Skip to main content
EPSS 0.2%top 90%

Red Hat Security Advisory: Red Hat OpenShift sandboxed containers release

0
High
Published: 07/31/2025 (07/31/2025, 10:50:08 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift sandboxed containers, based on the Kata Containers project.

Affected software

Affected versions
>=1.1 <=1.1Red HatRed Hat OpenShift sandboxed containersRed Hat OpenShift sandboxed containers 1.1amd64registry.redhat.io/openshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9@sha256:145a851ce5b328570edbb67840af93b2ac74b64d61ab53edb4c2b7a032bfc0d8_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 19:02:37 UTC

Technical Analysis

The vulnerability CVE-2025-5791 in Red Hat OpenShift sandboxed containers stems from a flaw in the Go net/http package, which incorrectly accepts HTTP messages ending with a line feed (LF) rather than the proper CRLF sequence. This can cause HTTP request smuggling when interacting with other servers that also misinterpret such messages. The issue is related to CWE-444 (Inconsistent Interpretation of HTTP Requests) and CWE-266 (Incorrect Privilege Assignment). Red Hat's advisory references CVE-2025-22871, which details this flaw and its impact. The vulnerability can lead to web cache poisoning, firewall bypass, unauthorized access, and potential exposure of client credentials. Red Hat rates the severity as high for affected components but notes that some products like Red Hat Satellite are less impacted due to their client-only usage of the affected component. Currently, no mitigation or patch meets Red Hat's criteria for ease of use, applicability, or stability, and remediation status is under investigation.

Potential Impact

The vulnerability allows an attacker to craft HTTP requests that exploit inconsistent parsing of HTTP messages, potentially leading to HTTP request smuggling. This can result in web cache poisoning, bypassing firewall protections, unauthorized access to web applications, and exposure of client credentials. The impact on confidentiality and integrity is rated low by Red Hat for their products, but the overall severity is high due to the potential for bypassing security controls. Red Hat Satellite is less affected as it uses the vulnerable component only as a client, not a server.

Mitigation Recommendations

Red Hat currently does not provide a patch or mitigation that meets their criteria for deployment ease, applicability, or stability. Users should monitor Red Hat advisories for updates. Red Hat recommends upgrading to supported product versions once fixes become available. Customers with a Technical Account Manager (TAM) can discuss this vulnerability directly with Red Hat. No immediate mitigation is available or recommended by Red Hat at this time.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:12359
Cve Count
2
Additional Cves
["CVE-2025-22871"]

Threat ID: 6a18be67e29bf47b503872bf

Added to database: 05/28/2026, 22:15:03 UTC

Last enriched: 08/17/2026, 19:02:37 UTC

Last updated: 09/10/2026, 19:36:51 UTC

Views: 90

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses