VDB
RHSA-2025%3A0121
RHSA-2025%3A0121
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in golang.org/x/net/html. This flaw allows an attacker to craft input to the parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This issue can cause a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-kube-rbac-proxy@sha256:432e75912b2dbc115c3a738eac3ed175bc5e40222c0b403c3e25553539ed1f69_s390x as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/ose-kube-rbac-proxy@sha256:432e75912b2dbc115c3a738eac3ed175bc5e40222c0b403c3e25553539ed1f69_s390x |
| Red Hat | openshift4/ose-csi-driver-manila-rhel8-operator@sha256:bae9bdbf1eb8d1b381d4e4f318566cbb2865864aff8b70a46b7513e9593766cb_ppc64le as a component of Red Hat OpenShift Container Platform 4.15 | *, * |
| Red Hat | openshift4/ose-monitoring-plugin-rhel8@sha256:be85e4962eee59d315e7ea4a7b3494970d31608d5486f03dc441e01bd9184aa1_arm64 as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/ose-monitoring-plugin-rhel8@sha256:be85e4962eee59d315e7ea4a7b3494970d31608d5486f03dc441e01bd9184aa1_arm64 |
| Red Hat | openshift4/ose-thanos-rhel8@sha256:4c21eca99bf50079cd223ece1a21177644bc118cf7ae2155a955996aeb7d4aab_s390x as a component of Red Hat OpenShift Container Platform 4.15 | *, * |
| Red Hat | openshift4/ose-prom-label-proxy@sha256:312d4285f0d2cf6224a7ee24bf7d7d6100bba7ed120ca4599313e5ac79baa0d3_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/ose-prom-label-proxy@sha256:312d4285f0d2cf6224a7ee24bf7d7d6100bba7ed120ca4599313e5ac79baa0d3_amd64 |
| Red Hat | openshift4/ose-insights-rhel9-operator@sha256:aa6e861d65b267092acb44164799a6b99465825a4d2a58c413131d4a6a716efd_s390x as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/ose-insights-rhel9-operator@sha256:aa6e861d65b267092acb44164799a6b99465825a4d2a58c413131d4a6a716efd_s390x |
| Red Hat | openshift4/ose-tests@sha256:40f51b62f58b39aa58e0affd9db5cd868c4f40cc1dfad94310f3c50fd0f9b40d_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/ose-tests@sha256:40f51b62f58b39aa58e0affd9db5cd868c4f40cc1dfad94310f3c50fd0f9b40d_amd64 |
| Red Hat | openshift4/ose-azure-workload-identity-webhook-rhel8@sha256:e480905bbe8b9c34a1b453fa2e1b0fbd6a594a9108149c9a5b75dedbc360dfe6_arm64 as a component of Red Hat OpenShift Container Platform 4.15 | *, * |
| Red Hat | openshift4/ose-installer-altinfra-rhel8@sha256:34c593dd2d5db12769bee021e390fa06b6e12f2e75e3cb54e945e85c6918a605_arm64 as a component of Red Hat OpenShift Container Platform 4.15 | *, * |
| Red Hat | openshift4/ose-deployer@sha256:e54c6e825c9086f4fae4eac561f1032dfc4fec8076450447306455db6cc97c77_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | *, * |
| Red Hat | openshift4/ose-agent-installer-orchestrator-rhel8@sha256:594e18a9f33fb784a30bb511a31069b65c007b9975cc3458a1cc589b002cc11d_s390x as a component of Red Hat OpenShift Container Platform 4.15 | *, * |
| Red Hat | openshift4/ose-cli-artifacts@sha256:8f2e863c6105ad391ffe7f73bca0a44c45acb0fdd79800eece1a1581f2170e09_s390x as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/ose-cli-artifacts@sha256:8f2e863c6105ad391ffe7f73bca0a44c45acb0fdd79800eece1a1581f2170e09_s390x |
| Red Hat | openshift4/ose-multus-route-override-cni-rhel8@sha256:a7356089863494b5a6e53516b424e5640dd2d5c5e52830e614f61f04efcf6860_arm64 as a component of Red Hat OpenShift Container Platform 4.15 | * |
| Red Hat | openshift4/ose-csi-driver-shared-resource-operator-rhel8@sha256:1ce790a2d5dfab3ce580885b956273bc6c291b0ab6366dfe622a0e74c849af87_arm64 as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/ose-csi-driver-shared-resource-operator-rhel8@sha256:1ce790a2d5dfab3ce580885b956273bc6c291b0ab6366dfe622a0e74c849af87_arm64 |
| Red Hat | openshift4/ose-vsphere-csi-driver-operator-rhel8@sha256:3062f4b7686100bfc62389aa38188e80ddb6d27b434579c79d2284325e7ff3e3_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | *, * |
| Red Hat | openshift4/ose-openstack-cluster-api-controllers-rhel8@sha256:e538ec0927e78536589b9adc4a54e0141d1cbf6788e729f3b316ffb7f106f34b_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | *, * |
| Red Hat | openshift4/ose-kube-proxy-rhel9@sha256:ccd8d03a9bfa9f00315b4f45cda2f79d2302d47fd070f085c9131739bbe50d22_arm64 as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/ose-kube-proxy-rhel9@sha256:ccd8d03a9bfa9f00315b4f45cda2f79d2302d47fd070f085c9131739bbe50d22_arm64 |
| Red Hat | openshift4/ose-kube-rbac-proxy@sha256:c7cdcc60cc82b377b16480c2ba028c4d8734814aae243d46b2345434dea1d611_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/ose-kube-rbac-proxy@sha256:c7cdcc60cc82b377b16480c2ba028c4d8734814aae243d46b2345434dea1d611_amd64 |
| Red Hat | openshift4/ose-csi-external-provisioner-rhel8@sha256:be21524d5739761dfb8b53431c30a15a9951c41f3a50b965362cdff97949545c_arm64 as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/ose-csi-external-provisioner-rhel8@sha256:be21524d5739761dfb8b53431c30a15a9951c41f3a50b965362cdff97949545c_arm64 |
| Red Hat | openshift4/ose-machine-api-rhel9-operator@sha256:9700cac610a12d5ff0c60d70f823dcfd27814ce94887e784fea850f2e2c20de4_ppc64le as a component of Red Hat OpenShift Container Platform 4.15 | openshift4/ose-machine-api-rhel9-operator@sha256:9700cac610a12d5ff0c60d70f823dcfd27814ce94887e784fea850f2e2c20de4_ppc64le |
…and 525 more
Timeline
- Jan 15, 2025 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Jul 19, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:0121 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://issues.redhat.com/browse/OCPBUGS-45204 advisory
- https://issues.redhat.com/browse/OCPBUGS-46075 advisory
- https://issues.redhat.com/browse/OCPBUGS-46080 advisory
- https://issues.redhat.com/browse/OCPBUGS-46430 advisory
- https://issues.redhat.com/browse/OCPBUGS-46525 advisory
- https://issues.redhat.com/browse/OCPBUGS-46576 advisory
- https://issues.redhat.com/browse/OCPBUGS-47520 advisory
- https://issues.redhat.com/browse/OCPBUGS-47534 advisory
- https://issues.redhat.com/browse/OCPBUGS-47646 advisory
- https://issues.redhat.com/browse/OCPBUGS-47680 advisory
- https://issues.redhat.com/browse/OCPBUGS-48105 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_0121.json advisory
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-45338 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45338 advisory
- https://go.dev/cl/637536 advisory
- https://go.dev/issue/70906 advisory
…and 2 more