Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:65115 - Security Advisory
Issued:
2026-09-08
Updated:
2026-09-08

RHSA-2026:65115 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Red Hat OpenShift Service Mesh 3.3.7

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Service Mesh 3.3.7

This update has a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Service Mesh 3.3.7, which is based on the open source Istio project, addresses a variety of problems in a microservice architecture by creating a centralized point of control in an application.

Security Fix(es):

  • CVE-2026-39825 openshift-service-mesh/istio-proxyv2-rhel9: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (OSSM-15833)
  • CVE-2026-39825 openshift-service-mesh/istio-pilot-rhel9: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (OSSM-15833)
  • CVE-2026-39825 openshift-service-mesh/istio-cni-rhel9: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (OSSM-15833)
  • CVE-2026-39825 openshift-service-mesh/istio-rhel9-operator: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (OSSM-15833)
  • CVE-2026-56859 openshift-service-mesh/istio-proxyv2-rhel9: Go: Denial of Service via XML decoding recursion depth issue (OSSM-15413)
  • CVE-2026-56859 openshift-service-mesh/istio-pilot-rhel9: Go: Denial of Service via XML decoding recursion depth issue (OSSM-15413)
  • CVE-2026-56859 openshift-service-mesh/istio-cni-rhel9: Go: Denial of Service via XML decoding recursion depth issue (OSSM-15413)
  • CVE-2026-56859 openshift-service-mesh/istio-rhel9-operator: Go: Denial of Service via XML decoding recursion depth issue (OSSM-15413)
  • CVE-2026-56853 openshift-service-mesh/istio-proxyv2-rhel9: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (OSSM-15425)
  • CVE-2026-56853 openshift-service-mesh/istio-pilot-rhel9: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (OSSM-15425)
  • CVE-2026-56853 openshift-service-mesh/istio-cni-rhel9: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (OSSM-15425)
  • CVE-2026-56853 openshift-service-mesh/istio-rhel9-operator: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (OSSM-15425)
  • CVE-2026-56858 openshift-service-mesh/istio-proxyv2-rhel9: Go html/template: Cross-Site Scripting via pathological input (OSSM-15439)
  • CVE-2026-56858 openshift-service-mesh/istio-pilot-rhel9: Go html/template: Cross-Site Scripting via pathological input (OSSM-15439)
  • CVE-2026-56858 openshift-service-mesh/istio-cni-rhel9: Go html/template: Cross-Site Scripting via pathological input (OSSM-15439)
  • CVE-2026-56858 openshift-service-mesh/istio-rhel9-operator: Go html/template: Cross-Site Scripting via pathological input (OSSM-15439)
  • CVE-2026-56862 openshift-service-mesh/istio-proxyv2-rhel9: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (OSSM-15449)
  • CVE-2026-56862 openshift-service-mesh/istio-pilot-rhel9: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (OSSM-15449)
  • CVE-2026-56862 openshift-service-mesh/istio-cni-rhel9: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (OSSM-15449)
  • CVE-2026-56862 openshift-service-mesh/istio-rhel9-operator: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (OSSM-15449)
  • CVE-2026-33818 openshift-service-mesh/istio-proxyv2-rhel9: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (OSSM-15459)
  • CVE-2026-33818 openshift-service-mesh/istio-pilot-rhel9: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (OSSM-15459)
  • CVE-2026-33818 openshift-service-mesh/istio-cni-rhel9: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (OSSM-15459)
  • CVE-2026-33818 openshift-service-mesh/istio-rhel9-operator: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (OSSM-15459)
  • CVE-2026-56860 openshift-service-mesh/istio-proxyv2-rhel9: golang net/url: Denial of Service from quadratic complexity in path resolution (OSSM-15464)
  • CVE-2026-56860 openshift-service-mesh/istio-pilot-rhel9: golang net/url: Denial of Service from quadratic complexity in path resolution (OSSM-15464)
  • CVE-2026-56860 openshift-service-mesh/istio-cni-rhel9: golang net/url: Denial of Service from quadratic complexity in path resolution (OSSM-15464)
  • CVE-2026-56860 openshift-service-mesh/istio-rhel9-operator: golang net/url: Denial of Service from quadratic complexity in path resolution (OSSM-15464)
  • CVE-2026-73513 openshift-service-mesh/istio-proxyv2-rhel9: envoy: HTTP/2 trailers without END_STREAM in oghttp2 cause heap use-after-free (OSSM-15645)
  • CVE-2026-73552 openshift-service-mesh/istio-proxyv2-rhel9: envoy: RBAC safe_regex fails to match non-UTF-8 HTTP header values (OSSM-15650)
  • CVE-2026-73547 openshift-service-mesh/istio-proxyv2-rhel9: envoy: ext_authz crash on CONNECT requests without :path pseudo-header (OSSM-15660)
  • CVE-2026-73549 openshift-service-mesh/istio-proxyv2-rhel9: envoy: scoped IPv6 handling crash for HTTP/3 clients in original DST clusters (OSSM-15665)
  • CVE-2026-50572 openshift-service-mesh/istio-proxyv2-rhel9: envoy: ext_authz use-after-free after rejecting an HTTP request (OSSM-15670)
  • CVE-2026-73546 openshift-service-mesh/istio-proxyv2-rhel9: envoy: stored XSS through dynamically generated stat names in admin interface (OSSM-15675)
  • CVE-2026-73551 openshift-service-mesh/istio-proxyv2-rhel9: envoy: path normalization bypass via dot/dot-dot segments with parameters (OSSM-15685)
  • CVE-2026-73511 openshift-service-mesh/istio-proxyv2-rhel9: envoy: path matching bypass via per-segment parameters not stripped by router (OSSM-15690)
  • CVE-2026-73548 openshift-service-mesh/istio-proxyv2-rhel9: envoy: connection poisoning through generic non-WebSocket HTTP upgrade requests (OSSM-15695)
  • CVE-2026-73550 openshift-service-mesh/istio-proxyv2-rhel9: envoy: HTTP/2 memory exhaustion via discarded Host headers not counted in limits (OSSM-15700)
  • CVE-2026-73553 openshift-service-mesh/istio-proxyv2-rhel9: envoy: RBAC authorization bypass when path-parameter stripping is enabled (OSSM-15705)
  • GHSA-qm8v-g4f9-qhjx openshift-service-mesh/istio-pilot-rhel9: BackendTLSPolicy fails open to plaintext on sidecars when its CA reference is unresolved

Fixes/Improvements:

  • Leaking X509 object in SSL_get0_peer_certificates() (OSSM-15075)
  • OpenSSL is using glibc allocator instead of tcmalloc (OSSM-15244)
  • Sail Operator ClusterRoles (istiod/istio-reader) missing aggregate-to-admin/edit labels — GitOps/namespace-admin users can't manage Istio CRs (e.g. Telemetry) (OSSM-15257)
  • Treat CRYPTO_set_mem_functions() failure as non-fatal (OSSM-15621)

Solution

See Red Hat OpenShift Service Mesh 3.3.7 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.3

Affected Products

  • Red Hat OpenShift Service Mesh

Fixes

  • OSSM-15075 - Leaking X509 object in SSL_get0_peer_certificates()
  • OSSM-15244 - OpenSSL is using glibc allocator instead of tcmalloc
  • OSSM-15257 - Sail Operator ClusterRoles (istiod/istio-reader) missing aggregate-to-admin/edit labels — GitOps/namespace-admin users can't manage Istio CRs (e.g. Telemetry)
  • OSSM-15621 - Treat CRYPTO_set_mem_functions() failure as non-fatal

CVEs

  • CVE-2026-33818
  • CVE-2026-39825
  • CVE-2026-50572
  • CVE-2026-56853
  • CVE-2026-56858
  • CVE-2026-56859
  • CVE-2026-56860
  • CVE-2026-56862
  • CVE-2026-73511
  • CVE-2026-73513
  • CVE-2026-73546
  • CVE-2026-73547
  • CVE-2026-73548
  • CVE-2026-73549
  • CVE-2026-73550
  • CVE-2026-73551
  • CVE-2026-73552
  • CVE-2026-73553

References

  • https://access.redhat.com/security/updates/classification/

amd64

registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:40ee95b790be644721ed77d2179ebf0cf539bce06a6f89d1f815be796f6c5133
registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:a464c1950dbb8fd6671cd7c9a931da21d53ee2b4f0da2080811f480747d9c165
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:e89b769b9346ef32020497a817d7a6ee2f11d9c9e19a01e45bf59ee5bc39b74e
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:769d18355f8955e68b6f91f282c63074b7253dfdc7a8937c4854318143df4fac
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:78b8134d45567565eb0eb365042b3c43414fed25e8d1b4b40d3029e864d9f72b
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:5dd85b7b1238aef2ba8da10843bf368234b90e5b7df1b5d8025c4ba40464f14f
registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:bf50a2807786e8be677017637355ce0db54d8aa60eb096543bfa4f787c4a4e1a

arm64

registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:e3a308f371571e57ce3e1d06a9b82c8a5e6ea7a6a011ee9ab13c2a5a593ca2f3
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:c91a30de947e1e8940733903af6bf278fdab15c4d46d7059fa7fe9b1c4f847fc
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:2a900ea36f46630f379d62ba6844b20f261f2ac259d663ccadc3cc4594b49653
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:5adbe715c519ac65ef4f930b3ada2326e534684bedc495fd66edc861e113e6eb
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:2231054be7e3cf53578c362ec677e2fecabf96e8516696b4e79710d5b6f875ac
registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:facaa199b4e2d33ddeef587b67227580e09a1725546608bc7e01b64d319995c4

ppc64le

registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:06d2290678383535a72adf45124b4ff4cd112e7488af5ff2b7ade0274e61958e
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:7ab3ebf0fdc1f2cd4eb1811d5f0d3d72551feb6b32bdc8129477d7f3bcd44dea
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:74e7228e6a477391e0223a3946d94483309e57eb4d4696b03ffa7342a9e3d2f4
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:6b3c9e21a907eec910e44f397781e4992e290ec4370428d8a85d829245667ef2
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:783b72559574075f713eaceea3bc428d7ec3274a2f9a475d7033d4b92f4575ba
registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:adc34cb413d31fa5d8a4bd6c560588079c3c271ad9de961da5aced5f6954ec70

s390x

registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:79ab7b6bcfcd078bc1d4b432b66c4556b9713d0185d1451c290e5fec0fc19147
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:7734ec145a1e150f724011f6ecdac20aedd59526add43e54826caf34671e439b
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:4d2c5e711320b986bddfa52c72d292430fee0196a88fdc4af0f10a9cdcb03970
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:16eed6d7deb07c19d61d95047c7add6470c09294235a230c5dbd18984858986c
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:c0b7d9fea706615ba973eb44c7c44eec4859d5037696e1b1c880fa4022f430d3
registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:6ae671c569cd553f9f48c8c3bf8d00a16db97178d0748f44ef3b6fb74c750038

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility