A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header sanitization in Envoy.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:HRed Hat Openshift Service Mesh
APPRedhat2.5.62.6.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2021-3586CRITICAL9.8PL ✓same product
Błędna konfiguracja NetworkPolicy w servicemesh-operator (Maistra)
CVE-2020-27846CRITICAL9.8PL ✓same product
Pominięcie uwierzytelniania SAML przez błąd weryfikacji podpisu
CVE-2026-47774HIGH7.5same product
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35....
CVE-2026-44495HIGH7.0same product
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axi...
CVE-2021-3495HIGH8.8same product
An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. ...