Red Hat Security Advisory: RHTAS 1.1.2 - Red Hat Trusted Artifact Signer Release
The RHTAS Operator can be used with OpenShift Container Platform 4.14, 4.15, 4.16, 4.17, and 4.18
AI Analysis
Technical Summary
CVE-2025-22868 is a vulnerability in the golang.org/x/oauth2/jws package's token parsing logic. The package uses strings.Split(token, ".") to split JWT tokens, which can be exploited by sending tokens with a large number of '.' characters, causing excessive memory consumption and potential denial of service. This affects Red Hat OpenShift Logging 6.2.7 and related components. Red Hat recommends pre-validating payloads passed to go-jose to check for excessive '.' characters to mitigate the issue. The vulnerability has a CVSS v3 base score of 7.5 (high) as assessed by Red Hat, with no confidentiality or integrity impact but high availability impact.
Potential Impact
An attacker can cause denial of service by sending numerous malformed JWT tokens containing excessive '.' characters, leading to memory exhaustion in affected components. This impacts availability of services relying on the vulnerable token parsing logic. There is no impact on confidentiality or integrity.
Mitigation Recommendations
Red Hat advises pre-validating any payloads passed to the go-jose library to ensure they do not contain an excessive number of '.' characters. Users should upgrade to Red Hat OpenShift Logging 6.2.7 or later where the issue is addressed. Follow Red Hat's official upgrade and patch instructions as detailed in their advisory. No other immediate actions are required beyond applying the update and validation.
Red Hat Security Advisory: RHTAS 1.1.2 - Red Hat Trusted Artifact Signer Release
Description
The RHTAS Operator can be used with OpenShift Container Platform 4.14, 4.15, 4.16, 4.17, and 4.18
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-22868 is a vulnerability in the golang.org/x/oauth2/jws package's token parsing logic. The package uses strings.Split(token, ".") to split JWT tokens, which can be exploited by sending tokens with a large number of '.' characters, causing excessive memory consumption and potential denial of service. This affects Red Hat OpenShift Logging 6.2.7 and related components. Red Hat recommends pre-validating payloads passed to go-jose to check for excessive '.' characters to mitigate the issue. The vulnerability has a CVSS v3 base score of 7.5 (high) as assessed by Red Hat, with no confidentiality or integrity impact but high availability impact.
Potential Impact
An attacker can cause denial of service by sending numerous malformed JWT tokens containing excessive '.' characters, leading to memory exhaustion in affected components. This impacts availability of services relying on the vulnerable token parsing logic. There is no impact on confidentiality or integrity.
Mitigation Recommendations
Red Hat advises pre-validating any payloads passed to the go-jose library to ensure they do not contain an excessive number of '.' characters. Users should upgrade to Red Hat OpenShift Logging 6.2.7 or later where the issue is addressed. Follow Red Hat's official upgrade and patch instructions as detailed in their advisory. No other immediate actions are required beyond applying the update and validation.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:3813
- Cve Count
- 3
- Additional Cves
- ["CVE-2025-22869","CVE-2025-30204"]
Threat ID: 6a160979e29bf47b50645cb4
Added to database: 05/26/2026, 20:58:33 UTC
Last enriched: 08/14/2026, 22:08:37 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 67
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.