Skip to main content
EPSS 0.2%top 89%

Red Hat Security Advisory: OpenShift Security Profiles Operator bug fix and enhancement update

0
High
Published: 02/17/2026 (02/17/2026, 23:04:21 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The Security Profiles Operator v0.10.0 is now available. See the documentation for release information: https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/security_and_compliance/security-profiles-operator

Affected software

Affected versions
<0.10.0Red HatSecurity Profiles OperatorSecurity Profiles Operator 1amd64registry.redhat.io/compliance/openshift-selinuxd-rhel10@sha256:1484157970f2cc4470dfec565fb5f81137402bdcd52d63cd40be4b0e9c8ce039_amd64OpenShift Security Profiles OperatorOpenShift Security Profiles Operator 1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 21:37:04 UTC

Technical Analysis

CVE-2025-66506 is a denial of service vulnerability in Fulcio, a certificate authority used by Red Hat products for code signing. The vulnerability arises from excessive memory allocation when processing a specially crafted OpenID Connect (OIDC) token containing many period characters, leading to resource exhaustion and potential service unavailability. This affects Red Hat products that utilize Fulcio, including the OpenShift Security Profiles Operator. Red Hat released version 0.10.0 of the Security Profiles Operator to fix this and other related bugs. The advisory references multiple bug fixes related to pod startup failures and container creation errors. The vulnerability is classified under CWE-405 (Asymmetric Resource Consumption). Red Hat rates this vulnerability as important and assigns a CVSS base score of 7.5 (high) for their products, although no official CVSS score is published in the advisory. The vendor recommends applying all previous errata before updating to the fixed version.

Potential Impact

The vulnerability can cause denial of service due to resource exhaustion (memory and CPU) when processing malicious OIDC tokens. This can lead to service unavailability in affected Red Hat products that use Fulcio, including the OpenShift Security Profiles Operator. There is no indication of confidentiality or integrity impact. No known exploits in the wild have been reported. The issue affects availability and could disrupt normal operations of the affected components.

Mitigation Recommendations

Red Hat has released Security Profiles Operator version 0.10.0 which includes fixes for this vulnerability and other bugs. Users should ensure all previously released errata relevant to their systems are applied before updating. The update process is documented by Red Hat. No additional mitigations are specified beyond applying the official update. There is no indication that the vulnerability is already mitigated or that no action is required.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:2852
Cve Count
2
Additional Cves
["CVE-2025-66564"]

Threat ID: 6a16096fe29bf47b50636fd0

Added to database: 05/26/2026, 20:58:23 UTC

Last enriched: 08/14/2026, 21:37:04 UTC

Last updated: 09/10/2026, 19:36:51 UTC

Views: 73

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses