Red Hat Security Advisory: Custom Metrics Autoscaler Operator for Red Hat OpenShift 2.18.1-2 Update
The Custom Metrics Autoscaler Operator for Red Hat OpenShift is an optional operator, based on the Kubernetes Event Driven Autoscaler (KEDA), which allows workloads to be scaled using additional metrics sources other than pod metrics. This release is based upon KEDA 2.18.1
AI Analysis
Technical Summary
CVE-2025-68156 is a denial of service vulnerability in the Expr Go library used by the Custom Metrics Autoscaler Operator for Red Hat OpenShift. The vulnerability arises from uncontrolled recursion during expression evaluation of user-provided data structures that are deeply nested or cyclic, leading to stack overflow and application crash. This affects Red Hat products that utilize the Expr library and evaluate expressions against untrusted or insufficiently validated data. The vulnerability is rated important due to its potential to cause denial of service. Mitigations include validating or sanitizing input data structures to avoid cyclic references and wrapping expression evaluation with panic recovery. Red Hat has released updated operator images based on KEDA 2.18.1 to address this issue.
Potential Impact
Successful exploitation can cause a denial of service by crashing the application through stack overflow. This impacts availability but does not affect confidentiality or integrity. Only applications that evaluate expressions against untrusted or insufficiently validated data structures using the Expr library are affected.
Mitigation Recommendations
Red Hat has released updated Custom Metrics Autoscaler Operator images based on KEDA 2.18.1 that address this vulnerability. Users should apply these updates after ensuring all prior relevant errata are applied. Additionally, applications should validate or sanitize externally supplied data structures to prevent cyclic references before passing them to Expr for evaluation. Wrapping expression evaluation with panic recovery can also help prevent full process crashes. Follow Red Hat's official update instructions at https://access.redhat.com/articles/11258.
Red Hat Security Advisory: Custom Metrics Autoscaler Operator for Red Hat OpenShift 2.18.1-2 Update
Description
The Custom Metrics Autoscaler Operator for Red Hat OpenShift is an optional operator, based on the Kubernetes Event Driven Autoscaler (KEDA), which allows workloads to be scaled using additional metrics sources other than pod metrics. This release is based upon KEDA 2.18.1
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-68156 is a denial of service vulnerability in the Expr Go library used by the Custom Metrics Autoscaler Operator for Red Hat OpenShift. The vulnerability arises from uncontrolled recursion during expression evaluation of user-provided data structures that are deeply nested or cyclic, leading to stack overflow and application crash. This affects Red Hat products that utilize the Expr library and evaluate expressions against untrusted or insufficiently validated data. The vulnerability is rated important due to its potential to cause denial of service. Mitigations include validating or sanitizing input data structures to avoid cyclic references and wrapping expression evaluation with panic recovery. Red Hat has released updated operator images based on KEDA 2.18.1 to address this issue.
Potential Impact
Successful exploitation can cause a denial of service by crashing the application through stack overflow. This impacts availability but does not affect confidentiality or integrity. Only applications that evaluate expressions against untrusted or insufficiently validated data structures using the Expr library are affected.
Mitigation Recommendations
Red Hat has released updated Custom Metrics Autoscaler Operator images based on KEDA 2.18.1 that address this vulnerability. Users should apply these updates after ensuring all prior relevant errata are applied. Additionally, applications should validate or sanitize externally supplied data structures to prevent cyclic references before passing them to Expr for evaluation. Wrapping expression evaluation with panic recovery can also help prevent full process crashes. Follow Red Hat's official update instructions at https://access.redhat.com/articles/11258.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:2368
- Cve Count
- 2
- Additional Cves
- ["CVE-2025-68476"]
Threat ID: 6a23404ae29bf47b50c743e7
Added to database: 06/05/2026, 21:31:54 UTC
Last enriched: 08/10/2026, 20:34:05 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 123
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.