Red Hat Security Advisory: OpenShift Security Profiles Operator bug fix and enhancement update
The Security Profiles Operator v0.10.0 is now available. See the documentation for release information: https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/security_and_compliance/security-profiles-operator
AI Analysis
Technical Summary
CVE-2025-66506 is a denial of service vulnerability in Fulcio, a certificate authority used by Red Hat products for code signing. The vulnerability arises from excessive memory allocation when processing a specially crafted OpenID Connect (OIDC) token containing many period characters, leading to resource exhaustion and potential service unavailability. This affects Red Hat products that utilize Fulcio, including the OpenShift Security Profiles Operator. Red Hat released version 0.10.0 of the Security Profiles Operator to fix this and other related bugs. The advisory references multiple bug fixes related to pod startup failures and container creation errors. The vulnerability is classified under CWE-405 (Asymmetric Resource Consumption). Red Hat rates this vulnerability as important and assigns a CVSS base score of 7.5 (high) for their products, although no official CVSS score is published in the advisory. The vendor recommends applying all previous errata before updating to the fixed version.
Potential Impact
The vulnerability can cause denial of service due to resource exhaustion (memory and CPU) when processing malicious OIDC tokens. This can lead to service unavailability in affected Red Hat products that use Fulcio, including the OpenShift Security Profiles Operator. There is no indication of confidentiality or integrity impact. No known exploits in the wild have been reported. The issue affects availability and could disrupt normal operations of the affected components.
Mitigation Recommendations
Red Hat has released Security Profiles Operator version 0.10.0 which includes fixes for this vulnerability and other bugs. Users should ensure all previously released errata relevant to their systems are applied before updating. The update process is documented by Red Hat. No additional mitigations are specified beyond applying the official update. There is no indication that the vulnerability is already mitigated or that no action is required.
Red Hat Security Advisory: OpenShift Security Profiles Operator bug fix and enhancement update
Description
The Security Profiles Operator v0.10.0 is now available. See the documentation for release information: https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/security_and_compliance/security-profiles-operator
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-66506 is a denial of service vulnerability in Fulcio, a certificate authority used by Red Hat products for code signing. The vulnerability arises from excessive memory allocation when processing a specially crafted OpenID Connect (OIDC) token containing many period characters, leading to resource exhaustion and potential service unavailability. This affects Red Hat products that utilize Fulcio, including the OpenShift Security Profiles Operator. Red Hat released version 0.10.0 of the Security Profiles Operator to fix this and other related bugs. The advisory references multiple bug fixes related to pod startup failures and container creation errors. The vulnerability is classified under CWE-405 (Asymmetric Resource Consumption). Red Hat rates this vulnerability as important and assigns a CVSS base score of 7.5 (high) for their products, although no official CVSS score is published in the advisory. The vendor recommends applying all previous errata before updating to the fixed version.
Potential Impact
The vulnerability can cause denial of service due to resource exhaustion (memory and CPU) when processing malicious OIDC tokens. This can lead to service unavailability in affected Red Hat products that use Fulcio, including the OpenShift Security Profiles Operator. There is no indication of confidentiality or integrity impact. No known exploits in the wild have been reported. The issue affects availability and could disrupt normal operations of the affected components.
Mitigation Recommendations
Red Hat has released Security Profiles Operator version 0.10.0 which includes fixes for this vulnerability and other bugs. Users should ensure all previously released errata relevant to their systems are applied before updating. The update process is documented by Red Hat. No additional mitigations are specified beyond applying the official update. There is no indication that the vulnerability is already mitigated or that no action is required.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:2852
- Cve Count
- 2
- Additional Cves
- ["CVE-2025-66564"]
Threat ID: 6a16096fe29bf47b50636fd0
Added to database: 05/26/2026, 20:58:23 UTC
Last enriched: 08/14/2026, 21:37:04 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 73
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.