Red Hat Security Advisory: Red Hat build of OpenTelemetry 3.6.1 release
This release of the Red Hat build of OpenTelemetry provides a CVE fix. Breaking changes: * Nothing Deprecations: * Nothing Technology Preview features: * Nothing Enhancements: * Nothing Bug fixes: * Nothing Known issues: * Nothing
AI Analysis
Technical Summary
CVE-2025-4673 is a vulnerability in the net/http package of the Go programming language where sensitive headers (Proxy-Authorization and Proxy-Authenticate) are not cleared on cross-origin redirects. This flaw can cause these headers to be inadvertently forwarded to unauthorized parties if a network attacker manipulates redirect responses. Exploitation requires a proxy that uses these headers for authentication and user interaction with a malicious URL. The vulnerability impacts confidentiality but not integrity or availability. Red Hat's advisory for their OpenTelemetry build (version 3.6.1) includes this fix, but no official patch or mitigation is currently available that meets Red Hat's deployment and stability criteria.
Potential Impact
The vulnerability can lead to significant confidentiality compromise by exposing sensitive authentication credentials during cross-origin redirects. However, the attack complexity is high, requiring specific proxy configurations and user interaction. There is no impact on system integrity or availability, and no arbitrary code execution is possible. Red Hat rates the issue as Moderate severity.
Mitigation Recommendations
Red Hat currently does not provide a mitigation or patch that meets their criteria for ease of use, deployment, applicability, or stability. Users are advised to monitor Red Hat advisories for updates. No immediate workaround is available. Upgrading to a fixed version when released is recommended once available.
Red Hat Security Advisory: Red Hat build of OpenTelemetry 3.6.1 release
Description
This release of the Red Hat build of OpenTelemetry provides a CVE fix. Breaking changes: * Nothing Deprecations: * Nothing Technology Preview features: * Nothing Enhancements: * Nothing Bug fixes: * Nothing Known issues: * Nothing
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-4673 is a vulnerability in the net/http package of the Go programming language where sensitive headers (Proxy-Authorization and Proxy-Authenticate) are not cleared on cross-origin redirects. This flaw can cause these headers to be inadvertently forwarded to unauthorized parties if a network attacker manipulates redirect responses. Exploitation requires a proxy that uses these headers for authentication and user interaction with a malicious URL. The vulnerability impacts confidentiality but not integrity or availability. Red Hat's advisory for their OpenTelemetry build (version 3.6.1) includes this fix, but no official patch or mitigation is currently available that meets Red Hat's deployment and stability criteria.
Potential Impact
The vulnerability can lead to significant confidentiality compromise by exposing sensitive authentication credentials during cross-origin redirects. However, the attack complexity is high, requiring specific proxy configurations and user interaction. There is no impact on system integrity or availability, and no arbitrary code execution is possible. Red Hat rates the issue as Moderate severity.
Mitigation Recommendations
Red Hat currently does not provide a mitigation or patch that meets their criteria for ease of use, deployment, applicability, or stability. Users are advised to monitor Red Hat advisories for updates. No immediate workaround is available. Upgrading to a fixed version when released is recommended once available.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:10735
- Cve Count
- 2
- Additional Cves
- ["CVE-2025-6020"]
Threat ID: 6a1f4e87e29bf47b50080a13
Added to database: 06/02/2026, 21:43:35 UTC
Last enriched: 08/16/2026, 17:14:23 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 86
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.