Red Hat Security Advisory: Red Hat build of OpenTelemetry 3.6.0 release
Breaking changes: * Nothing Deprecations: * Nothing Technology Preview features: * Cumulative-to-Delta Processor Enhancements: * The following Technology Preview features reach General Availability: * Kafka Exporter * Attributes Processor * Resource Processor * Prometheus Receiver * With this update, the OpenTelemetry Collector can read TLS certificates in the `tss2` format according to the TPM Software Stack specification (TSS) 2.0 of the Trusted Platform Module (TPM) 2.0 Library by the Trusted Computing Group (TCG). * With this update, the Red Hat build of OpenTelemetry Operator automatically upgrades all OpenTelemetryCollector custom resources during its startup. The Operator reconciles all managed instances during its startup. If there is an error, the Operator retries the upgrade at exponential backoff. If an upgrade fails, the Operator will retry the upgrade again when it restarts. Bug fixes: * Nothing Known issues: There is currently a known issue with the following exporters: * AWS CloudWatch Logs Exporter * AWS EMF Exporter * AWS X-Ray Exporter This known issue affects deployments that use the optional endpoint field of the exporter configuration in the Collector custom resource. Not specifying the protocol, such as https://, as part of the endpoint value results in the unsupported protocol scheme error. Workaround: Include the protocol, such as https://, as part of the endpoint value.
AI Analysis
Technical Summary
CVE-2025-22868 is a denial of service vulnerability in the golang.org/x/oauth2/jws package's token parsing logic, specifically due to the use of strings.Split(token, ".") on JWT tokens. Maliciously crafted tokens with a large number of '.' characters can cause excessive memory consumption, leading to memory exhaustion and service disruption. This vulnerability affects the Red Hat build of OpenTelemetry 3.6.0, including Red Hat OpenShift distributed tracing components. The Red Hat advisory recommends mitigating this by pre-validating payloads passed to the go-jose library to ensure they do not contain an excessive number of '.' characters. The advisory does not explicitly confirm a patch but provides guidance on mitigation and references related bug reports and CVEs.
Potential Impact
An attacker can exploit this vulnerability by sending numerous malformed JWT tokens with many '.' characters, causing excessive memory consumption and potentially triggering a denial of service in affected OpenTelemetry components. The impact is limited to availability disruption; confidentiality and integrity are not affected.
Mitigation Recommendations
The vendor advisory recommends pre-validating any JWT payloads passed to the go-jose library to ensure they do not contain an excessive number of '.' characters, thereby preventing memory exhaustion. There is no explicit mention of an official patch or update fixing this issue in the advisory. Users should apply this mitigation and monitor Red Hat's official channels for any forthcoming patches or updates.
Red Hat Security Advisory: Red Hat build of OpenTelemetry 3.6.0 release
Description
Breaking changes: * Nothing Deprecations: * Nothing Technology Preview features: * Cumulative-to-Delta Processor Enhancements: * The following Technology Preview features reach General Availability: * Kafka Exporter * Attributes Processor * Resource Processor * Prometheus Receiver * With this update, the OpenTelemetry Collector can read TLS certificates in the `tss2` format according to the TPM Software Stack specification (TSS) 2.0 of the Trusted Platform Module (TPM) 2.0 Library by the Trusted Computing Group (TCG). * With this update, the Red Hat build of OpenTelemetry Operator automatically upgrades all OpenTelemetryCollector custom resources during its startup. The Operator reconciles all managed instances during its startup. If there is an error, the Operator retries the upgrade at exponential backoff. If an upgrade fails, the Operator will retry the upgrade again when it restarts. Bug fixes: * Nothing Known issues: There is currently a known issue with the following exporters: * AWS CloudWatch Logs Exporter * AWS EMF Exporter * AWS X-Ray Exporter This known issue affects deployments that use the optional endpoint field of the exporter configuration in the Collector custom resource. Not specifying the protocol, such as https://, as part of the endpoint value results in the unsupported protocol scheme error. Workaround: Include the protocol, such as https://, as part of the endpoint value.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-22868 is a denial of service vulnerability in the golang.org/x/oauth2/jws package's token parsing logic, specifically due to the use of strings.Split(token, ".") on JWT tokens. Maliciously crafted tokens with a large number of '.' characters can cause excessive memory consumption, leading to memory exhaustion and service disruption. This vulnerability affects the Red Hat build of OpenTelemetry 3.6.0, including Red Hat OpenShift distributed tracing components. The Red Hat advisory recommends mitigating this by pre-validating payloads passed to the go-jose library to ensure they do not contain an excessive number of '.' characters. The advisory does not explicitly confirm a patch but provides guidance on mitigation and references related bug reports and CVEs.
Potential Impact
An attacker can exploit this vulnerability by sending numerous malformed JWT tokens with many '.' characters, causing excessive memory consumption and potentially triggering a denial of service in affected OpenTelemetry components. The impact is limited to availability disruption; confidentiality and integrity are not affected.
Mitigation Recommendations
The vendor advisory recommends pre-validating any JWT payloads passed to the go-jose library to ensure they do not contain an excessive number of '.' characters, thereby preventing memory exhaustion. There is no explicit mention of an official patch or update fixing this issue in the advisory. Users should apply this mitigation and monitor Red Hat's official channels for any forthcoming patches or updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:9167
- Cve Count
- 4
- Additional Cves
- ["CVE-2025-27144","CVE-2025-29786","CVE-2025-30204"]
Threat ID: 6a160970e29bf47b50638563
Added to database: 05/26/2026, 20:58:24 UTC
Last enriched: 08/14/2026, 21:59:54 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 58
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.