Red Hat Security Advisory: Kiali 2.11.9 for Red Hat OpenShift Service Mesh 3.1
Kiali 2.11.9, for Red Hat OpenShift Service Mesh 3.1, provides observability for the service mesh by offering a visual representation of the mesh topology and metrics, helping users monitor, trace, and manage efficiently. Security Fix(es): * CVE-2025-62718 Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization (OSSM-13231, OSSM-13234) * CVE-2026-25679 Incorrect parsing of IPv6 host literals in net/url (OSSM-12921) * CVE-2026-29074 SVGO: Denial of Service via XML entity expansion (OSSM-12897, OSSM-12898) * CVE-2026-29063 Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (OSSM-12977, OSSM-12978) * CVE-2026-33186 gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (OSSM-13012) * CVE-2026-4800 lodash: Arbitrary code execution via untrusted input in template imports (OSSM-13119, OSSM-13120) * CVE-2026-34986 Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (OSSM-13147) * CVE-2026-40175 Axios: Remote Code Execution via Prototype Pollution escalation (OSSM-13256, OSSM-13257) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
This Red Hat security advisory concerns the multicluster engine for Kubernetes version 2.6 images, which enable centralized management of Kubernetes clusters across data centers, public clouds, and private clouds. The advisory references multiple CVEs including CVE-2025-62718 and several CVE-2026 series vulnerabilities. The update to version 2.6.11 includes security updates, bug fixes, and enhancements. The advisory does not provide explicit patch or remediation details but points users to installation documentation for updated images. The multicluster engine is not a cloud service; thus, remediation depends on user deployment of updated images. No known exploits in the wild have been reported at this time.
Potential Impact
The vulnerabilities affect the multicluster engine for Kubernetes v2.6 images used for centralized cluster management. The impact is rated high severity by the source, indicating potential significant security risks if exploited. However, specific impacts per CVE are not detailed in the provided data. The vulnerabilities could affect the security posture of Kubernetes cluster management, potentially impacting configuration distribution and cluster lifecycle operations.
Mitigation Recommendations
The vendor advisory indicates updated images in the multicluster engine for Kubernetes v2.6.11 release that include security updates and bug fixes. Users should follow Red Hat's official documentation to install or upgrade to these updated images. Since this is not a cloud service, remediation requires user action to deploy the updated images. Patch status is not explicitly confirmed in the advisory; therefore, users should consult the Red Hat advisory page (https://access.redhat.com/errata/RHSA-2026:17657) for the latest remediation guidance and ensure they apply the recommended updates promptly.
Red Hat Security Advisory: Kiali 2.11.9 for Red Hat OpenShift Service Mesh 3.1
Description
Kiali 2.11.9, for Red Hat OpenShift Service Mesh 3.1, provides observability for the service mesh by offering a visual representation of the mesh topology and metrics, helping users monitor, trace, and manage efficiently. Security Fix(es): * CVE-2025-62718 Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization (OSSM-13231, OSSM-13234) * CVE-2026-25679 Incorrect parsing of IPv6 host literals in net/url (OSSM-12921) * CVE-2026-29074 SVGO: Denial of Service via XML entity expansion (OSSM-12897, OSSM-12898) * CVE-2026-29063 Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (OSSM-12977, OSSM-12978) * CVE-2026-33186 gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (OSSM-13012) * CVE-2026-4800 lodash: Arbitrary code execution via untrusted input in template imports (OSSM-13119, OSSM-13120) * CVE-2026-34986 Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (OSSM-13147) * CVE-2026-40175 Axios: Remote Code Execution via Prototype Pollution escalation (OSSM-13256, OSSM-13257) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory concerns the multicluster engine for Kubernetes version 2.6 images, which enable centralized management of Kubernetes clusters across data centers, public clouds, and private clouds. The advisory references multiple CVEs including CVE-2025-62718 and several CVE-2026 series vulnerabilities. The update to version 2.6.11 includes security updates, bug fixes, and enhancements. The advisory does not provide explicit patch or remediation details but points users to installation documentation for updated images. The multicluster engine is not a cloud service; thus, remediation depends on user deployment of updated images. No known exploits in the wild have been reported at this time.
Potential Impact
The vulnerabilities affect the multicluster engine for Kubernetes v2.6 images used for centralized cluster management. The impact is rated high severity by the source, indicating potential significant security risks if exploited. However, specific impacts per CVE are not detailed in the provided data. The vulnerabilities could affect the security posture of Kubernetes cluster management, potentially impacting configuration distribution and cluster lifecycle operations.
Mitigation Recommendations
The vendor advisory indicates updated images in the multicluster engine for Kubernetes v2.6.11 release that include security updates and bug fixes. Users should follow Red Hat's official documentation to install or upgrade to these updated images. Since this is not a cloud service, remediation requires user action to deploy the updated images. Patch status is not explicitly confirmed in the advisory; therefore, users should consult the Red Hat advisory page (https://access.redhat.com/errata/RHSA-2026:17657) for the latest remediation guidance and ensure they apply the recommended updates promptly.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:8490
- Cve Count
- 8
- Additional Cves
- ["CVE-2026-4800","CVE-2026-25679","CVE-2026-29063","CVE-2026-29074","CVE-2026-33186","CVE-2026-34986","CVE-2026-40175"]
- Cvss Version
- null
Threat ID: 6a160952e29bf47b50618cc8
Added to database: 05/26/2026, 20:57:54 UTC
Last enriched: 07/30/2026, 12:11:07 UTC
Last updated: 07/31/2026, 21:47:06 UTC
Views: 96
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.