Red Hat Security Advisory: Kiali 1.73.27 for Red Hat OpenShift Service Mesh 2.6
Kiali 1.73.27, for Red Hat OpenShift Service Mesh 2.6, provides observability for the service mesh by offering a visual representation of the mesh topology and metrics, helping users monitor, trace, and manage efficiently Security Fix(es): * kiali-ossmc-rhel8: Axios affected by Denial of Service via __proto__ Key in mergeConfig (CVE-2026-25639) * kiali-rhel8: Axios affected by Denial of Service via __proto__ Key in mergeConfig (CVE-2026-25639) * kiali-rhel8: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)
AI Analysis
Technical Summary
The advisory covers two main vulnerabilities in Kiali 1.73.27 for Red Hat OpenShift Service Mesh 2.6. CVE-2025-61729 is a golang vulnerability where a specially crafted certificate triggers unbounded string concatenation during error string construction in HostnameError.Error(), leading to excessive resource consumption and potential denial of service. CVE-2026-25639 affects Axios used in Kiali, where a denial of service can be triggered via the __proto__ key in the mergeConfig function. Both vulnerabilities can cause denial of service conditions by exhausting CPU, memory, or other resources. Red Hat classifies the impact as important and assigns a high severity rating. The advisory does not explicitly state a fixed version but references Kiali 1.73.27 as the version containing the fixes.
Potential Impact
Successful exploitation of CVE-2025-61729 can cause denial of service due to excessive resource consumption (CPU, memory, or other resources) triggered by a crafted certificate during error processing in golang. CVE-2026-25639 can cause denial of service via manipulation of the __proto__ key in Axios mergeConfig. Both vulnerabilities impact availability by potentially causing service disruption or degradation in Red Hat OpenShift Service Mesh 2.6 environments running Kiali 1.73.27 or earlier. There is no indication of confidentiality or integrity impact.
Mitigation Recommendations
Red Hat has released Kiali version 1.73.27 for OpenShift Service Mesh 2.6 which includes fixes for these vulnerabilities. Users should upgrade to this version to remediate the issues. No additional mitigations or workarounds are specified in the advisory. Since this is not a cloud service, remediation is the responsibility of the user. Patch status is confirmed by the vendor advisory referencing Kiali 1.73.27 as the fixed version.
Red Hat Security Advisory: Kiali 1.73.27 for Red Hat OpenShift Service Mesh 2.6
Description
Kiali 1.73.27, for Red Hat OpenShift Service Mesh 2.6, provides observability for the service mesh by offering a visual representation of the mesh topology and metrics, helping users monitor, trace, and manage efficiently Security Fix(es): * kiali-ossmc-rhel8: Axios affected by Denial of Service via __proto__ Key in mergeConfig (CVE-2026-25639) * kiali-rhel8: Axios affected by Denial of Service via __proto__ Key in mergeConfig (CVE-2026-25639) * kiali-rhel8: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The advisory covers two main vulnerabilities in Kiali 1.73.27 for Red Hat OpenShift Service Mesh 2.6. CVE-2025-61729 is a golang vulnerability where a specially crafted certificate triggers unbounded string concatenation during error string construction in HostnameError.Error(), leading to excessive resource consumption and potential denial of service. CVE-2026-25639 affects Axios used in Kiali, where a denial of service can be triggered via the __proto__ key in the mergeConfig function. Both vulnerabilities can cause denial of service conditions by exhausting CPU, memory, or other resources. Red Hat classifies the impact as important and assigns a high severity rating. The advisory does not explicitly state a fixed version but references Kiali 1.73.27 as the version containing the fixes.
Potential Impact
Successful exploitation of CVE-2025-61729 can cause denial of service due to excessive resource consumption (CPU, memory, or other resources) triggered by a crafted certificate during error processing in golang. CVE-2026-25639 can cause denial of service via manipulation of the __proto__ key in Axios mergeConfig. Both vulnerabilities impact availability by potentially causing service disruption or degradation in Red Hat OpenShift Service Mesh 2.6 environments running Kiali 1.73.27 or earlier. There is no indication of confidentiality or integrity impact.
Mitigation Recommendations
Red Hat has released Kiali version 1.73.27 for OpenShift Service Mesh 2.6 which includes fixes for these vulnerabilities. Users should upgrade to this version to remediate the issues. No additional mitigations or workarounds are specified in the advisory. Since this is not a cloud service, remediation is the responsibility of the user. Patch status is confirmed by the vendor advisory referencing Kiali 1.73.27 as the fixed version.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:3107
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-25639"]
- State
- PUBLISHED
Threat ID: 6a160970e29bf47b50638281
Added to database: 05/26/2026, 20:58:24 UTC
Last enriched: 08/14/2026, 21:53:27 UTC
Last updated: 09/14/2026, 10:01:28 UTC
Views: 85
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.