Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:49765 - Security Advisory
Issued:
2026-08-03
Updated:
2026-08-03

RHSA-2026:49765 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Red Hat OpenShift Service Mesh 3.3.6

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Service Mesh 3.3.6

This update has a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Service Mesh 3.3.6, which is based on the open source Istio project, addresses a variety of problems in a microservice architecture by creating a centralized point of control in an application.

Security Fix(es):

  • CVE-2026-27145 openshift-service-mesh/istio-proxyv2-rhel9: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (OSSM-14633)
  • CVE-2026-27145 openshift-service-mesh/istio-pilot-rhel9: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (OSSM-14633)
  • CVE-2026-27145 openshift-service-mesh/istio-cni-rhel9: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (OSSM-14633)
  • CVE-2026-27145 openshift-service-mesh/istio-rhel9-operator: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (OSSM-14633)
  • CVE-2026-48743 openshift-service-mesh/istio-proxyv2-rhel9: Envoy: Request desynchronization allows security policy bypass via HTTP/3 to HTTP/1 translation (OSSM-14882)
  • CVE-2026-47204 openshift-service-mesh/istio-proxyv2-rhel9: Envoy: Denial of Service via Connect protocol request (OSSM-14883)
  • CVE-2026-47221 openshift-service-mesh/istio-proxyv2-rhel9: Envoy: Null pointer deref in internal redirects (OSSM-14884)
  • CVE-2026-48042 openshift-service-mesh/istio-proxyv2-rhel9: Envoy: Denial of Service via deeply nested JSON objects (OSSM-14885)
  • CVE-2026-48044 openshift-service-mesh/istio-proxyv2-rhel9: Envoy: Denial of Service via specially crafted zstd payload (OSSM-14886)
  • CVE-2026-48706 openshift-service-mesh/istio-proxyv2-rhel9: Envoy Heap Buffer Overflow in TcpStatsdSink (OSSM-14887)

Fixes/Improvements:

  • Istiod-default-validator points to non-existent istiod Service after OSSM 3.3.4 upgrade when using non-default Istio name with default revision tag (OSSM-14646)

Solution

See Red Hat OpenShift Service Mesh 3.3.6 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.3

Affected Products

  • Red Hat OpenShift Service Mesh

Fixes

(none)

CVEs

  • CVE-2026-27145
  • CVE-2026-47204
  • CVE-2026-47221
  • CVE-2026-48042
  • CVE-2026-48044
  • CVE-2026-48706
  • CVE-2026-48743

References

  • https://access.redhat.com/security/updates/classification/

amd64

registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:ed441b7161d15b4f1b1e5fba0b7e7c10fced1de39ff17b18cf4ffa552235e6b1
registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:88e85b5bfe701c95ae5b52086c5916fec69f2df6a19148e1d1e818893453b4ca
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:73d9ab206c3ede1747f17736d75df8cf90badfc92026e0c1d0014b9adb0ff8fd
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:821f4acfea78e5207952841ab3c153cb42d8e5a0e9c5f79b6ac947e919523c44
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:ced221968e9eb8e9f9f7f073da99db9032c2677ee5c4342baf800d738befbee5
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:9eba1d3fbc947bb0fe267818fc7a5e06bf403004a045e80c65b2592a7bd06da4
registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:26d46e7ca66a08614de1e43b1b6a32ab6f56dd02408a93be317956db354df023

arm64

registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:68ddaeddb2e22ed94e0de9a0dc07fcae90265047280376bba562b39dccfd54ae
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:4c3beafc255025f29b04c6e79f17944be5c697aa104bff48cd9b10c1510ecdd4
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:b3cac830d31372ec560fec29eddb344861b9cfd08bccb46a35b443e0997f8b6a
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:fe14d77cd8257197c8bb14ae4f3e85a3ba06e53b68627293be9686087dc129e9
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:2822039fd4beacdce9ba55663107db291846050ffae0a59c4a8059b81a2a99bd
registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:723c1bb7a91e040f29bc78817b140adb6e6bb4863f0bf7c529e27c9bfda118d4

ppc64le

registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:00d38604ec92065c2da6de5100eded9a3bd94429ef333ab30bffe9f4b88fa81a
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:d4897d5dbd9bcf39e0777462c71fa8cceb47cb1131102901e94356fa60647186
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:9b27c3c0ae1c827768f29ef1b5c411a8f725a04af6ad834c7e24a49835f2f13f
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:5942a3782d861044c6ba7afc822b59a8fd25dd93c93cb6b8d615c5a2d3b2a7c4
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:09292f6545b2e6619bbbd267024fa4f9c6c8b760e53cfc2833eb54d9f453453e
registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:6aa03c09ea788efeacaf5e189aa0ad98d7fbe9f072f2a5c3cb5b109c18b1d6fe

s390x

registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:30ec9e046bea82559e14663d660f5b0f2c3efa9919d7afe5b28710dd6e45d07b
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:7497ff1f09797032487b442cb1b96b154a1bd2267cd97443eca08cc5db209524
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:1a81558c67a5e3a62842ccf1ac5d686d9f83c448e693fe2ac83d46ec60c0f57d
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:75c04065e4a708a4ba4ccecca06bd7ba703405922181d466801c94a351d37ecf
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:4938aa51aff7c6cd248fa954e00bc414221f4236001fc4b032305b33ce3cfa12
registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:5722dd927b0b6f6ad167ffc995514aea1bd029f7b036cc3437041e53b49f103d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility