Skip to main content
EPSS 0.8%top 45%

Consul k8s fips: excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate (CVE-2025-22871)

0
Critical
Published: 02/26/2026 (02/26/2026, 00:41:27 UTC)
Source: GCVE Database
Product: consul-k8s-fips

Description

Multiple security vulnerabilities affect the consul-k8s-fips package. An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. See references for individual vulnerability details.

CVSS v3.1

Score 9.8critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected software

Affected versions
>=2.5.0 <2.6.0>=4.19.0 <4.19.10=4Red HatRed Hat OpenShift Container PlatformRed Hat OpenShift Container Platform 4.14amd64registry.redhat.io/openshift4/ose-cluster-autoscaler@sha256:c2dada3dfe7331d785da035ffe66b73a3bb1ce7eec3bba9eb29fe93e7496250e_amd64Logging Subsystem for Red Hat OpenShiftLogging Subsystem for Red Hat OpenShift 6.2registry.redhat.io/openshift-logging/cluster-logging-operator-bundle@sha256:94f256283b590b46946eb090170b62b824331c1d969102d214f04eb6537227e4_amd64Red Hat OpenShift EnterpriseRed Hat OpenShift Container Platform 4.19srccri-o-0:1.32.7-3.rhaos4.19.git23094d9.el9.srcRed Hat OpenShift Container Platform 4.18s390xopenshift4/ose-cluster-autoscaler-rhel9@sha256:8fd2174a195e0b19686d63284806b55ea0c0b3e9f58c6a3288f1b7406e2cf3ae_s390xRed Hat OpenShift Service MeshRed Hat OpenShift Service Mesh 3.0registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:12cc152afeeaa61a08a6dcea4f90678452a2838f847e2669843b857faafef420_amd64Red Hat multicluster global hubRed Hat multicluster global hub 1.4.3registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:be7d51547516d77996b93119a454f06c52b3d2159f85eefe623c21c8a5938bcb_amd64Logging for Red Hat OpenShiftLogging for Red Hat OpenShift 6.2Red Hat OpenShift Container Platform 4.12cri-o-0:1.25.5-31.rhaos4.12.git53dc492.el8.srcCryostatCryostat 4 on RHEL 9arm64cryostat/cryostat-agent-init-rhel9@sha256:aa01ceadbd32d164f7feb7caaa2c58297b899155d3a3599c874c83bd9f57feaf_arm64MicrosoftAzure Linux2.0CBL Mariner 2.0Red Hat OpenShift AIRed Hat OpenShift AI 2.21registry.redhat.io/rhoai/odh-codeflare-operator-rhel9@sha256:4c57dcf4df09fe0d03578cc8b9a3ca2ea485b6af0ca0203bfb85e640058b7daf_amd64Multicluster Global HubMulticluster Global Hub 1.4.5Red Hat OpenShift Container Platform 4.16<1.7.8-r0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 19:05:57 UTC

Technical Analysis

This vulnerability (CVE-2025-22871) concerns the net/http package in Red Hat OpenShift and Cryostat 4 on RHEL 9, where acceptance of invalid chunked data allows HTTP request smuggling. This flaw can potentially be exploited to interfere with HTTP request processing. Red Hat has issued security advisories and updated packages to fix this issue, including Cryostat 4 updates and OpenShift Container Platform 4.19.10 packages. The vulnerability is rated as high severity by Red Hat Product Security.

Potential Impact

The vulnerability allows HTTP request smuggling via invalid chunked data, which can disrupt normal HTTP request handling within affected Red Hat OpenShift and Cryostat components. This may lead to unauthorized request manipulation or bypassing security controls. No known exploits in the wild have been reported at this time.

Mitigation Recommendations

Red Hat has released official security updates addressing CVE-2025-22871. Users should apply the Cryostat 4 update for RHEL 9 and upgrade OpenShift Container Platform to version 4.19.10 or later as soon as these updates are available in their release channels. Prior errata should be applied before updating. Follow Red Hat's official documentation for upgrade procedures. Patch status is confirmed as official-fix available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:6493
Cve Count
4
Additional Cves
["CVE-2025-47907","CVE-2025-58183","CVE-2025-65637"]

Threat ID: 6a16096ee29bf47b50636297

Added to database: 05/26/2026, 20:58:22 UTC

Last enriched: 08/17/2026, 19:05:57 UTC

Last updated: 09/10/2026, 19:36:49 UTC

Views: 65

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2025:10323https://access.redhat.com/security/updates/classification/#important23584932372307Canonical URLhttps://access.redhat.com/errata/RHBA-2025:14817Canonical URLhttps://access.redhat.com/errata/RHSA-2025:8298https://access.redhat.com/security/cve/CVE-2025-22871https://access.redhat.com/security/updates/classificationhttps://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2025:12891Canonical URLhttps://access.redhat.com/errata/RHSA-2025:13241Canonical URLhttps://access.redhat.com/errata/RHSA-2025:10271https://access.redhat.com/security/updates/classification/#moderateCanonical URLhttps://access.redhat.com/errata/RHSA-2025:10291Canonical URLhttps://access.redhat.com/errata/RHSA-2025:9102https://docs.redhat.com/en/documentation/red_hat_openshift_ai/Canonical URLhttps://access.redhat.com/errata/RHSA-2025:107672374692OCPBUGS-43939OCPBUGS-46401OCPBUGS-46629OCPBUGS-47495OCPBUGS-54744OCPBUGS-55246OCPBUGS-55297OCPBUGS-56434OCPBUGS-56609OCPBUGS-56624OCPBUGS-56928OCPBUGS-57037OCPBUGS-57070OCPBUGS-57124OCPBUGS-57197OCPBUGS-57213https://access.redhat.com/errata/RHSA-2025:21331Canonical URLhttps://access.redhat.com/errata/RHSA-2025:10768Canonical URLhttps://access.redhat.com/errata/RHSA-2025:10782Canonical URLhttps://access.redhat.com/errata/RHSA-2025:11352Canonical URLhttps://access.redhat.com/errata/RHSA-2025:16124https://access.redhat.com/security/cve/cve-2025-22871https://issues.redhat.com/browse/OCPBUGS-42559https://issues.redhat.com/browse/AUTOSCALE-267https://issues.redhat.com/browse/OCPBUGS-35181https://issues.redhat.com/browse/OCPBUGS-58129https://issues.redhat.com/browse/OCPBUGS-55598Canonical URLhttps://access.redhat.com/errata/RHSA-2025:11479https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.7/html/release_notes/release-notes-47ROX-30092Canonical URLhttps://access.redhat.com/errata/RHSA-2025:11678OCPBUGS-58323Canonical URLhttps://access.redhat.com/errata/RHSA-2025:11682Canonical URLCVE-2025-22871 Request smuggling due to acceptance of invalid chunked data in net/http - VEXMicrosoft Support LifecycleCommon Vulnerability Scoring Systemhttps://access.redhat.com/errata/RHSA-2025:12091OSPRH-14708OSPRH-16204OSPRH-16331OSPRH-16366OSPRH-16586OSPRH-16785OSPRH-16994OSPRH-17012OSPRH-17029OSPRH-17106OSPRH-17187RHOSSTRAT-23RHOSSTRAT-259RHOSSTRAT-662RHOSSTRAT-682RHOSSTRAT-789RHOSSTRAT-871https://access.redhat.com/errata/RHSA-2025:12831Canonical URLhttps://access.redhat.com/errata/RHSA-2025:12850Canonical URLReference 93Reference 94Reference 95Reference 96Reference 97Reference 98Reference 99Reference 100Reference 101Reference 102Reference 103Reference 104Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses