Consul k8s fips: excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate (CVE-2025-22871)
Multiple security vulnerabilities affect the consul-k8s-fips package. An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. See references for individual vulnerability details.
AI Analysis
Technical Summary
This vulnerability (CVE-2025-22871) concerns the net/http package in Red Hat OpenShift and Cryostat 4 on RHEL 9, where acceptance of invalid chunked data allows HTTP request smuggling. This flaw can potentially be exploited to interfere with HTTP request processing. Red Hat has issued security advisories and updated packages to fix this issue, including Cryostat 4 updates and OpenShift Container Platform 4.19.10 packages. The vulnerability is rated as high severity by Red Hat Product Security.
Potential Impact
The vulnerability allows HTTP request smuggling via invalid chunked data, which can disrupt normal HTTP request handling within affected Red Hat OpenShift and Cryostat components. This may lead to unauthorized request manipulation or bypassing security controls. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released official security updates addressing CVE-2025-22871. Users should apply the Cryostat 4 update for RHEL 9 and upgrade OpenShift Container Platform to version 4.19.10 or later as soon as these updates are available in their release channels. Prior errata should be applied before updating. Follow Red Hat's official documentation for upgrade procedures. Patch status is confirmed as official-fix available.
Consul k8s fips: excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate (CVE-2025-22871)
Description
Multiple security vulnerabilities affect the consul-k8s-fips package. An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. See references for individual vulnerability details.
CVSS v3.1
Score 9.8critical
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2025-22871) concerns the net/http package in Red Hat OpenShift and Cryostat 4 on RHEL 9, where acceptance of invalid chunked data allows HTTP request smuggling. This flaw can potentially be exploited to interfere with HTTP request processing. Red Hat has issued security advisories and updated packages to fix this issue, including Cryostat 4 updates and OpenShift Container Platform 4.19.10 packages. The vulnerability is rated as high severity by Red Hat Product Security.
Potential Impact
The vulnerability allows HTTP request smuggling via invalid chunked data, which can disrupt normal HTTP request handling within affected Red Hat OpenShift and Cryostat components. This may lead to unauthorized request manipulation or bypassing security controls. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released official security updates addressing CVE-2025-22871. Users should apply the Cryostat 4 update for RHEL 9 and upgrade OpenShift Container Platform to version 4.19.10 or later as soon as these updates are available in their release channels. Prior errata should be applied before updating. Follow Red Hat's official documentation for upgrade procedures. Patch status is confirmed as official-fix available.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:6493
- Cve Count
- 4
- Additional Cves
- ["CVE-2025-47907","CVE-2025-58183","CVE-2025-65637"]
Threat ID: 6a16096ee29bf47b50636297
Added to database: 05/26/2026, 20:58:22 UTC
Last enriched: 08/17/2026, 19:05:57 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 65
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.