Red Hat Security Advisory: Kiali 2.22.2 for Red Hat OpenShift Service Mesh 3.3
Kiali 2.22.2, for Red Hat OpenShift Service Mesh 3.3, provides observability for the service mesh by offering a visual representation of the mesh topology and metrics, helping users monitor, trace, and manage efficiently. Security Fix(es): * CVE-2025-62718 Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization (OSSM-13237, OSSM-13238) * CVE-2026-25679 Incorrect parsing of IPv6 host literals in net/url (OSSM-13272) * CVE-2026-29074 SVGO: Denial of Service via XML entity expansion (OSSM-13274, OSSM-13275) * CVE-2026-29063 Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (OSSM-13276, OSSM-13277, OSSM-13278) * CVE-2026-33186 gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (OSSM-13279, OSSM-13280) * CVE-2026-4800 lodash: Arbitrary code execution via untrusted input in template imports (OSSM-13281, OSSM-13282) * CVE-2026-34986 Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (OSSM-13283) * CVE-2026-40175 Axios: Remote Code Execution via Prototype Pollution escalation (OSSM-13284, OSSM-13285) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
Axios versions used in Red Hat Advanced Cluster Security for Kubernetes prior to the 4.9.7 update improperly handle hostname normalization when evaluating NO_PROXY environment variables. This flaw allows attackers to craft requests targeting loopback addresses that bypass NO_PROXY rules, causing requests to be routed through the configured proxy instead of being excluded. This behavior can be exploited to perform SSRF attacks, potentially accessing sensitive internal or loopback services. Exploitation requires the attacker to influence URLs passed to axios in a server-side context, have both HTTP_PROXY and NO_PROXY configured, and rely on a proxy that can intercept or be compromised to misuse the rerouted traffic. Red Hat has issued a security advisory and released updated RHACS images containing fixes for this vulnerability. No alternative mitigations meeting Red Hat's criteria are currently available.
Potential Impact
Successful exploitation of this vulnerability can lead to SSRF, allowing attackers to access internal or loopback services that should be protected by NO_PROXY rules. However, the impact is limited by the need for specific environmental conditions and attacker capabilities, including control over server-side axios URL inputs and proxy configurations. The vulnerability is rated as high severity by Red Hat due to the potential confidentiality impact, though integrity and availability impacts are low.
Mitigation Recommendations
Red Hat advises upgrading to RHACS version 4.9.7 or later to address this vulnerability. No other mitigations meeting Red Hat's criteria for ease of use, applicability, and stability are currently available. Users should apply the updated images provided by Red Hat as soon as possible to benefit from the security patches.
Red Hat Security Advisory: Kiali 2.22.2 for Red Hat OpenShift Service Mesh 3.3
Description
Kiali 2.22.2, for Red Hat OpenShift Service Mesh 3.3, provides observability for the service mesh by offering a visual representation of the mesh topology and metrics, helping users monitor, trace, and manage efficiently. Security Fix(es): * CVE-2025-62718 Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization (OSSM-13237, OSSM-13238) * CVE-2026-25679 Incorrect parsing of IPv6 host literals in net/url (OSSM-13272) * CVE-2026-29074 SVGO: Denial of Service via XML entity expansion (OSSM-13274, OSSM-13275) * CVE-2026-29063 Immutable.js: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (OSSM-13276, OSSM-13277, OSSM-13278) * CVE-2026-33186 gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (OSSM-13279, OSSM-13280) * CVE-2026-4800 lodash: Arbitrary code execution via untrusted input in template imports (OSSM-13281, OSSM-13282) * CVE-2026-34986 Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (OSSM-13283) * CVE-2026-40175 Axios: Remote Code Execution via Prototype Pollution escalation (OSSM-13284, OSSM-13285) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Axios versions used in Red Hat Advanced Cluster Security for Kubernetes prior to the 4.9.7 update improperly handle hostname normalization when evaluating NO_PROXY environment variables. This flaw allows attackers to craft requests targeting loopback addresses that bypass NO_PROXY rules, causing requests to be routed through the configured proxy instead of being excluded. This behavior can be exploited to perform SSRF attacks, potentially accessing sensitive internal or loopback services. Exploitation requires the attacker to influence URLs passed to axios in a server-side context, have both HTTP_PROXY and NO_PROXY configured, and rely on a proxy that can intercept or be compromised to misuse the rerouted traffic. Red Hat has issued a security advisory and released updated RHACS images containing fixes for this vulnerability. No alternative mitigations meeting Red Hat's criteria are currently available.
Potential Impact
Successful exploitation of this vulnerability can lead to SSRF, allowing attackers to access internal or loopback services that should be protected by NO_PROXY rules. However, the impact is limited by the need for specific environmental conditions and attacker capabilities, including control over server-side axios URL inputs and proxy configurations. The vulnerability is rated as high severity by Red Hat due to the potential confidentiality impact, though integrity and availability impacts are low.
Mitigation Recommendations
Red Hat advises upgrading to RHACS version 4.9.7 or later to address this vulnerability. No other mitigations meeting Red Hat's criteria for ease of use, applicability, and stability are currently available. Users should apply the updated images provided by Red Hat as soon as possible to benefit from the security patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:20938
- Cve Count
- 10
- Additional Cves
- ["CVE-2026-32281","CVE-2026-40175","CVE-2026-40895","CVE-2026-42033","CVE-2026-42035","CVE-2026-42039","CVE-2026-42041","CVE-2026-42043","CVE-2026-42044"]
Threat ID: 6a160973e29bf47b5063cc97
Added to database: 05/26/2026, 20:58:27 UTC
Last enriched: 08/14/2026, 23:28:51 UTC
Last updated: 09/15/2026, 01:45:37 UTC
Views: 142
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.