Skip to main content
EPSS 0.7%top 48%

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.6.15

0
High
Published: 04/29/2026 (04/29/2026, 12:20:23 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Service Mesh 2.6.15, which is based on the open source Istio project, addresses a variety of problems in a microservice architecture by creating a centralized point of control in an application. Security Fix(es): * istio-operator-rhel8: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-cni-rhel8: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * pilot-rhel8: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * ratelimit-rhel8: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-cni-rhel8: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) * pilot-rhel8: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) * istio-rhel8-operator: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) * istio-cni-rhel8: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) * pilot-rhel8: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) * ratelimit-rhel8: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) * istio-rhel8-operator: possible memory corruption after bound check elimination (CVE-2026-27143) * istio-cni-rhel8: possible memory corruption after bound check elimination (CVE-2026-27143) * pilot-rhel8: possible memory corruption after bound check elimination (CVE-2026-27143) * ratelimit-rhel8: possible memory corruption after bound check elimination (CVE-2026-27143) * istio-rhel8-operator: no-op interface conversion bypasses overlap checking (CVE-2026-27144) * istio-cni-rhel8: no-op interface conversion bypasses overlap checking (CVE-2026-27144) * pilot-rhel8: no-op interface conversion bypasses overlap checking (CVE-2026-27144) * ratelimit-rhel8: no-op interface conversion bypasses overlap checking (CVE-2026-27144)

Affected software

Affected versions
>=2.6.0 <2.6.15Red HatRed Hat OpenShift Service MeshRed Hat OpenShift Service Mesh 2.6amd64registry.redhat.io/openshift-service-mesh/istio-operator-bundle@sha256:eb939796d4c218cf2dcb1f74452a4f1928076aed130b84a2cd7da07ffc24a929_amd64Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 10)srcrhc-worker-playbook-0:0.2.3-4.el10_1.src

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 19:17:22 UTC

Technical Analysis

The Red Hat OpenShift Service Mesh 2.6.15 update fixes several vulnerabilities primarily related to the Go standard library and Istio components. CVE-2026-25679 involves incorrect parsing of IPv6 host literals in net/url.Parse, which improperly accepts invalid URLs by ignoring garbage before an IP-literal. Other vulnerabilities include denial of service via crafted JSON Web Encryption (JWE) objects (CVE-2026-34986), denial of service in certificate chain building (CVE-2026-32280), possible memory corruption after bound check elimination (CVE-2026-27143), and no-op interface conversion bypassing overlap checking (CVE-2026-27144). These issues affect multiple components of the OpenShift Service Mesh such as istio-operator-rhel8, istio-cni-rhel8, pilot-rhel8, and ratelimit-rhel8. The update to version 2.6.15 addresses these vulnerabilities.

Potential Impact

The vulnerabilities can lead to denial of service conditions and potential memory corruption in affected components of Red Hat OpenShift Service Mesh. Specifically, the incorrect parsing of IPv6 host literals can cause the system to accept invalid URLs, potentially disrupting service availability. Denial of service vulnerabilities in JSON Web Encryption handling and certificate chain building can cause service interruptions. Memory corruption issues may affect stability and reliability. No confidentiality or integrity impacts are reported.

Mitigation Recommendations

Red Hat has released OpenShift Service Mesh version 2.6.15 which includes fixes for these vulnerabilities. Users should upgrade to version 2.6.15 to remediate the issues. No alternative mitigations meeting Red Hat's criteria are currently available. Refer to Red Hat's official advisory and documentation for upgrade instructions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:11688
Cve Count
5
Additional Cves
["CVE-2026-27143","CVE-2026-27144","CVE-2026-32280","CVE-2026-34986"]
State
PUBLISHED

Threat ID: 6a16095be29bf47b50624ed7

Added to database: 05/26/2026, 20:58:03 UTC

Last enriched: 08/14/2026, 19:17:22 UTC

Last updated: 09/10/2026, 19:42:35 UTC

Views: 91

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses