RHSA-2026:65113HighCVSS 8.1

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.2.9

Published
September 8, 2026
Last Modified
September 17, 2026

🔗 CVE IDs covered (18)

CVE-2026-33818CVE-2026-56853CVE-2026-56858CVE-2026-73548 · pendingCVE-2026-73550 · pendingCVE-2026-50572 · pendingCVE-2026-56859CVE-2026-56860CVE-2026-73511 · pendingCVE-2026-73553 · pendingCVE-2026-73546 · pendingCVE-2026-73547 · pendingCVE-2026-39825CVE-2026-56862CVE-2026-73513 · pendingCVE-2026-73549 · pendingCVE-2026-73551 · pendingCVE-2026-73552 · pending

📋 Description

CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-39825 — net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls CVE-2026-50572 — envoy: envoy: ext_authz use-after-free after rejecting an HTTP request CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-73511 — envoy: envoy: path matching bypass via per-segment parameters not stripped by router CVE-2026-73513 — envoy: envoy: HTTP/2 trailers without END_STREAM in oghttp2 cause heap use-after-free CVE-2026-73546 — envoy: envoy: stored XSS through dynamically generated stat names in admin interface CVE-2026-73547 — envoy: envoy: ext_authz crash on CONNECT requests without :path pseudo-header CVE-2026-73548 — envoy: envoy: connection poisoning through generic non-WebSocket HTTP upgrade requests CVE-2026-73549 — envoy: envoy: scoped IPv6 handling crash for HTTP/3 clients in original DST clusters CVE-2026-73550 — envoy: envoy: HTTP/2 memory exhaustion via discarded Host headers not counted in limits CVE-2026-73551 — envoy: envoy: path normalization bypass via dot/dot-dot segments with parameters CVE-2026-73552 — envoy: envoy: RBAC safe_regex fails to match non-UTF-8 HTTP header values CVE-2026-73553 — envoy: envoy: RBAC authorization bypass when path-parameter stripping is enabled

🎯 Affected products26

  • Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:29d18180796eb2d6e4cd9d95cbce16d38317502ee24ff026e11d51ef3c1eafdf_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:46c81f793491323d5defb95c4e4ad93dddc04d82e889e64cce2acdc20f92699e_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:4ffc6146684bda6af767cad621522bcb176ce7602adcaedade9382b788265715_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:5385395ae91fd1d122e0665f7fddb6e03f91e9a35df2b0b8f9e95555d015c993_s390x as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:18ad591010dcde8eae8e93dc08980ef6484f75dda14bb8255b9d29328d3dd317_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:294e6a6d1e18b985985d77f4e21014f1f45429b8a0ab77680d7016d96ac602cf_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:6c5491aa0334785af7852b75bd60ed6f46683e88d55fa4f24ea70e0a71b705b9_s390x as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:8d87aa918619a10cc93b8d39d2106d6739e74222b550c97795558bb737d7faa6_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:4eb4e69f6f8705b7cde6865c407166a0e1b205bf6644a1b3fe797450f852b192_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:6c6d020a455ff73efc6933b72c9e4d1d305adc11e583bf2654f602e4b786fdfb_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:6cef1ef0092d6ce904d22b40330325df4575bc9ab994c5c6ad35ea9883bc6bc9_s390x as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:a06bd02dd201db526588e7079370b28e9de45dca8ecaa9a52a78620c7e702303_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:55a523deb053cfbce9281d3e52e52114fd925eab40905b8a7597871eb0904415_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:57f73171450c78cb3ca21608209c1eb668159e58b0b39887f896f3ca1e58d64c_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:5bf9f6dafcc666a4a3a232ce892e1d51fc07d2bc8110538457577318f0364788_s390x as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:d4e96e5d7cd3baaa9dbc6304a7e199c33fe212389b55f1307f5a446efb9ae15f_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:23113a477c65b8b9d7dfd5e80d6c256b2020644e842eb87353c81f9173fa52a1_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:8859e4b8a895b5cb83972cb1c9d2820534453df2035cbe8a4fc722ff50321559_s390x as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:8e8afd57c00f07be5de52d556e08b26a9c800119fa6f4ce30c9c8f64315ba60d_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:cbb85cb9a6031afa1fee8d8fb17a752380194f49db1359fa9685c793520aae12_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:af4e8993fcbb78a0f818f81bc8ef2b3bac2a1cc7df515ac9f71016c107dbc583_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:719a4397dc46d265ed1e31d2dd04c270ae3353c68550f0ef60d84cd5fa867d89_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:95ddc2d9bb0f3e45f3ec067e5e75e7ebf9b2a59a52960f2037180c465c3d68c3_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:ad46505b375e413060423be59ab7652c437f7c31812915f1b630f2e1ab9aa54e_s390x as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:ad5a1a998ccfb3b04a8d53b2f522d6156087ac1c00d454a67ceacf4d0e28178c_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2

✅ Remediation

See Red Hat OpenShift Service Mesh 3.2.9 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.2 Workaround: Increase the maximum number of query parameters allowed by setting the GODEBUG environment variable `urlmaxqueryparams` to a higher value (e.g., `GODEBUG=urlmaxqueryparams=20000`), or validate and enforce security controls on query parameters at the backend service rather than relying solely on the ReverseProxy's Rewrite or Director function for security filtering. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (21)