RHSA-2026:26072: Kiali 1.73.32 for Red Hat OpenShift Service Mesh 2.6
Kiali 1.73.32, for Red Hat OpenShift Service Mesh 2.6, provides observability for the service mesh by offering a visual representation of the mesh topology and metrics, helping users monitor, trace, and manage efficiently.Security Fix(es): CVE-2026-9277 openshift-service-mesh/kiali-rhel8: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators (OSSM-13906) CVE-2026-9277 openshift-service-mesh/kiali-ossmc-rhel8: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators (OSSM-13905) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
openshift-service-mesh/kiali-rhel8to a version that resolves this vulnerability.Fixed in 1.73.32Patch OSSM-13906 - Upgrade
Upgrade
openshift-service-mesh/kiali-ossmc-rhel8to a version that resolves this vulnerability.Fixed in 1.73.32Patch OSSM-13905
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:26072?
The severity of RHSA-2026:26072 is rated as 73.
What kind of vulnerability is associated with RHSA-2026:26072?
RHSA-2026:26072 is associated with a command injection vulnerability (CVE-2026-9277).
How do I fix RHSA-2026:26072?
To fix RHSA-2026:26072, update to the latest version of Kiali for Red Hat OpenShift Service Mesh.
What products are affected by RHSA-2026:26072?
The products affected by RHSA-2026:26072 include Kiali 1.73.32 and Red Hat OpenShift Service Mesh 2.6.
When was RHSA-2026:26072 published?
RHSA-2026:26072 was published on June 15, 2026.