Red Hat Security Advisory: Red Hat AI Inference Server 3.2.5 (CUDA)
Red Hat AI Inference Server 3.2.5 (CUDA) is affected by multiple security vulnerabilities, including CVE-2025-9230 and others. One notable issue is a flaw in the golang.org/x/oauth2/jws package used for token parsing, which can lead to excessive memory consumption and denial of service when processing maliciously crafted tokens. The advisory does not currently provide a fix for these vulnerabilities. Mitigation involves pre-validating payloads to avoid excessive '.' characters in tokens. The vulnerabilities have a high severity rating but no known exploits in the wild have been reported.
AI Analysis
Technical Summary
The Red Hat AI Inference Server 3.2.5 (CUDA) contains multiple vulnerabilities, including CVE-2025-22868, which involves improper token parsing in the golang.org/x/oauth2/jws package. This vulnerability arises from using strings.Split(token, ".") to parse JWT tokens, allowing attackers to craft tokens with many '.' characters that cause excessive memory consumption and potential denial of service. The advisory lists 11 CVEs affecting the product but does not indicate any available patches or fixes. The vulnerabilities are rated high severity by Red Hat, with no known exploits in the wild. Mitigation recommendations include pre-validating tokens to limit '.' characters before processing.
Potential Impact
The primary impact is a denial of service condition caused by memory exhaustion when processing maliciously crafted tokens with excessive '.' characters. This can disrupt the availability of the Red Hat AI Inference Server. No confidentiality or integrity impacts are indicated. There are no known active exploits in the wild at this time.
Mitigation Recommendations
Currently, no official fix or patch is available for these vulnerabilities in Red Hat AI Inference Server 3.2.5 (CUDA). Red Hat recommends mitigating the token parsing vulnerability by pre-validating any payloads passed to the go-jose library to ensure they do not contain an excessive number of '.' characters. Users should monitor Red Hat advisories for updates and consider applying mitigations as described until a fix is released.
Red Hat Security Advisory: Red Hat AI Inference Server 3.2.5 (CUDA)
Description
Red Hat AI Inference Server 3.2.5 (CUDA) is affected by multiple security vulnerabilities, including CVE-2025-9230 and others. One notable issue is a flaw in the golang.org/x/oauth2/jws package used for token parsing, which can lead to excessive memory consumption and denial of service when processing maliciously crafted tokens. The advisory does not currently provide a fix for these vulnerabilities. Mitigation involves pre-validating payloads to avoid excessive '.' characters in tokens. The vulnerabilities have a high severity rating but no known exploits in the wild have been reported.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Red Hat AI Inference Server 3.2.5 (CUDA) contains multiple vulnerabilities, including CVE-2025-22868, which involves improper token parsing in the golang.org/x/oauth2/jws package. This vulnerability arises from using strings.Split(token, ".") to parse JWT tokens, allowing attackers to craft tokens with many '.' characters that cause excessive memory consumption and potential denial of service. The advisory lists 11 CVEs affecting the product but does not indicate any available patches or fixes. The vulnerabilities are rated high severity by Red Hat, with no known exploits in the wild. Mitigation recommendations include pre-validating tokens to limit '.' characters before processing.
Potential Impact
The primary impact is a denial of service condition caused by memory exhaustion when processing maliciously crafted tokens with excessive '.' characters. This can disrupt the availability of the Red Hat AI Inference Server. No confidentiality or integrity impacts are indicated. There are no known active exploits in the wild at this time.
Mitigation Recommendations
Currently, no official fix or patch is available for these vulnerabilities in Red Hat AI Inference Server 3.2.5 (CUDA). Red Hat recommends mitigating the token parsing vulnerability by pre-validating any payloads passed to the go-jose library to ensure they do not contain an excessive number of '.' characters. Users should monitor Red Hat advisories for updates and consider applying mitigations as described until a fix is released.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:23204
- Cve Count
- 11
- Additional Cves
- ["CVE-2025-9714","CVE-2025-22868","CVE-2025-22869","CVE-2025-52565","CVE-2025-59375","CVE-2025-62164","CVE-2025-62372","CVE-2025-62593","CVE-2025-66448","CVE-2025-66506"]
- Cvss Version
- null
Threat ID: 6a160974e29bf47b5063decf
Added to database: 05/26/2026, 20:58:28 UTC
Last enriched: 08/07/2026, 00:28:12 UTC
Last updated: 08/07/2026, 00:41:11 UTC
Views: 69
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.