Red Hat Security Advisory: Custom Metrics Autoscaler Operator for Red Hat OpenShift 2.15.1-4 Update
The Custom Metrics Autoscaler Operator for Red Hat OpenShift is an optional operator, based on the Kubernetes Event Driven Autoscaler (KEDA), which allows workloads to be scaled using additional metrics sources other than pod metrics. This release is based upon KEDA 2.15.1
AI Analysis
Technical Summary
The Custom Metrics Autoscaler Operator for Red Hat OpenShift, based on Kubernetes Event Driven Autoscaler (KEDA) 2.15.1, contains a vulnerability identified as CVE-2024-34156. This flaw arises from the use of strings.Split(token, ".") in the golang.org/x/oauth2/jws package during JWT token parsing, which can cause excessive memory consumption when processing tokens with many '.' characters. An attacker can exploit this by sending numerous malformed tokens, leading to memory exhaustion and denial of service. Red Hat has issued an update to version 2.15.1-4 of the operator that includes fixes for this and related vulnerabilities (CVE-2025-22868, CVE-2025-27144). The advisory references the Red Hat Security Advisory RHSA-2025:3501 and recommends applying the update after prior errata are installed.
Potential Impact
The vulnerability can cause denial of service due to memory exhaustion when the operator processes maliciously crafted tokens containing excessive '.' characters. This impacts availability of the Custom Metrics Autoscaler Operator in Red Hat OpenShift environments. There is no reported impact on confidentiality or integrity. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
A fixed update is available in Custom Metrics Autoscaler Operator version 2.15.1-4. Red Hat advises applying this update after ensuring all previously released errata relevant to the system have been applied. Additionally, pre-validation of token payloads to check for excessive '.' characters can mitigate the issue. Users should follow the update instructions provided in the Red Hat advisory RHSA-2025:3501 at https://access.redhat.com/articles/11258. No other mitigation actions are specified or required.
Red Hat Security Advisory: Custom Metrics Autoscaler Operator for Red Hat OpenShift 2.15.1-4 Update
Description
The Custom Metrics Autoscaler Operator for Red Hat OpenShift is an optional operator, based on the Kubernetes Event Driven Autoscaler (KEDA), which allows workloads to be scaled using additional metrics sources other than pod metrics. This release is based upon KEDA 2.15.1
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Custom Metrics Autoscaler Operator for Red Hat OpenShift, based on Kubernetes Event Driven Autoscaler (KEDA) 2.15.1, contains a vulnerability identified as CVE-2024-34156. This flaw arises from the use of strings.Split(token, ".") in the golang.org/x/oauth2/jws package during JWT token parsing, which can cause excessive memory consumption when processing tokens with many '.' characters. An attacker can exploit this by sending numerous malformed tokens, leading to memory exhaustion and denial of service. Red Hat has issued an update to version 2.15.1-4 of the operator that includes fixes for this and related vulnerabilities (CVE-2025-22868, CVE-2025-27144). The advisory references the Red Hat Security Advisory RHSA-2025:3501 and recommends applying the update after prior errata are installed.
Potential Impact
The vulnerability can cause denial of service due to memory exhaustion when the operator processes maliciously crafted tokens containing excessive '.' characters. This impacts availability of the Custom Metrics Autoscaler Operator in Red Hat OpenShift environments. There is no reported impact on confidentiality or integrity. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
A fixed update is available in Custom Metrics Autoscaler Operator version 2.15.1-4. Red Hat advises applying this update after ensuring all previously released errata relevant to the system have been applied. Additionally, pre-validation of token payloads to check for excessive '.' characters can mitigate the issue. Users should follow the update instructions provided in the Red Hat advisory RHSA-2025:3501 at https://access.redhat.com/articles/11258. No other mitigation actions are specified or required.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:3501
- Cve Count
- 3
- Additional Cves
- ["CVE-2025-22868","CVE-2025-27144"]
Threat ID: 6a160973e29bf47b5063c9e8
Added to database: 05/26/2026, 20:58:27 UTC
Last enriched: 08/14/2026, 22:11:08 UTC
Last updated: 09/10/2026, 19:36:48 UTC
Views: 108
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.