VDB
RHSA-2026%3A16535
RHSA-2026%3A16535
PUBLISHED
CVSS 7.199999809265137 HIGH
A flaw was found in the Go standard library packages `crypto/x509` and `crypto/tls`. During the process of building a certificate chain, an attacker can provide a large number of intermediate certificates. This excessive input is not properly limited, leading to an uncontrolled amount of work being performed. This can result in a denial of service (DoS) condition, making the affected system or application unavailable to legitimate users.
Risk Scores
CVSS 3.1
7.199999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | OpenShift Service Mesh 3.2 | |
| Red Hat | registry.redhat.io/openshift-service-mesh/kiali-rhel9 | |
| Red Hat | registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:670dbb0cdefd1e46fc6919d4b232f88b3e39599b6ea90602476fd84308986bca_arm64 as a component of Red Hat OpenShift Service Mesh 3.2 | *, *, * |
| Red Hat | OpenShift Service Mesh | |
| golang | Go | |
| Red Hat | registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:36a99220c56b2552bbc8c8c6026047b9d1f5dd271ee10c07365faefc06486382_arm64 as a component of Red Hat OpenShift Service Mesh 3.2 | |
| Red Hat | registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:cc913771d88f564060b1562034a5b6dd62842e899f852364d90f4ae4e6c85fd2_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2 | *, *, * |
| Red Hat | registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:361c90a4629005ec10140af3b719c739de36cf15adb6fb03bffb62eaff9a9a89_ppc64le | |
| Red Hat | registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:0b03493fd9127e224c88e3cc775fdb8e4d6851c07b0cda8220af37f3ea58b817_amd64 as a component of Red Hat OpenShift Service Mesh 3.2 | registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:0b03493fd9127e224c88e3cc775fdb8e4d6851c07b0cda8220af37f3ea58b817_amd64, *, * |
| Red Hat | registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:36a99220c56b2552bbc8c8c6026047b9d1f5dd271ee10c07365faefc06486382_arm64 as a component of Red Hat OpenShift Service Mesh 3.2 | *, *, * |
| Red Hat | registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:cc913771d88f564060b1562034a5b6dd62842e899f852364d90f4ae4e6c85fd2_ppc64le | |
| Red Hat | registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:361c90a4629005ec10140af3b719c739de36cf15adb6fb03bffb62eaff9a9a89_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2 | *, *, * |
| Red Hat | registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:b4ba774d9dfa6e96c320cb2da532882a2525567fac9367fd625b26edbc59dfc0_s390x as a component of Red Hat OpenShift Service Mesh 3.2 | *, *, * |
| Red Hat | registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:af21dad17afca9999408d97167c950d3b37ccd14e199e8e69c7f1b80a95d536c_amd64 as a component of Red Hat OpenShift Service Mesh 3.2 | registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:af21dad17afca9999408d97167c950d3b37ccd14e199e8e69c7f1b80a95d536c_amd64, *, * |
| Red Hat | registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:f8862c4fa112301aa30870c2f6a891acb0e0c55e9da8d5f5dd5e057df72249ee_s390x as a component of Red Hat OpenShift Service Mesh 3.2 | *, *, * |
Timeline
- May 12, 2026 CVE Published
- Aug 23, 2026 CVE Updated
- Aug 23, 2026 Distribution Patch
- Aug 23, 2026 Distribution Patch
- Aug 23, 2026 Security Advisory
- Aug 23, 2026 Security Advisory
- Aug 23, 2026 Security Advisory
- Aug 23, 2026 Security Advisory
- Aug 23, 2026 Security Advisory
- Aug 23, 2026 Security Advisory
- Aug 23, 2026 Security Advisory
- Aug 23, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2026:16535 advisory
- https://access.redhat.com/security/cve/CVE-2025-62718 advisory
- https://access.redhat.com/security/cve/CVE-2026-25679 advisory
- https://access.redhat.com/security/cve/CVE-2026-29063 advisory
- https://access.redhat.com/security/cve/CVE-2026-29074 advisory
- https://access.redhat.com/security/cve/CVE-2026-32280 advisory
- https://access.redhat.com/security/cve/CVE-2026-33186 advisory
- https://access.redhat.com/security/cve/CVE-2026-34986 advisory
- https://access.redhat.com/security/cve/CVE-2026-40175 advisory
- https://access.redhat.com/security/cve/CVE-2026-40895 advisory
- https://access.redhat.com/security/cve/CVE-2026-42033 advisory
- https://access.redhat.com/security/cve/CVE-2026-42035 advisory
- https://access.redhat.com/security/cve/CVE-2026-42039 advisory
- https://access.redhat.com/security/cve/CVE-2026-42041 advisory
- https://access.redhat.com/security/cve/CVE-2026-42043 advisory
- https://access.redhat.com/security/cve/CVE-2026-42044 advisory
- https://access.redhat.com/security/cve/CVE-2026-4800 advisory
- https://access.redhat.com/security/updates/classification advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_16535.json advisory
…and 35 more