Red Hat Security Advisory: Red Hat OpenShift API for Data Protection
OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume data, and internal container images to external backup storage. OADP enables both file system-based and snapshot-based backups for persistent volumes.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2025-47911 affects the html.Parse function in the golang.org/x/net/html package, which is used by Red Hat OpenShift API for Data Protection (OADP). The function exhibits quadratic parsing complexity on certain crafted inputs, enabling an attacker to cause uncontrolled resource consumption (CPU, memory) leading to denial of service. This can result in application slowdown, crashes, or unavailability when processing untrusted HTML content. Red Hat has released a security advisory (RHSA-2026:43692) with an updated OADP version that includes fixes for this and other issues. The vulnerability is associated with CWE-400 (Uncontrolled Resource Consumption).
Potential Impact
Exploitation of this vulnerability can cause denial of service by exhausting system resources due to inefficient parsing of malicious HTML input. This may lead to application crashes or unresponsiveness, affecting availability of backup and restore functionality in OpenShift API for Data Protection. There is no impact on confidentiality or integrity reported. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat has released an updated version of OpenShift API for Data Protection that addresses this vulnerability. Users should apply the update as per the Red Hat advisory RHSA-2026:43692 after ensuring all previous relevant errata are applied. No additional mitigations are specified by the vendor. Patch status is confirmed as fixed in the updated OADP release.
Red Hat Security Advisory: Red Hat OpenShift API for Data Protection
Description
OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume data, and internal container images to external backup storage. OADP enables both file system-based and snapshot-based backups for persistent volumes.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2025-47911 affects the html.Parse function in the golang.org/x/net/html package, which is used by Red Hat OpenShift API for Data Protection (OADP). The function exhibits quadratic parsing complexity on certain crafted inputs, enabling an attacker to cause uncontrolled resource consumption (CPU, memory) leading to denial of service. This can result in application slowdown, crashes, or unavailability when processing untrusted HTML content. Red Hat has released a security advisory (RHSA-2026:43692) with an updated OADP version that includes fixes for this and other issues. The vulnerability is associated with CWE-400 (Uncontrolled Resource Consumption).
Potential Impact
Exploitation of this vulnerability can cause denial of service by exhausting system resources due to inefficient parsing of malicious HTML input. This may lead to application crashes or unresponsiveness, affecting availability of backup and restore functionality in OpenShift API for Data Protection. There is no impact on confidentiality or integrity reported. No known exploits in the wild have been reported.
Mitigation Recommendations
Red Hat has released an updated version of OpenShift API for Data Protection that addresses this vulnerability. Users should apply the update as per the Red Hat advisory RHSA-2026:43692 after ensuring all previous relevant errata are applied. No additional mitigations are specified by the vendor. Patch status is confirmed as fixed in the updated OADP release.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:43692
- Cve Count
- 34
- Additional Cves
- ["CVE-2025-47913","CVE-2025-47914","CVE-2025-58181","CVE-2025-58190","CVE-2026-25680","CVE-2026-25681","CVE-2026-27136","CVE-2026-33186","CVE-2026-33811","CVE-2026-33814","CVE-2026-39817","CVE-2026-39820","CVE-2026-39821","CVE-2026-39823","CVE-2026-39825","CVE-2026-39826","CVE-2026-39827","CVE-2026-39828","CVE-2026-39829","CVE-2026-39830","CVE-2026-39831","CVE-2026-39832","CVE-2026-39833","CVE-2026-39834","CVE-2026-39835","CVE-2026-40356","CVE-2026-42499","CVE-2026-42502","CVE-2026-42506","CVE-2026-42508","CVE-2026-46595","CVE-2026-46597","CVE-2026-46598"]
- Cvss Version
- null
Threat ID: 6a6150e99c2644c7f8da234b
Added to database: 07/22/2026, 23:23:21 UTC
Last enriched: 08/14/2026, 18:53:39 UTC
Last updated: 09/02/2026, 22:52:06 UTC
Views: 98
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.