Skip to main content
EPSS 0.9%top 44%

Red Hat Security Advisory: Logging for Red Hat OpenShift - 6.2.7

0
High
Published: 12/17/2025 (12/17/2025, 15:37:08 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat OpenShift Logging 6.2.7 is a cluster-wide logging solution for OpenShift that collects and manages applications, infrastructure, and audit logs.

Affected software

Affected versions
Red HatRed Hat ACMRed Hat Advanced Cluster Management for Kubernetes 2.10 for RHEL 9ppc64lerhacm2/lighthouse-agent-rhel9@sha256:8f22385b2571331ce6d0577a296d1de34a17b7467ce5e93808ac67f51c36319f_ppc64leRed Hat QuayQuay v3amd64quay/quay-bridge-operator-bundle@sha256:d783dc9ca701f4d06550c11274ae432b70c827dd6dfc0cd53083112ab2c934cb_amd64Logging for Red Hat OpenShiftLogging for Red Hat OpenShift 6.2registry.redhat.io/openshift-logging/cluster-logging-operator-bundle@sha256:912e0be15a46e77b2495db1dad335edc4116027c342698cedd8e7718cc15a5c1_amd64gatekeepergatekeeper 3.17 for RHEL 9s390xgatekeeper/gatekeeper-rhel9@sha256:ca290a799cd15897e62314cea4603653a1da7aa935db51640409b00e8361707e_s390xLogging Subsystem for Red Hat OpenShiftLogging Subsystem for Red Hat OpenShift 6.2Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9rhacm2/volsync-rhel9@sha256:ab0e5a22a273e298802437e3b4d083c8cfc55da6c23a43d7c840b740248bf110_amd64CryostatCryostat 4 on RHEL 9cryostat/cryostat-agent-init-rhel9@sha256:12a06a8e0d5d382c26d38c483c4f78e1a51d6ad3d79dff1639bec6a622a09d52_amd64rhacm2/acm-cli-rhel9@sha256:a2e706586a41dee7bf197285ddb55e53518d422f26e30513230aa1afdd45fdc9_amd64Red Hat Trusted Artifact SignerRed Hat Trusted Artifact Signer 1.1registry.redhat.io/rhtas/rekor-backfill-redis-rhel9@sha256:6131053778ea04e437f3005f90d1138aa11ebc58e3a9295e2a8d8ef6713a52be_amd64Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9rhacm2/volsync-rhel9@sha256:fa18cbf3efd16da8e961ab1077fe5af57aa041f09a38220ae733a2bb5c1ad6d0_amd64Red Hat OpenShift AIRed Hat OpenShift AI 2.19registry.redhat.io/rhoai/odh-codeflare-operator-rhel8@sha256:ed1221a6e826166806ec6e18e42e098cb97767471059527c7fc6f47b8d6fb58a_amd64<1.10.0-r1<3.3.0-r1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 00:09:12 UTC

Technical Analysis

The vulnerability CVE-2025-22868 affects the golang.org/x/oauth2/jws package's token parsing component, specifically due to the use of strings.Split(token, ".") to split JWT tokens. Malicious tokens with a large number of '.' characters can cause excessive memory consumption, leading to denial of service via memory exhaustion. The issue is fixed in postgres-operator version 1.12.2-r2 and related Red Hat OpenShift Logging 6.2.7 and other affected products. The recommended mitigation is to pre-validate payloads passed to go-jose to ensure they do not contain an excessive number of '.' characters.

Potential Impact

An attacker can exploit this vulnerability by sending numerous malformed JWT tokens with excessive '.' characters, causing the vulnerable component to consume excessive memory and potentially crash or become unavailable, resulting in denial of service. There is no impact on confidentiality or integrity, only availability is affected. No known exploits in the wild have been reported.

Mitigation Recommendations

A patch is available in postgres-operator version 1.12.2-r2 and related Red Hat products such as Red Hat OpenShift Logging 6.2.7. It is recommended to upgrade to these fixed versions. Additionally, pre-validate any JWT tokens or payloads passed to the go-jose library to check for an excessive number of '.' characters to mitigate the vulnerability. Follow vendor upgrade instructions and advisories for full remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:9541
Cve Count
2
Additional Cves
["CVE-2025-30204"]

Threat ID: 6a160970e29bf47b50638546

Added to database: 05/26/2026, 20:58:24 UTC

Last enriched: 08/15/2026, 00:09:12 UTC

Last updated: 09/10/2026, 19:55:26 UTC

Views: 64

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2025:23534https://access.redhat.com/security/cve/CVE-2025-22868https://access.redhat.com/security/cve/CVE-2025-30204https://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2025:9541https://access.redhat.com/security/updates/classification/#important23483662354195Canonical URLhttps://access.redhat.com/errata/RHSA-2025:3051https://github.com/open-policy-agent/gatekeeper/releases/tag/v3.17.0https://github.com/open-policy-agent/gatekeeper/releases/tag/v3.17.1https://github.com/open-policy-agent/gatekeeper/releases/tag/v3.17.22348367ACM-18302ACM-18535HYPBLD-605Canonical URLhttps://access.redhat.com/errata/RHSA-2025:3172ACM-19030HYPBLD-617Canonical URLhttps://access.redhat.com/errata/RHSA-2025:3503Canonical URLhttps://access.redhat.com/errata/RHSA-2025:3814https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.1https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.1/html-single/release_notes/indexhttps://access.redhat.com/security/cve/CVE-2025-22869Canonical URLhttps://access.redhat.com/errata/RHSA-2025:3886https://access.redhat.com/security/cve/CVE-2025-26791https://docs.redhat.com/en/documentation/red_hat_openshift_ai/Canonical URLhttps://access.redhat.com/errata/RHSA-2025:3959ACM-19031HYPBLD-618Canonical URLhttps://access.redhat.com/errata/RHBA-2025:7674PROJQUAY-5172PROJQUAY-8673PROJQUAY-8680PROJQUAY-8683PROJQUAY-8716PROJQUAY-8740PROJQUAY-8771Canonical URLhttps://access.redhat.com/errata/RHSA-2025:3763ACM-18827ACM-19094Canonical URLReference 52Reference 53Reference 54Reference 55Reference 56Reference 57Reference 58Reference 59Reference 60Reference 61Reference 62Reference 63Reference 64Reference 65Reference 66Reference 67Reference 68Reference 69Reference 70Reference 71Reference 72Reference 73Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses