Skip to main content
EPSS 0.9%top 44%

Red Hat Security Advisory: Red Hat build of OpenTelemetry 3.6.0 release

0
High
Published: 06/17/2025 (06/17/2025, 09:27:34 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Breaking changes: * Nothing Deprecations: * Nothing Technology Preview features: * Cumulative-to-Delta Processor Enhancements: * The following Technology Preview features reach General Availability: * Kafka Exporter * Attributes Processor * Resource Processor * Prometheus Receiver * With this update, the OpenTelemetry Collector can read TLS certificates in the `tss2` format according to the TPM Software Stack specification (TSS) 2.0 of the Trusted Platform Module (TPM) 2.0 Library by the Trusted Computing Group (TCG). * With this update, the Red Hat build of OpenTelemetry Operator automatically upgrades all OpenTelemetryCollector custom resources during its startup. The Operator reconciles all managed instances during its startup. If there is an error, the Operator retries the upgrade at exponential backoff. If an upgrade fails, the Operator will retry the upgrade again when it restarts. Bug fixes: * Nothing Known issues: There is currently a known issue with the following exporters: * AWS CloudWatch Logs Exporter * AWS EMF Exporter * AWS X-Ray Exporter This known issue affects deployments that use the optional endpoint field of the exporter configuration in the Collector custom resource. Not specifying the protocol, such as https://, as part of the endpoint value results in the unsupported protocol scheme error. Workaround: Include the protocol, such as https://, as part of the endpoint value.

Affected software

Affected versions
>=3.6.0 <=3.6.1Red HatRed Hat OpenShift distributed tracingRed Hat OpenShift distributed tracing 3.6.0amd64registry.redhat.io/rhosdt/opentelemetry-operator-bundle@sha256:f08e30a5035f1c1bb79d62bc3db9ab19b9b8652c32b8c365e92ceab8abd01090_amd64Red Hat OpenShift distributed tracing 3.6.1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 21:59:54 UTC

Technical Analysis

CVE-2025-22868 is a denial of service vulnerability in the golang.org/x/oauth2/jws package's token parsing logic, specifically due to the use of strings.Split(token, ".") on JWT tokens. Maliciously crafted tokens with a large number of '.' characters can cause excessive memory consumption, leading to memory exhaustion and service disruption. This vulnerability affects the Red Hat build of OpenTelemetry 3.6.0, including Red Hat OpenShift distributed tracing components. The Red Hat advisory recommends mitigating this by pre-validating payloads passed to the go-jose library to ensure they do not contain an excessive number of '.' characters. The advisory does not explicitly confirm a patch but provides guidance on mitigation and references related bug reports and CVEs.

Potential Impact

An attacker can exploit this vulnerability by sending numerous malformed JWT tokens with many '.' characters, causing excessive memory consumption and potentially triggering a denial of service in affected OpenTelemetry components. The impact is limited to availability disruption; confidentiality and integrity are not affected.

Mitigation Recommendations

The vendor advisory recommends pre-validating any JWT payloads passed to the go-jose library to ensure they do not contain an excessive number of '.' characters, thereby preventing memory exhaustion. There is no explicit mention of an official patch or update fixing this issue in the advisory. Users should apply this mitigation and monitor Red Hat's official channels for any forthcoming patches or updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:9167
Cve Count
4
Additional Cves
["CVE-2025-27144","CVE-2025-29786","CVE-2025-30204"]

Threat ID: 6a160970e29bf47b50638563

Added to database: 05/26/2026, 20:58:24 UTC

Last enriched: 08/14/2026, 21:59:54 UTC

Last updated: 09/10/2026, 22:04:10 UTC

Views: 59

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses