef45ee8547bd817f45146769109513992274_amd64Red Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:83ffcd8afe730203afd97713292fb56e29a120b6296d03439c0e8e8cf3013186_amd64Red Hat OpenShift Service Mesh 3.1registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:ad9538959ca5035ec315dbb597343b67dab3979417fc3003e77888f1a8ed7827_amd64< 1.35.11>= 1.36.0, < 1.36.7>= 1.37.0, < 1.37.3>= 1.38.0, < 1.38.1Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:e3712a16441ba402c3df852b757d2d04b83772cd3bb1858688c5df2faf9b9a77_amd64Red Hat OpenShift Service Mesh 3.0registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:afba220ae878102ac25604ec734206c4859eda22973804f89c51d85e6a92184e_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 15:51:28 UTC

Technical Analysis

CVE-2026-47774 is a denial-of-service vulnerability in Envoy's HTTP/2 HPACK header compression implementation, used in Red Hat OpenShift Service Mesh. The vulnerability allows a remote attacker to send crafted HTTP/2 requests that trigger disproportionately large memory allocations on the server, causing resource exhaustion and denial of service. This is due to improper handling of highly compressed data (CWE-409). Red Hat OpenShift Service Mesh versions >=3.0.0 and <3.2.6 are affected. Red Hat has issued a security advisory (RHSA-2026:26231) and released version 3.2.6 with a fix.

Potential Impact

The vulnerability can cause high resource consumption (CPU and memory) on affected systems, leading to degraded performance or system crashes due to denial of service. There is no impact on confidentiality or integrity, only availability is affected.

Mitigation Recommendations

Red Hat has released OpenShift Service Mesh version 3.2.6 which addresses this vulnerability. Users should upgrade to version 3.2.6 or later to remediate the issue. Refer to the Red Hat security advisory RHSA-2026:26231 and official documentation for detailed upgrade instructions. No other mitigations are specified or required.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:26231
Cve Count
1
Cvss Version
3.1

Threat ID: 6a32705b0b89be68881d44da

Added to database: 06/17/2026, 10:00:59 UTC

Last enriched: 08/16/2026, 15:51:28 UTC

Last updated: 09/13/2026, 23:10:37 UTC

Views: 324

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses