VDB
RHSA-2025%3A1119
RHSA-2025%3A1119
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in golang.org/x/net/html. This flaw allows an attacker to craft input to the parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This issue can cause a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-local-storage-rhel9-operator@sha256:8bfe6ace2f4be3848ea204a705d791d0f2bfb966909a538f22c828728238d319_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | *, *, * |
| Red Hat | openshift4/ptp-must-gather-rhel9@sha256:f455859949594480bcb9b8e394343f85824197857b25e759905b22e6215e493f_amd64 as a component of Red Hat OpenShift Container Platform 4.17 | openshift4/ptp-must-gather-rhel9@sha256:f455859949594480bcb9b8e394343f85824197857b25e759905b22e6215e493f_amd64, openshift4/ptp-must-gather-rhel9@sha256:f455859949594480bcb9b8e394343f85824197857b25e759905b22e6215e493f_amd64 |
| Red Hat | openshift4/metallb-rhel9-operator@sha256:5ee9294a12e5d60b15ee0838b3cd6b87410834d2b3b597cef6da1d41a447a2de_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | *, openshift4/metallb-rhel9-operator@sha256:5ee9294a12e5d60b15ee0838b3cd6b87410834d2b3b597cef6da1d41a447a2de_arm64 |
| Red Hat | OpenShift Container Platform | |
| Red Hat | openshift4/ose-operator-sdk-rhel9@sha256:e3205b40d1b837d61d3fef16c2d304a7302bc05fa30d0d53fcf2d64dd597cbf7_amd64 as a component of Red Hat OpenShift Container Platform 4.17 | *, * |
| Red Hat | openshift4/ose-sriov-network-webhook-rhel9@sha256:f2e16bd06fe8a98901d1f13439a417d2b95bea2e7a5ad811db2628de4a024dd3_amd64 as a component of Red Hat OpenShift Container Platform 4.17 | *, *, * |
| Red Hat | openshift4/ose-sriov-network-webhook-rhel9@sha256:f2e16bd06fe8a98901d1f13439a417d2b95bea2e7a5ad811db2628de4a024dd3_amd64 as a component of Red Hat OpenShift Container Platform 4.17 | openshift4/ose-sriov-network-webhook-rhel9@sha256:f2e16bd06fe8a98901d1f13439a417d2b95bea2e7a5ad811db2628de4a024dd3_amd64, openshift4/ose-sriov-network-webhook-rhel9@sha256:f2e16bd06fe8a98901d1f13439a417d2b95bea2e7a5ad811db2628de4a024dd3_amd64 |
| Red Hat | openshift4/ose-csi-driver-shared-resource-mustgather-rhel9@sha256:dac7a47f140321bdc554325a34c77cf5369d399834240a7959482fbb25b52ef7_s390x as a component of Red Hat OpenShift Container Platform 4.17 | *, *, * |
| Red Hat | openshift4/ose-secrets-store-csi-mustgather-rhel9@sha256:400a9ac28ef61e7b6c25ce939183eb60f634a44990f0d0654f47d8ff781b229e_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | *, *, * |
| Red Hat | openshift4/ose-sriov-network-config-daemon-rhel9@sha256:a901c4f12ab7640b85283c54dc059001cf4dbcfb93d89fc0c110d21361b72bfb_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | *, *, * |
| Red Hat | openshift4/ose-sriov-network-config-daemon-rhel9@sha256:a1e5aed89962552881d38c933a53a816b8655ca4c856507996561dade257227d_ppc64le as a component of Red Hat OpenShift Container Platform 4.17 | *, *, * |
| Red Hat | openshift4/metallb-rhel9-operator@sha256:ad79ec41f761e8f44955f623b760fb01955bcee48afa20c17d0f362349372cf4_s390x as a component of Red Hat OpenShift Container Platform 4.17 | openshift4/metallb-rhel9-operator@sha256:ad79ec41f761e8f44955f623b760fb01955bcee48afa20c17d0f362349372cf4_s390x, openshift4/metallb-rhel9-operator@sha256:ad79ec41f761e8f44955f623b760fb01955bcee48afa20c17d0f362349372cf4_s390x |
| Red Hat | openshift4/kube-compare-artifacts-rhel9@sha256:1a4b823bb17287ae51b3d7770e0f14975b962276383573db6c2d79d1a9fd9636_amd64 as a component of Red Hat OpenShift Container Platform 4.17 | *, *, * |
| Red Hat | openshift4/ose-local-storage-rhel9-operator@sha256:7cde8ea58b6bca97a66b4f55ce8a9fccd567f869288c0574e2cbd28c343cf45f_s390x as a component of Red Hat OpenShift Container Platform 4.17 | openshift4/ose-local-storage-rhel9-operator@sha256:7cde8ea58b6bca97a66b4f55ce8a9fccd567f869288c0574e2cbd28c343cf45f_s390x, openshift4/ose-local-storage-rhel9-operator@sha256:7cde8ea58b6bca97a66b4f55ce8a9fccd567f869288c0574e2cbd28c343cf45f_s390x |
| Red Hat | openshift4/ose-aws-efs-csi-driver-rhel9-operator@sha256:4e41138d77ce09c459970d0de4fa53b72eaf62da154e389bf18ab6d70b1f63fc_amd64 as a component of Red Hat OpenShift Container Platform 4.17 | *, *, * |
| Red Hat | openshift4/ose-secrets-store-csi-mustgather-rhel9@sha256:400a9ac28ef61e7b6c25ce939183eb60f634a44990f0d0654f47d8ff781b229e_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | openshift4/ose-secrets-store-csi-mustgather-rhel9@sha256:400a9ac28ef61e7b6c25ce939183eb60f634a44990f0d0654f47d8ff781b229e_arm64, openshift4/ose-secrets-store-csi-mustgather-rhel9@sha256:400a9ac28ef61e7b6c25ce939183eb60f634a44990f0d0654f47d8ff781b229e_arm64 |
| Red Hat | openshift4/ose-csi-driver-shared-resource-mustgather-rhel9@sha256:2c9493a94535682db564c76d3f9d21cc707075a0c6aed619a01ca0fcbc297031_ppc64le as a component of Red Hat OpenShift Container Platform 4.17 | *, *, * |
| Red Hat | openshift4/ptp-must-gather-rhel9@sha256:7632d692fae57120e2a6149a3a95fc70e45b17c993bf7e258a120aef54ec4573_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | *, *, * |
| Red Hat | openshift4/ose-secrets-store-csi-driver-rhel9-operator@sha256:d957a9db284d307030e2455e6216ae49f920970800ced74056f25dbc0b52892b_ppc64le as a component of Red Hat OpenShift Container Platform 4.17 | *, *, * |
| Red Hat | openshift4/ose-operator-sdk-rhel9@sha256:24c0960f3e30a43373e26c8929c17b9cbe2d721e97ee17603f13045a494261ba_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | *, *, * |
…and 83 more
Timeline
- Feb 11, 2025 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
- Jul 13, 2026 Security Advisory
- Jul 13, 2026 Security Advisory
- Jul 19, 2026 CVE Updated
References
- https://www.cve.org/CVERecord?id=CVE-2024-45338 advisory
- https://go.dev/cl/637536 advisory
- https://go.dev/issue/70906 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1119.json advisory
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-21613 advisory
- https://access.redhat.com/errata/RHSA-2025:1119 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://access.redhat.com/security/cve/CVE-2025-21613 advisory
- https://github.com/go-git/go-git/security/advisories/GHSA-v725-9546-7q7m advisory
- https://www.cve.org/CVERecord?id=CVE-2025-21614 advisory
- https://pkg.go.dev/vuln/GO-2025-3367 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2335888 issue
- https://access.redhat.com/security/cve/CVE-2025-21614 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2335901 issue
- https://nvd.nist.gov/vuln/detail/CVE-2024-45338 advisory
- https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJ advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-21614 advisory
- https://pkg.go.dev/vuln/GO-2024-3333 advisory
…and 3 more