Skip to main content
EPSS 1.1%top 36%

Red Hat Security Advisory: Custom Metrics Autoscaler Operator for Red Hat OpenShift 2.15.1-4 Update

0
High
Published: 04/01/2025 (04/01/2025, 20:50:35 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The Custom Metrics Autoscaler Operator for Red Hat OpenShift is an optional operator, based on the Kubernetes Event Driven Autoscaler (KEDA), which allows workloads to be scaled using additional metrics sources other than pod metrics. This release is based upon KEDA 2.15.1

Affected software

Affected versions
>=2.15 <2.15.1-4Red HatCustom Metric Autoscaler operator for Red Hat OpenshiftCustom Metric Autoscaler operator for Red Hat Openshift 2.15amd64registry.redhat.io/custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator@sha256:f29faa109ea2a8c418e5a3c6cb2069805037232872122db46e7c0a2033e9ec9e_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 22:11:08 UTC

Technical Analysis

The Custom Metrics Autoscaler Operator for Red Hat OpenShift, based on Kubernetes Event Driven Autoscaler (KEDA) 2.15.1, contains a vulnerability identified as CVE-2024-34156. This flaw arises from the use of strings.Split(token, ".") in the golang.org/x/oauth2/jws package during JWT token parsing, which can cause excessive memory consumption when processing tokens with many '.' characters. An attacker can exploit this by sending numerous malformed tokens, leading to memory exhaustion and denial of service. Red Hat has issued an update to version 2.15.1-4 of the operator that includes fixes for this and related vulnerabilities (CVE-2025-22868, CVE-2025-27144). The advisory references the Red Hat Security Advisory RHSA-2025:3501 and recommends applying the update after prior errata are installed.

Potential Impact

The vulnerability can cause denial of service due to memory exhaustion when the operator processes maliciously crafted tokens containing excessive '.' characters. This impacts availability of the Custom Metrics Autoscaler Operator in Red Hat OpenShift environments. There is no reported impact on confidentiality or integrity. No known exploits in the wild have been reported at this time.

Mitigation Recommendations

A fixed update is available in Custom Metrics Autoscaler Operator version 2.15.1-4. Red Hat advises applying this update after ensuring all previously released errata relevant to the system have been applied. Additionally, pre-validation of token payloads to check for excessive '.' characters can mitigate the issue. Users should follow the update instructions provided in the Red Hat advisory RHSA-2025:3501 at https://access.redhat.com/articles/11258. No other mitigation actions are specified or required.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:3501
Cve Count
3
Additional Cves
["CVE-2025-22868","CVE-2025-27144"]

Threat ID: 6a160973e29bf47b5063c9e8

Added to database: 05/26/2026, 20:58:27 UTC

Last enriched: 08/14/2026, 22:11:08 UTC

Last updated: 09/10/2026, 19:36:48 UTC

Views: 108

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses