Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:65112 - Security Advisory
Issued:
2026-09-08
Updated:
2026-09-08

RHSA-2026:65112 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Red Hat OpenShift Service Mesh 3.1.12

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Service Mesh 3.1.12

This update has a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Service Mesh 3.1.12, which is based on the open source Istio project, addresses a variety of problems in a microservice architecture by creating a centralized point of control in an application.

Security Fix(es):

  • CVE-2026-39825 openshift-service-mesh/istio-proxyv2-rhel9: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (OSSM-15831)
  • CVE-2026-39825 openshift-service-mesh/istio-pilot-rhel9: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (OSSM-15831)
  • CVE-2026-39825 openshift-service-mesh/istio-cni-rhel9: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (OSSM-15831)
  • CVE-2026-39825 openshift-service-mesh/istio-rhel9-operator: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (OSSM-15831)
  • CVE-2026-56859 openshift-service-mesh/istio-proxyv2-rhel9: Go: Denial of Service via XML decoding recursion depth issue (OSSM-15410)
  • CVE-2026-56859 openshift-service-mesh/istio-pilot-rhel9: Go: Denial of Service via XML decoding recursion depth issue (OSSM-15410)
  • CVE-2026-56859 openshift-service-mesh/istio-cni-rhel9: Go: Denial of Service via XML decoding recursion depth issue (OSSM-15410)
  • CVE-2026-56859 openshift-service-mesh/istio-rhel9-operator: Go: Denial of Service via XML decoding recursion depth issue (OSSM-15410)
  • CVE-2026-56853 openshift-service-mesh/istio-proxyv2-rhel9: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (OSSM-15426)
  • CVE-2026-56853 openshift-service-mesh/istio-pilot-rhel9: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (OSSM-15426)
  • CVE-2026-56853 openshift-service-mesh/istio-cni-rhel9: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (OSSM-15426)
  • CVE-2026-56853 openshift-service-mesh/istio-rhel9-operator: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (OSSM-15426)
  • CVE-2026-56858 openshift-service-mesh/istio-proxyv2-rhel9: Go html/template: Cross-Site Scripting via pathological input (OSSM-15440)
  • CVE-2026-56858 openshift-service-mesh/istio-pilot-rhel9: Go html/template: Cross-Site Scripting via pathological input (OSSM-15440)
  • CVE-2026-56858 openshift-service-mesh/istio-cni-rhel9: Go html/template: Cross-Site Scripting via pathological input (OSSM-15440)
  • CVE-2026-56858 openshift-service-mesh/istio-rhel9-operator: Go html/template: Cross-Site Scripting via pathological input (OSSM-15440)
  • CVE-2026-56862 openshift-service-mesh/istio-proxyv2-rhel9: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (OSSM-15450)
  • CVE-2026-56862 openshift-service-mesh/istio-pilot-rhel9: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (OSSM-15450)
  • CVE-2026-56862 openshift-service-mesh/istio-cni-rhel9: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (OSSM-15450)
  • CVE-2026-56862 openshift-service-mesh/istio-rhel9-operator: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (OSSM-15450)
  • CVE-2026-33818 openshift-service-mesh/istio-proxyv2-rhel9: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (OSSM-15460)
  • CVE-2026-33818 openshift-service-mesh/istio-pilot-rhel9: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (OSSM-15460)
  • CVE-2026-33818 openshift-service-mesh/istio-cni-rhel9: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (OSSM-15460)
  • CVE-2026-33818 openshift-service-mesh/istio-rhel9-operator: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (OSSM-15460)
  • CVE-2026-56860 openshift-service-mesh/istio-proxyv2-rhel9: golang net/url: Denial of Service from quadratic complexity in path resolution (OSSM-15465)
  • CVE-2026-56860 openshift-service-mesh/istio-pilot-rhel9: golang net/url: Denial of Service from quadratic complexity in path resolution (OSSM-15465)
  • CVE-2026-56860 openshift-service-mesh/istio-cni-rhel9: golang net/url: Denial of Service from quadratic complexity in path resolution (OSSM-15465)
  • CVE-2026-56860 openshift-service-mesh/istio-rhel9-operator: golang net/url: Denial of Service from quadratic complexity in path resolution (OSSM-15465)
  • CVE-2026-73513 openshift-service-mesh/istio-proxyv2-rhel9: envoy: HTTP/2 trailers without END_STREAM in oghttp2 cause heap use-after-free (OSSM-15643)
  • CVE-2026-73552 openshift-service-mesh/istio-proxyv2-rhel9: envoy: RBAC safe_regex fails to match non-UTF-8 HTTP header values (OSSM-15648)
  • CVE-2026-73547 openshift-service-mesh/istio-proxyv2-rhel9: envoy: ext_authz crash on CONNECT requests without :path pseudo-header (OSSM-15658)
  • CVE-2026-73549 openshift-service-mesh/istio-proxyv2-rhel9: envoy: scoped IPv6 handling crash for HTTP/3 clients in original DST clusters (OSSM-15663)
  • CVE-2026-50572 openshift-service-mesh/istio-proxyv2-rhel9: envoy: ext_authz use-after-free after rejecting an HTTP request (OSSM-15668)
  • CVE-2026-73546 openshift-service-mesh/istio-proxyv2-rhel9: envoy: stored XSS through dynamically generated stat names in admin interface (OSSM-15673)
  • CVE-2026-73551 openshift-service-mesh/istio-proxyv2-rhel9: envoy: path normalization bypass via dot/dot-dot segments with parameters (OSSM-15683)
  • CVE-2026-73511 openshift-service-mesh/istio-proxyv2-rhel9: envoy: path matching bypass via per-segment parameters not stripped by router (OSSM-15688)
  • CVE-2026-73548 openshift-service-mesh/istio-proxyv2-rhel9: envoy: connection poisoning through generic non-WebSocket HTTP upgrade requests (OSSM-15693)
  • CVE-2026-73550 openshift-service-mesh/istio-proxyv2-rhel9: envoy: HTTP/2 memory exhaustion via discarded Host headers not counted in limits (OSSM-15698)
  • CVE-2026-73553 openshift-service-mesh/istio-proxyv2-rhel9: envoy: RBAC authorization bypass when path-parameter stripping is enabled (OSSM-15703)

Fixes/Improvements:

  • Leaking X509 object in SSL_get0_peer_certificates() (OSSM-15075)
  • OpenSSL is using glibc allocator instead of tcmalloc (OSSM-15244)
  • Treat CRYPTO_set_mem_functions() failure as non-fatal (OSSM-15621)

Solution

See Red Hat OpenShift Service Mesh 3.1.12 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.1

Affected Products

  • Red Hat OpenShift Service Mesh

Fixes

  • OSSM-15075 - Leaking X509 object in SSL_get0_peer_certificates()
  • OSSM-15244 - OpenSSL is using glibc allocator instead of tcmalloc
  • OSSM-15621 - Treat CRYPTO_set_mem_functions() failure as non-fatal

CVEs

  • CVE-2026-33818
  • CVE-2026-39825
  • CVE-2026-50572
  • CVE-2026-56853
  • CVE-2026-56858
  • CVE-2026-56859
  • CVE-2026-56860
  • CVE-2026-56862
  • CVE-2026-73511
  • CVE-2026-73513
  • CVE-2026-73546
  • CVE-2026-73547
  • CVE-2026-73548
  • CVE-2026-73549
  • CVE-2026-73550
  • CVE-2026-73551
  • CVE-2026-73552
  • CVE-2026-73553

References

  • https://access.redhat.com/security/updates/classification/

amd64

registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:1fc184f8a69ecfac1d9567f273dd1d37268fd7c9c8978782ae91fe5ce9d72904
registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:675c59668d6b8813125d25a1fda99536c841b4e8ba050d9bd1209fea886e59ac
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:495a5267e462a1a7f41dbc8d21fa712d874624b2dacbaafd039ea23db35b4f26
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:43fedbb46995785fa9a85914f3fe56dab9f73f87f436477eb02490c21f5b4034
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:6aaf6ae8457377dcb522c882d41ce528e97cb9dbc657ec006782bc0afaa0bb10
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:7cf632f4760c7a97847ca2cc8fc7bbe9d5285ff2ca3ea23bd49c834542d98d68
registry.redhat.io/openshift-service-mesh-tech-preview/istio-ztunnel-rhel9@sha256:0ddd440ad576a9386df1c297f40cbe441abe1c2bdc7e135b4e380f3391dd42d1

arm64

registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:5fd2d9c600ae46b86402bc06496006cb13642e2a9661d90c8ab23cea9fed15ba
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:eda102599f89ca316c194b296e90d0924043e6e7cc3df11f66bac84e26708a3d
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:636782d2a4dc01982b448268751ebf752cd3b7aa789ad9bbc16d091111f3f71a
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:4271a3a1815a544168990b0c49e5b297e302c8f2ebab42a4e1347ac944d8cfe5
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:005a5f7c0d8dfba971609b6cffe7ff4d20ea1271ed4b7b5a99161f46d9c0f779
registry.redhat.io/openshift-service-mesh-tech-preview/istio-ztunnel-rhel9@sha256:083d716a65d38c594834ef23c1f58d82db2dadb53839b0592634642f07056898

ppc64le

registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:3310ef15ec51db6d42424b59003810ef82433bb4f216bf62c5ac06198bdf8ab8
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:12a379e721bd69f730550f7f2b68a2515e5da29ec3d309d2268acf245a89f81c
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:505d5d1b2c6415b390ee39ee7242c6671befddc8cddbf8345904ae95c0599256
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:dd1ff3d2e08595ea5ee1c077e5b049c54c0115ef02e3b5ae00203727ef4ad496
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:ce2ff7eed3f4692e611ada5b5a7a7e927b400618a75c38d8bfa2baecb1a9d34e
registry.redhat.io/openshift-service-mesh-tech-preview/istio-ztunnel-rhel9@sha256:b82183a582c81d027eb2dff9edde6d251f27ce73338b93dff3cb9c0d0121cbd1

s390x

registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:f27e53966a538e5c9be9136fda6ee939b1e1ae178f50aff7225805642cf272f6
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:fa6d9be050907e80d859e8ede390156bb7db72c3ffeb5b046172addb96ef9b52
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:b3f3ac266130fc78dbeebec1b1d31473a98d826a9b45911620952a83de313286
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:a6f3b2871050d1d49a5a1e7acbc391d0b3d05f80be8275501bfa9a7ba277993e
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:24f10dd378af1f1cb935734efd57064881899d1d7f37333f6e7cc275b1e3a5de
registry.redhat.io/openshift-service-mesh-tech-preview/istio-ztunnel-rhel9@sha256:eaa07bac206415d869c11c6b0ae35b9e69c3c5096194da011c4e59afce88576c

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility