Skip to main content
EPSS 1.2%top 35%

Red Hat Security Advisory: Kiali 2.22.2 for Red Hat OpenShift Service Mesh 3.3

0
Critical
Published: 04/16/2026 (04/16/2026, 14:41:31 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Kiali 2.22.2, for Red Hat OpenShift Service Mesh 3.3, provides observability for the service mesh by offering a visual representation of the mesh topology and metrics, helping users monitor, trace, and manage efficiently. Security Fix(es): * CVE-2025-62718 Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization (OSSM-13237, OSSM-13238) * CVE-2026-25679 Incorrect parsing of IPv6 host literals in net/url (OSSM-13272) * CVE-2026-29074 SVGO: Denial of Service via XML entity expansion (OSSM-13274, OSSM-13275) * CVE-2026-29063 Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (OSSM-13276, OSSM-13277, OSSM-13278) * CVE-2026-33186 gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (OSSM-13279, OSSM-13280) * CVE-2026-4800 lodash: Arbitrary code execution via untrusted input in template imports (OSSM-13281, OSSM-13282) * CVE-2026-34986 Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (OSSM-13283) * CVE-2026-40175 Axios: Remote Code Execution via Prototype Pollution escalation (OSSM-13284, OSSM-13285) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected software

Affected versions
>=4.9.0 <4.9.7Red HatRed Hat Advanced Cluster SecurityRed Hat Advanced Cluster Security 4.9amd64registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:35f6d1d992eea9f67da1adf5418823547cb0dff248a54556d06ec7156fb35e87_amd64Red Hat Advanced Cluster Security for KubernetesRed Hat Advanced Cluster Security for Kubernetes 4.10registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:a32574be1c7a5a9ef0aa8b8ce4946ffe4920cb72b402eb17d1ca07c43925faef_amd64Red Hat Advanced Cluster Security for Kubernetes 4.9Red Hat QuayRed Hat Quay 3.10registry.redhat.io/quay/quay-container-security-operator-bundle@sha256:6171d21593edfd320b55fb27381e5fb16cb98ee77f37bbf51da755c99727a253_amd64Red Hat OpenShift Service MeshRed Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:daa972852bddb585e4ff5fa28d41680bea204fb29cac28a8f354d1a93591ab0c_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 23:28:51 UTC

Technical Analysis

Axios versions used in Red Hat Advanced Cluster Security for Kubernetes prior to the 4.9.7 update improperly handle hostname normalization when evaluating NO_PROXY environment variables. This flaw allows attackers to craft requests targeting loopback addresses that bypass NO_PROXY rules, causing requests to be routed through the configured proxy instead of being excluded. This behavior can be exploited to perform SSRF attacks, potentially accessing sensitive internal or loopback services. Exploitation requires the attacker to influence URLs passed to axios in a server-side context, have both HTTP_PROXY and NO_PROXY configured, and rely on a proxy that can intercept or be compromised to misuse the rerouted traffic. Red Hat has issued a security advisory and released updated RHACS images containing fixes for this vulnerability. No alternative mitigations meeting Red Hat's criteria are currently available.

Potential Impact

Successful exploitation of this vulnerability can lead to SSRF, allowing attackers to access internal or loopback services that should be protected by NO_PROXY rules. However, the impact is limited by the need for specific environmental conditions and attacker capabilities, including control over server-side axios URL inputs and proxy configurations. The vulnerability is rated as high severity by Red Hat due to the potential confidentiality impact, though integrity and availability impacts are low.

Mitigation Recommendations

Red Hat advises upgrading to RHACS version 4.9.7 or later to address this vulnerability. No other mitigations meeting Red Hat's criteria for ease of use, applicability, and stability are currently available. Users should apply the updated images provided by Red Hat as soon as possible to benefit from the security patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:20938
Cve Count
10
Additional Cves
["CVE-2026-32281","CVE-2026-40175","CVE-2026-40895","CVE-2026-42033","CVE-2026-42035","CVE-2026-42039","CVE-2026-42041","CVE-2026-42043","CVE-2026-42044"]

Threat ID: 6a160973e29bf47b5063cc97

Added to database: 05/26/2026, 20:58:27 UTC

Last enriched: 08/14/2026, 23:28:51 UTC

Last updated: 09/15/2026, 01:45:37 UTC

Views: 142

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:20938https://access.redhat.com/security/cve/CVE-2025-62718https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/cve/CVE-2026-40175https://access.redhat.com/security/cve/CVE-2026-40895https://access.redhat.com/security/cve/CVE-2026-42033https://access.redhat.com/security/cve/CVE-2026-42035https://access.redhat.com/security/cve/CVE-2026-42039https://access.redhat.com/security/cve/CVE-2026-42041https://access.redhat.com/security/cve/CVE-2026-42043https://access.redhat.com/security/cve/CVE-2026-42044https://access.redhat.com/security/cve/CVE-2026-42264https://access.redhat.com/security/cve/CVE-2026-44486https://access.redhat.com/security/cve/CVE-2026-44487https://access.redhat.com/security/cve/CVE-2026-44488https://access.redhat.com/security/cve/CVE-2026-44492https://access.redhat.com/security/cve/CVE-2026-44494https://access.redhat.com/security/cve/CVE-2026-44495https://access.redhat.com/security/cve/CVE-2026-44496https://access.redhat.com/security/updates/classification/https://access.redhat.com/errata/RHSA-2026:20889https://access.redhat.com/security/cve/CVE-2026-25679https://access.redhat.com/security/cve/CVE-2026-32280https://access.redhat.com/errata/RHSA-2026:9742https://access.redhat.com/security/cve/CVE-2025-69534https://access.redhat.com/security/cve/CVE-2025-69873https://access.redhat.com/security/cve/CVE-2026-1525https://access.redhat.com/security/cve/CVE-2026-1526https://access.redhat.com/security/cve/CVE-2026-1528https://access.redhat.com/security/cve/CVE-2026-2229https://access.redhat.com/security/cve/CVE-2026-26996https://access.redhat.com/security/cve/CVE-2026-27601https://access.redhat.com/security/cve/CVE-2026-27904https://access.redhat.com/security/cve/CVE-2026-29063https://access.redhat.com/security/cve/CVE-2026-29074https://access.redhat.com/security/cve/CVE-2026-29186https://access.redhat.com/security/cve/CVE-2026-3118https://access.redhat.com/security/cve/CVE-2026-32141https://access.redhat.com/security/cve/CVE-2026-33036https://access.redhat.com/security/cve/CVE-2026-33228https://access.redhat.com/security/cve/CVE-2026-33891https://access.redhat.com/errata/RHSA-2026:22840https://access.redhat.com/security/cve/CVE-2026-2377https://access.redhat.com/security/cve/CVE-2026-32282https://access.redhat.com/security/cve/CVE-2026-32589https://access.redhat.com/security/cve/CVE-2026-32590https://access.redhat.com/security/cve/CVE-2026-33894https://access.redhat.com/security/cve/CVE-2026-34986https://access.redhat.com/security/cve/CVE-2026-39892https://access.redhat.com/security/cve/CVE-2026-40192https://access.redhat.com/security/cve/CVE-2026-4598https://access.redhat.com/errata/RHSA-2026:24866https://access.redhat.com/security/cve/CVE-2026-23490https://access.redhat.com/security/cve/CVE-2026-28390https://access.redhat.com/security/cve/CVE-2026-28684https://access.redhat.com/security/cve/CVE-2026-33154https://access.redhat.com/security/cve/CVE-2026-39363https://access.redhat.com/security/cve/CVE-2026-39364https://access.redhat.com/security/cve/CVE-2026-40217https://access.redhat.com/security/cve/CVE-2026-41140https://access.redhat.com/security/cve/CVE-2026-48710https://access.redhat.com/security/cve/CVE-2026-4926https://access.redhat.com/security/cve/CVE-2026-6321https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updatesCanonical URLhttps://access.redhat.com/errata/RHSA-2026:22629Canonical URLhttps://access.redhat.com/errata/RHSA-2026:8493https://access.redhat.com/security/cve/CVE-2026-33186https://access.redhat.com/security/cve/CVE-2026-4800https://access.redhat.com/security/updates/classificationCanonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses