Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cve-2026-42044'

View all threats tagged with 'cve-2026-42044'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-42044

Threats Tagged 'cve-2026-42044'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat Security Advisory: Kiali 2.11.10 for Red Hat OpenShift Service Mesh 3.1CVE-2026-32280
0

Red Hat OpenShift Service Mesh 3. 1's Kiali component version 2. 11. 10 addresses multiple security vulnerabilities including denial of service, information disclosure, HTTP transport hijacking, arbitrary HTTP header injection, authentication bypass, and JSON response tampering. These issues stem from flaws in dependencies such as Go certificate chain building, follow-redirects, and Axios HTTP client, particularly involving prototype pollution and crafted URLs. The update is rated with a high security impact by Red Hat Product Security. No known exploits in the wild have been reported. The advisory provides updated RPM packages for remediation.

Join the discussion
Red Hat Security Advisory: Kiali 2.4.16 for Red Hat OpenShift Service Mesh 3.0CVE-2026-32280
0

Kiali 2. 4. 16 for Red Hat OpenShift Service Mesh 3. 0 addresses multiple security vulnerabilities affecting observability and management of service mesh topology and metrics. The update fixes eight distinct vulnerabilities including denial of service, information disclosure, HTTP transport hijacking, arbitrary HTTP header injection, authentication bypass, and JSON response tampering, primarily related to Go certificate chain building and prototype pollution issues in the Axios HTTP client. Red Hat has rated the overall security impact of these issues as critical. No explicit CVSS scores are provided in the advisory. The vulnerabilities affect Red Hat OpenShift Service Mesh 3. 0 deployments using Kiali 2. 4.

Join the discussion
Red Hat Security Advisory: Kiali 2.17.7 for Red Hat OpenShift Service Mesh 3.2CVE-2026-32280
0

Red Hat OpenShift Service Mesh 3. 2's Kiali component version 2. 17. 7 addresses multiple security vulnerabilities including denial of service, information disclosure, HTTP transport hijacking, arbitrary HTTP header injection, authentication bypass, and JSON response tampering. These issues stem from flaws in dependencies such as Go certificate chain building, follow-redirects, and Axios HTTP client, notably involving prototype pollution and crafted URL attacks. Red Hat has released an updated Kiali version 2. 17. 7 to remediate these vulnerabilities. The advisory rates the security impact as critical, though no CVSS scores are provided. There are no known exploits in the wild at this time.

Join the discussion
Red Hat Security Advisory: RHACS 4.9.7 security and bug fix updateCVE-2025-62718
0

Red Hat Advanced Cluster Security for Kubernetes (RHACS) version 4. 9. 7 includes multiple security and bug fixes addressing a set of vulnerabilities identified by CVE-2025-62718 and nine additional CVEs. The advisory highlights an important security update that resolves inconsistencies in CVE severity and fixes several security issues across components. Users of earlier RHACS versions are advised to upgrade to 4. 9. 7 to benefit from these patches. No known exploits in the wild have been reported for these vulnerabilities at this time.

Join the discussion
Red Hat Security Advisory: Kiali 1.73.31 for Red Hat OpenShift Service Mesh 2.6CVE-2026-32281
0

Kiali 1. 73. 31 for Red Hat OpenShift Service Mesh 2. 6 addresses two security vulnerabilities: CVE-2026-32281, a denial of service issue caused by inefficient certificate chain validation in Go's crypto/x509 package, and CVE-2026-42044, an invisible JSON response tampering vulnerability via prototype pollution in Axios. These vulnerabilities affect observability components that visualize and manage service mesh topology and metrics. Red Hat has released this update rated as having a Moderate security impact. No explicit patch details are provided in the advisory, but updated RPM packages for Kiali 1. 73. 31 are available. No known exploits in the wild have been reported.

Join the discussion
Red Hat Security Advisory: multicluster engine for Kubernetes v2.6.11 security updateCVE-2025-62718
0

Red Hat OpenShift Service Mesh 3. 1's Kiali component version 2. 11. 9 addresses multiple critical security vulnerabilities affecting various third-party libraries and components. These include server-side request forgery and proxy bypass, denial of service, prototype pollution leading to remote code execution, authorization bypass, and arbitrary code execution. The advisory covers eight CVEs impacting dependencies such as Axios, lodash, gRPC-Go, Immutable. js, SVGO, Go JOSE, and net/url parsing. Red Hat has released this updated Kiali version to remediate these issues. No known exploits in the wild have been reported at this time.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: cve-2026-42044
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses