Skip to main content
EPSS 0.5%top 62%

Red Hat Security Advisory: Kiali 1.73.27 for Red Hat OpenShift Service Mesh 2.6

0
High
Published: 02/23/2026 (02/23/2026, 17:16:07 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Kiali 1.73.27, for Red Hat OpenShift Service Mesh 2.6, provides observability for the service mesh by offering a visual representation of the mesh topology and metrics, helping users monitor, trace, and manage efficiently Security Fix(es): * kiali-ossmc-rhel8: Axios affected by Denial of Service via __proto__ Key in mergeConfig (CVE-2026-25639) * kiali-rhel8: Axios affected by Denial of Service via __proto__ Key in mergeConfig (CVE-2026-25639) * kiali-rhel8: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)

Affected software

Affected versions
Red HatRed Hat OpenShift Service MeshRed Hat OpenShift Service Mesh 2.6amd64registry.redhat.io/openshift-service-mesh/kiali-rhel8@sha256:148cd3650dbfad079a80ff1b908aa6d992f7b2063aa4bda3687f04e1655b5e36_amd64cert-manager operator for Red Hat OpenShiftcert-manager operator for Red Hat OpenShift 1.18registry.redhat.io/cert-manager/cert-manager-istio-csr-rhel9@sha256:e64804e94fe3781b7d371097e53749867a2b4b1783ada1660b5363e9df3cdb44_amd64registry.redhat.io/cert-manager/cert-manager-istio-csr-rhel9@sha256:41df7aabbce42599bad7fdc721cd12aa6e12d17e1c0658fb3294a1f68483d656_amd64Red Hat Web TerminalRed Hat Web Terminal 1.12registry.redhat.io/web-terminal/web-terminal-exec-rhel9@sha256:423baadb7daeaf78b5df584e7e5e8f2ad991e0db803a22ec7a90f7d468e55415_amd64Red Hat Satellite 6Red Hat Satellite 6.16 for RHEL 8Red Hat Edge ManagerRHEM 1.0 for RHEL 9srcflightctl-0:1.0.3-1.el9em.srcRHEM 1.1 for RHEL 10RHEM 1.1 for RHEL 9<1.32.10-r0Red Hat OpenShift AIRed Hat OpenShift AI 2.25registry.redhat.io/rhoai/odh-built-in-detector-rhel9@sha256:89cdb5783188b1b594cd7e0c6da1993397d60fe706e3469c331693f38c168b4d_amd64

Weaknesses

CWE-1050CWE-1287CWE-409CWE-606CWE-770CWE-367CWE-1289CWE-1341CWE-1286CWE-764CWE-551CWE-295CWE-787CWE-281CWE-1284CWE-772CWE-476CWE-256CWE-303CWE-22CWE-1333CWE-940CWE-346CWE-918CWE-306CWE-250CWE-338CWE-915CWE-639CWE-266CWE-79CWE-835CWE-444CWE-88CWE-212CWE-502CWE-93CWE-201CWE-805CWE-824CWE-617CWE-347CWE-807CWE-911CWE-776CWE-674CWE-214CWE-78CWE-1389CWE-125CWE-914CWE-414

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 21:53:27 UTC

Technical Analysis

The advisory covers two main vulnerabilities in Kiali 1.73.27 for Red Hat OpenShift Service Mesh 2.6. CVE-2025-61729 is a golang vulnerability where a specially crafted certificate triggers unbounded string concatenation during error string construction in HostnameError.Error(), leading to excessive resource consumption and potential denial of service. CVE-2026-25639 affects Axios used in Kiali, where a denial of service can be triggered via the __proto__ key in the mergeConfig function. Both vulnerabilities can cause denial of service conditions by exhausting CPU, memory, or other resources. Red Hat classifies the impact as important and assigns a high severity rating. The advisory does not explicitly state a fixed version but references Kiali 1.73.27 as the version containing the fixes.

Potential Impact

Successful exploitation of CVE-2025-61729 can cause denial of service due to excessive resource consumption (CPU, memory, or other resources) triggered by a crafted certificate during error processing in golang. CVE-2026-25639 can cause denial of service via manipulation of the __proto__ key in Axios mergeConfig. Both vulnerabilities impact availability by potentially causing service disruption or degradation in Red Hat OpenShift Service Mesh 2.6 environments running Kiali 1.73.27 or earlier. There is no indication of confidentiality or integrity impact.

Mitigation Recommendations

Red Hat has released Kiali version 1.73.27 for OpenShift Service Mesh 2.6 which includes fixes for these vulnerabilities. Users should upgrade to this version to remediate the issues. No additional mitigations or workarounds are specified in the advisory. Since this is not a cloud service, remediation is the responsibility of the user. Patch status is confirmed by the vendor advisory referencing Kiali 1.73.27 as the fixed version.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:3107
Cve Count
2
Additional Cves
["CVE-2026-25639"]
State
PUBLISHED

Threat ID: 6a160970e29bf47b50638281

Added to database: 05/26/2026, 20:58:24 UTC

Last enriched: 08/14/2026, 21:53:27 UTC

Last updated: 09/14/2026, 10:01:28 UTC

Views: 85

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:3107https://access.redhat.com/security/cve/CVE-2025-61729https://access.redhat.com/security/cve/CVE-2026-25639https://access.redhat.com/security/cve/cve-2025-61729https://access.redhat.com/security/cve/cve-2026-25639https://access.redhat.com/security/updates/classificationhttps://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1038https://access.redhat.com/security/cve/CVE-2025-66471https://access.redhat.com/security/cve/CVE-2026-21441https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.htmlCanonical URLhttps://access.redhat.com/errata/RHSA-2026:1166Canonical URLhttps://access.redhat.com/errata/RHSA-2026:27076https://access.redhat.com/security/updates/classification/#important24184622445356244983324563332456336245633824563392458856SAT-44720SAT-45906Canonical URLhttps://access.redhat.com/errata/RHSA-2026:36796https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5/html/managing_device_fleets_with_the_red_hat_edge_manager/assembly-edge-manager-introhttps://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.15/html-single/edge_manager/index#edge-mgr-intro244534524559722455975245633524577292466505246650724678222480680https://access.redhat.com/errata/RHSA-2026:41019https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1/html/installing_red_hat_edge_manager_on_red_hat_enterprise_linux/rhem-integrating-with-aaphttps://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1/html/installing_red_hat_edge_manager_on_red_hat_openshift_container_platform/edge-manager-install-rhem-ocp#edge-manager-verify-rhem-acm-console2480681https://access.redhat.com/errata/RHSA-2026:42047https://access.redhat.com/security/cve/CVE-2026-27145https://access.redhat.com/security/cve/CVE-2026-32280https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/cve/CVE-2026-32282https://access.redhat.com/security/cve/CVE-2026-33810https://access.redhat.com/security/cve/CVE-2026-33811https://access.redhat.com/security/cve/CVE-2026-39821https://access.redhat.com/security/cve/CVE-2026-42504https://redhat.atlassian.net/browse/WTO-359https://redhat.atlassian.net/browse/WTO-402https://redhat.atlassian.net/browse/WTO-407https://redhat.atlassian.net/browse/WTO-413https://redhat.atlassian.net/browse/WTO-418https://redhat.atlassian.net/browse/WTO-429https://redhat.atlassian.net/browse/WTO-433https://redhat.atlassian.net/browse/WTO-448https://redhat.atlassian.net/browse/WTO-450Reference 63https://access.redhat.com/errata/RHSA-2026:65126https://access.redhat.com/security/cve/CVE-2025-67030https://access.redhat.com/security/cve/CVE-2026-12151https://access.redhat.com/security/cve/CVE-2026-12243https://access.redhat.com/security/cve/CVE-2026-13149https://access.redhat.com/security/cve/CVE-2026-15075https://access.redhat.com/security/cve/CVE-2026-15154https://access.redhat.com/security/cve/CVE-2026-15378https://access.redhat.com/security/cve/CVE-2026-15581https://access.redhat.com/security/cve/CVE-2026-16745https://access.redhat.com/security/cve/CVE-2026-18608https://access.redhat.com/security/cve/CVE-2026-18611https://access.redhat.com/security/cve/CVE-2026-18617https://access.redhat.com/security/cve/CVE-2026-18620https://access.redhat.com/security/cve/CVE-2026-18621https://access.redhat.com/security/cve/CVE-2026-25681https://access.redhat.com/security/cve/CVE-2026-26996https://access.redhat.com/security/cve/CVE-2026-27136https://access.redhat.com/security/cve/CVE-2026-27904Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses