Red Hat Security Advisory: Red Hat Multicluster GlobalHub 1.2.3 bug fixes and container updates
Red Hat multicluster global hub 1.2.3 images This advisory contains the container images for Red Hat multicluster global hub. These container images provide enhancements and fix several bugs. Security fixes: * golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204)
AI Analysis
Technical Summary
The Multicluster engine for Kubernetes prior to version 2.7.5 contains a vulnerability in the golang-jwt/jwt library (CVE-2025-30204) that permits excessive memory allocation during JWT header parsing. This could potentially lead to resource exhaustion or denial of service conditions. Red Hat has released version 2.7.5 of the Multicluster engine which includes security updates and bug fixes to address this issue. The engine is used for centralized management of Kubernetes clusters across data centers and cloud environments, facilitating cluster creation, import, and configuration distribution via APIs. The advisory also references updates to VolSync v0.12 with security fixes. The vendor advisory confirms the availability of fixed images and provides detailed installation and update instructions.
Potential Impact
The vulnerability allows excessive memory allocation during JWT header parsing, which may lead to denial of service or resource exhaustion in affected Multicluster engine components. This impacts the stability and reliability of centralized Kubernetes cluster management operations. No known exploits in the wild have been reported. The impact is rated as high by Red Hat due to the potential for disruption in critical cluster management infrastructure.
Mitigation Recommendations
Red Hat has released Multicluster engine for Kubernetes version 2.7.5 which includes fixes for CVE-2025-30204. Users should upgrade to version 2.7.5 or later to remediate this vulnerability. Updated container images and installation instructions are available in the Red Hat documentation. No additional mitigations are required beyond applying the official update. The vendor manages remediation for this product via these updated releases.
Red Hat Security Advisory: Red Hat Multicluster GlobalHub 1.2.3 bug fixes and container updates
Description
Red Hat multicluster global hub 1.2.3 images This advisory contains the container images for Red Hat multicluster global hub. These container images provide enhancements and fix several bugs. Security fixes: * golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204)
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Multicluster engine for Kubernetes prior to version 2.7.5 contains a vulnerability in the golang-jwt/jwt library (CVE-2025-30204) that permits excessive memory allocation during JWT header parsing. This could potentially lead to resource exhaustion or denial of service conditions. Red Hat has released version 2.7.5 of the Multicluster engine which includes security updates and bug fixes to address this issue. The engine is used for centralized management of Kubernetes clusters across data centers and cloud environments, facilitating cluster creation, import, and configuration distribution via APIs. The advisory also references updates to VolSync v0.12 with security fixes. The vendor advisory confirms the availability of fixed images and provides detailed installation and update instructions.
Potential Impact
The vulnerability allows excessive memory allocation during JWT header parsing, which may lead to denial of service or resource exhaustion in affected Multicluster engine components. This impacts the stability and reliability of centralized Kubernetes cluster management operations. No known exploits in the wild have been reported. The impact is rated as high by Red Hat due to the potential for disruption in critical cluster management infrastructure.
Mitigation Recommendations
Red Hat has released Multicluster engine for Kubernetes version 2.7.5 which includes fixes for CVE-2025-30204. Users should upgrade to version 2.7.5 or later to remediate this vulnerability. Updated container images and installation instructions are available in the Red Hat documentation. No additional mitigations are required beyond applying the official update. The vendor manages remediation for this product via these updated releases.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:9388
- Cve Count
- 1
Threat ID: 6a160970e29bf47b5063854e
Added to database: 05/26/2026, 20:58:24 UTC
Last enriched: 08/10/2026, 18:23:06 UTC
Last updated: 09/10/2026, 22:04:10 UTC
Views: 58
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.