- Issued:
- 2026-09-08
- Updated:
- 2026-09-08
RHSA-2026:65106 - Security Advisory
Synopsis
Red Hat OpenShift Service Mesh 3.0.15
Type/Severity
Security Advisory: Important
Topic
Red Hat OpenShift Service Mesh 3.0.15
This update has a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
Red Hat OpenShift Service Mesh 3.0.15, which is based on the open source Istio project, addresses a variety of problems in a microservice architecture by creating a centralized point of control in an application.
Security Fix(es):
- CVE-2026-39825 openshift-service-mesh/istio-proxyv2-rhel9: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (OSSM-15834)
- CVE-2026-39825 openshift-service-mesh/istio-pilot-rhel9: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (OSSM-15834)
- CVE-2026-39825 openshift-service-mesh/istio-cni-rhel9: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (OSSM-15834)
- CVE-2026-39825 openshift-service-mesh/istio-rhel9-operator: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (OSSM-15834)
- CVE-2026-56859 openshift-service-mesh/istio-proxyv2-rhel9: Go: Denial of Service via XML decoding recursion depth issue (OSSM-15412)
- CVE-2026-56859 openshift-service-mesh/istio-pilot-rhel9: Go: Denial of Service via XML decoding recursion depth issue (OSSM-15412)
- CVE-2026-56859 openshift-service-mesh/istio-cni-rhel9: Go: Denial of Service via XML decoding recursion depth issue (OSSM-15412)
- CVE-2026-56859 openshift-service-mesh/istio-rhel9-operator: Go: Denial of Service via XML decoding recursion depth issue (OSSM-15412)
- CVE-2026-56853 openshift-service-mesh/istio-proxyv2-rhel9: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (OSSM-15427)
- CVE-2026-56853 openshift-service-mesh/istio-pilot-rhel9: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (OSSM-15427)
- CVE-2026-56853 openshift-service-mesh/istio-cni-rhel9: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (OSSM-15427)
- CVE-2026-56853 openshift-service-mesh/istio-rhel9-operator: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (OSSM-15427)
- CVE-2026-56858 openshift-service-mesh/istio-proxyv2-rhel9: Go html/template: Cross-Site Scripting via pathological input (OSSM-15441)
- CVE-2026-56858 openshift-service-mesh/istio-pilot-rhel9: Go html/template: Cross-Site Scripting via pathological input (OSSM-15441)
- CVE-2026-56858 openshift-service-mesh/istio-cni-rhel9: Go html/template: Cross-Site Scripting via pathological input (OSSM-15441)
- CVE-2026-56858 openshift-service-mesh/istio-rhel9-operator: Go html/template: Cross-Site Scripting via pathological input (OSSM-15441)
- CVE-2026-56862 openshift-service-mesh/istio-proxyv2-rhel9: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (OSSM-15451)
- CVE-2026-56862 openshift-service-mesh/istio-pilot-rhel9: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (OSSM-15451)
- CVE-2026-56862 openshift-service-mesh/istio-cni-rhel9: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (OSSM-15451)
- CVE-2026-56862 openshift-service-mesh/istio-rhel9-operator: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (OSSM-15451)
- CVE-2026-33818 openshift-service-mesh/istio-proxyv2-rhel9: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (OSSM-15461)
- CVE-2026-33818 openshift-service-mesh/istio-pilot-rhel9: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (OSSM-15461)
- CVE-2026-33818 openshift-service-mesh/istio-cni-rhel9: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (OSSM-15461)
- CVE-2026-33818 openshift-service-mesh/istio-rhel9-operator: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (OSSM-15461)
- CVE-2026-56860 openshift-service-mesh/istio-proxyv2-rhel9: golang net/url: Denial of Service from quadratic complexity in path resolution (OSSM-15466)
- CVE-2026-56860 openshift-service-mesh/istio-pilot-rhel9: golang net/url: Denial of Service from quadratic complexity in path resolution (OSSM-15466)
- CVE-2026-56860 openshift-service-mesh/istio-cni-rhel9: golang net/url: Denial of Service from quadratic complexity in path resolution (OSSM-15466)
- CVE-2026-56860 openshift-service-mesh/istio-rhel9-operator: golang net/url: Denial of Service from quadratic complexity in path resolution (OSSM-15466)
- CVE-2026-73513 openshift-service-mesh/istio-proxyv2-rhel9: envoy: HTTP/2 trailers without END_STREAM in oghttp2 cause heap use-after-free (OSSM-15642)
- CVE-2026-73552 openshift-service-mesh/istio-proxyv2-rhel9: envoy: RBAC safe_regex fails to match non-UTF-8 HTTP header values (OSSM-15647)
- CVE-2026-73547 openshift-service-mesh/istio-proxyv2-rhel9: envoy: ext_authz crash on CONNECT requests without :path pseudo-header (OSSM-15657)
- CVE-2026-73549 openshift-service-mesh/istio-proxyv2-rhel9: envoy: scoped IPv6 handling crash for HTTP/3 clients in original DST clusters (OSSM-15662)
- CVE-2026-50572 openshift-service-mesh/istio-proxyv2-rhel9: envoy: ext_authz use-after-free after rejecting an HTTP request (OSSM-15667)
- CVE-2026-73546 openshift-service-mesh/istio-proxyv2-rhel9: envoy: stored XSS through dynamically generated stat names in admin interface (OSSM-15672)
- CVE-2026-73551 openshift-service-mesh/istio-proxyv2-rhel9: envoy: path normalization bypass via dot/dot-dot segments with parameters (OSSM-15682)
- CVE-2026-73511 openshift-service-mesh/istio-proxyv2-rhel9: envoy: path matching bypass via per-segment parameters not stripped by router (OSSM-15687)
- CVE-2026-73548 openshift-service-mesh/istio-proxyv2-rhel9: envoy: connection poisoning through generic non-WebSocket HTTP upgrade requests (OSSM-15692)
- CVE-2026-73550 openshift-service-mesh/istio-proxyv2-rhel9: envoy: HTTP/2 memory exhaustion via discarded Host headers not counted in limits (OSSM-15697)
- CVE-2026-73553 openshift-service-mesh/istio-proxyv2-rhel9: envoy: RBAC authorization bypass when path-parameter stripping is enabled (OSSM-15702)
Fixes/Improvements:
- OpenSSL is using glibc allocator instead of tcmalloc (OSSM-15244)
- Treat CRYPTO_set_mem_functions() failure as non-fatal (OSSM-15621)
Solution
See Red Hat OpenShift Service Mesh 3.0.15 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.0
Affected Products
- Red Hat OpenShift Service Mesh
Fixes
- OSSM-15244 - OpenSSL is using glibc allocator instead of tcmalloc
- OSSM-15621 - Treat CRYPTO_set_mem_functions() failure as non-fatal
CVEs
amd64
| registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:a539d099456345ff3d70c00305931a5e79066a84f9cf76c187d748a908848cae |
| registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:06c59127232704d22fc20bde68bef9ae8ae155ec1d90dd153a6f217f0ae77a88 |
| registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:abd08e5193631af6fce57869a8bf19bc46f501146fe1260e6cb616811783f1a5 |
| registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:4f3ddd104108a77c679f5c0097d9cd18cdc56b4b4ad3727334fe60cd2f054fae |
| registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:8ac0f5ce78617bab61539255e97f182f2a1b1d8491adcae9d27d1757f02c3849 |
| registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:33fec0cbbd8c276d1db10f7461adf93f4cafbf6703c184532180dea8e76c4e77 |
| registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:25e62cf6f61f23426447448409f44f70272d348787180983cd8fac84a1c2842b |
arm64
| registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:0bcd21ad4d0dd9233972d0343a846343a7830fff981e77092ce0efd4c7dce056 |
| registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:054c247a7d49d9d973d6f72fc4cfe1c7742f2243d87b4b518b7b04789a4a24d9 |
| registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:8d6ea9cb2913c606aceac872e41b40b2d2435eba77361995b95403721c03c633 |
| registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:6fc69b6b7c9929c3acf00d8ab06a4c1f4f916a8eba1ee22adac376ba3fcf5635 |
| registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:13c0b9cb79e8475fdc40865ba1b68997afdc03bc2ed0bc1e0ed67f581f63fb68 |
| registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:64ea3accffb5aae6bba702135c7515e6cba4139a11e7c50d922466bf00702b07 |
ppc64le
| registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:1db604f1ae63096819cf93f270091d7d23308d152862d1c3121db6b9ed5e155a |
| registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:7a14702627ed430ec8fd688eaaace7648fc08e2e8277b8ae4a18a9fff94bb5c2 |
| registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:25e3039cd79737181a25ee29af17717e2faef25bde8f8bb02ae7efa808362746 |
| registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:2f20ef03d500268455dda62e017d1aaddcf1ab5bce3e08163afae51e3d9c236b |
| registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:d4344eb4b4c6ce9ac5219dbb2d556a3c54f82bc39358158ba8ca5d395e92457a |
| registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:d25e53e05618055b4817703c27611f7eb36a5862efa21f88b1324414afed06ef |
s390x
| registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:114c2d8f805e20e2e1a49f4291b60c513e378f5360ca17d8303e58b2ef1ed9b4 |
| registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:0191fd74aab21fb7482f2bfdb57b08884910cd00c968f5f03df260bb3e137c6b |
| registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:7f1de9aea1dff65a8b1b3c5f8574a2fc6cce7d8ee1425118a34289d7ec109367 |
| registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:c839fa764645c52fd3f40989d231706ef05f63ade536ccb312c4e9718a934c40 |
| registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:0b21488cd868210ed7e8cba745414e4daf40483e8cebe6058a34cbda83b11cfd |
| registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:ca3b0ad3adc6cb42dbb3c8e80b55649ef09a6f5b70c6d186cf00360d84dff99c |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.