Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.6.15
Red Hat OpenShift Service Mesh 2.6.15, which is based on the open source Istio project, addresses a variety of problems in a microservice architecture by creating a centralized point of control in an application. Security Fix(es): * istio-operator-rhel8: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-cni-rhel8: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * pilot-rhel8: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * ratelimit-rhel8: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-cni-rhel8: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) * pilot-rhel8: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) * istio-rhel8-operator: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) * istio-cni-rhel8: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) * pilot-rhel8: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) * ratelimit-rhel8: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) * istio-rhel8-operator: possible memory corruption after bound check elimination (CVE-2026-27143) * istio-cni-rhel8: possible memory corruption after bound check elimination (CVE-2026-27143) * pilot-rhel8: possible memory corruption after bound check elimination (CVE-2026-27143) * ratelimit-rhel8: possible memory corruption after bound check elimination (CVE-2026-27143) * istio-rhel8-operator: no-op interface conversion bypasses overlap checking (CVE-2026-27144) * istio-cni-rhel8: no-op interface conversion bypasses overlap checking (CVE-2026-27144) * pilot-rhel8: no-op interface conversion bypasses overlap checking (CVE-2026-27144) * ratelimit-rhel8: no-op interface conversion bypasses overlap checking (CVE-2026-27144)
AI Analysis
Technical Summary
The Red Hat OpenShift Service Mesh 2.6.15 update fixes several vulnerabilities primarily related to the Go standard library and Istio components. CVE-2026-25679 involves incorrect parsing of IPv6 host literals in net/url.Parse, which improperly accepts invalid URLs by ignoring garbage before an IP-literal. Other vulnerabilities include denial of service via crafted JSON Web Encryption (JWE) objects (CVE-2026-34986), denial of service in certificate chain building (CVE-2026-32280), possible memory corruption after bound check elimination (CVE-2026-27143), and no-op interface conversion bypassing overlap checking (CVE-2026-27144). These issues affect multiple components of the OpenShift Service Mesh such as istio-operator-rhel8, istio-cni-rhel8, pilot-rhel8, and ratelimit-rhel8. The update to version 2.6.15 addresses these vulnerabilities.
Potential Impact
The vulnerabilities can lead to denial of service conditions and potential memory corruption in affected components of Red Hat OpenShift Service Mesh. Specifically, the incorrect parsing of IPv6 host literals can cause the system to accept invalid URLs, potentially disrupting service availability. Denial of service vulnerabilities in JSON Web Encryption handling and certificate chain building can cause service interruptions. Memory corruption issues may affect stability and reliability. No confidentiality or integrity impacts are reported.
Mitigation Recommendations
Red Hat has released OpenShift Service Mesh version 2.6.15 which includes fixes for these vulnerabilities. Users should upgrade to version 2.6.15 to remediate the issues. No alternative mitigations meeting Red Hat's criteria are currently available. Refer to Red Hat's official advisory and documentation for upgrade instructions.
Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.6.15
Description
Red Hat OpenShift Service Mesh 2.6.15, which is based on the open source Istio project, addresses a variety of problems in a microservice architecture by creating a centralized point of control in an application. Security Fix(es): * istio-operator-rhel8: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-cni-rhel8: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * pilot-rhel8: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * ratelimit-rhel8: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * istio-cni-rhel8: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) * pilot-rhel8: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) * istio-rhel8-operator: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) * istio-cni-rhel8: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) * pilot-rhel8: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) * ratelimit-rhel8: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) * istio-rhel8-operator: possible memory corruption after bound check elimination (CVE-2026-27143) * istio-cni-rhel8: possible memory corruption after bound check elimination (CVE-2026-27143) * pilot-rhel8: possible memory corruption after bound check elimination (CVE-2026-27143) * ratelimit-rhel8: possible memory corruption after bound check elimination (CVE-2026-27143) * istio-rhel8-operator: no-op interface conversion bypasses overlap checking (CVE-2026-27144) * istio-cni-rhel8: no-op interface conversion bypasses overlap checking (CVE-2026-27144) * pilot-rhel8: no-op interface conversion bypasses overlap checking (CVE-2026-27144) * ratelimit-rhel8: no-op interface conversion bypasses overlap checking (CVE-2026-27144)
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Red Hat OpenShift Service Mesh 2.6.15 update fixes several vulnerabilities primarily related to the Go standard library and Istio components. CVE-2026-25679 involves incorrect parsing of IPv6 host literals in net/url.Parse, which improperly accepts invalid URLs by ignoring garbage before an IP-literal. Other vulnerabilities include denial of service via crafted JSON Web Encryption (JWE) objects (CVE-2026-34986), denial of service in certificate chain building (CVE-2026-32280), possible memory corruption after bound check elimination (CVE-2026-27143), and no-op interface conversion bypassing overlap checking (CVE-2026-27144). These issues affect multiple components of the OpenShift Service Mesh such as istio-operator-rhel8, istio-cni-rhel8, pilot-rhel8, and ratelimit-rhel8. The update to version 2.6.15 addresses these vulnerabilities.
Potential Impact
The vulnerabilities can lead to denial of service conditions and potential memory corruption in affected components of Red Hat OpenShift Service Mesh. Specifically, the incorrect parsing of IPv6 host literals can cause the system to accept invalid URLs, potentially disrupting service availability. Denial of service vulnerabilities in JSON Web Encryption handling and certificate chain building can cause service interruptions. Memory corruption issues may affect stability and reliability. No confidentiality or integrity impacts are reported.
Mitigation Recommendations
Red Hat has released OpenShift Service Mesh version 2.6.15 which includes fixes for these vulnerabilities. Users should upgrade to version 2.6.15 to remediate the issues. No alternative mitigations meeting Red Hat's criteria are currently available. Refer to Red Hat's official advisory and documentation for upgrade instructions.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:11688
- Cve Count
- 5
- Additional Cves
- ["CVE-2026-27143","CVE-2026-27144","CVE-2026-32280","CVE-2026-34986"]
- State
- PUBLISHED
Threat ID: 6a16095be29bf47b50624ed7
Added to database: 05/26/2026, 20:58:03 UTC
Last enriched: 08/14/2026, 19:17:22 UTC
Last updated: 09/10/2026, 19:42:35 UTC
Views: 91
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.