VDB
RHSA-2025%3A15872
RHSA-2025%3A15872
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in the golang-jwt implementation of JSON Web Tokens (JWT). In affected versions, a malicious request with specially crafted Authorization header data may trigger an excessive consumption of resources on the host system. This issue can cause significant performance degradation or an application crash, leading to a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/rhacm2/volsync-rhel9@sha256:45062a944d954154413191d2678924296122ff595da5facf7d4b3d127887032e_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13 | *, registry.redhat.io/rhacm2/volsync-rhel9@sha256:45062a944d954154413191d2678924296122ff595da5facf7d4b3d127887032e_s390x, registry.redhat.io/rhacm2/volsync-rhel9@sha256:45062a944d954154413191d2678924296122ff595da5facf7d4b3d127887032e_s390x |
| Red Hat | registry.redhat.io/rhacm2/volsync-rhel9@sha256:e3ea8237c2dc7ca0443c06e432c66a5938ce360733887ceb0d4accaf2e1852f1_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13 | registry.redhat.io/rhacm2/volsync-rhel9@sha256:e3ea8237c2dc7ca0443c06e432c66a5938ce360733887ceb0d4accaf2e1852f1_ppc64le, registry.redhat.io/rhacm2/volsync-rhel9@sha256:e3ea8237c2dc7ca0443c06e432c66a5938ce360733887ceb0d4accaf2e1852f1_ppc64le, registry.redhat.io/rhacm2/volsync-rhel9@sha256:e3ea8237c2dc7ca0443c06e432c66a5938ce360733887ceb0d4accaf2e1852f1_ppc64le |
| Red Hat | registry.redhat.io/rhacm2/volsync-rhel9@sha256:dec387317abbe8f550227d41a8b5cf48b054c31d077c818de7cc6b927e04295d_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13 | registry.redhat.io/rhacm2/volsync-rhel9@sha256:dec387317abbe8f550227d41a8b5cf48b054c31d077c818de7cc6b927e04295d_amd64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:dec387317abbe8f550227d41a8b5cf48b054c31d077c818de7cc6b927e04295d_amd64, * |
| Red Hat | registry.redhat.io/rhacm2/volsync-rhel9@sha256:0aab427ffab7d0adc213f28ff5d3b046a1e452c40fd74f62741fef7e1ed7c1b5_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13 | registry.redhat.io/rhacm2/volsync-rhel9@sha256:0aab427ffab7d0adc213f28ff5d3b046a1e452c40fd74f62741fef7e1ed7c1b5_arm64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:0aab427ffab7d0adc213f28ff5d3b046a1e452c40fd74f62741fef7e1ed7c1b5_arm64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:0aab427ffab7d0adc213f28ff5d3b046a1e452c40fd74f62741fef7e1ed7c1b5_arm64 |
| Red Hat | registry.redhat.io/rhacm2/volsync-rhel9@sha256:e3ea8237c2dc7ca0443c06e432c66a5938ce360733887ceb0d4accaf2e1852f1_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13 | registry.redhat.io/rhacm2/volsync-rhel9@sha256:e3ea8237c2dc7ca0443c06e432c66a5938ce360733887ceb0d4accaf2e1852f1_ppc64le, registry.redhat.io/rhacm2/volsync-rhel9@sha256:e3ea8237c2dc7ca0443c06e432c66a5938ce360733887ceb0d4accaf2e1852f1_ppc64le, registry.redhat.io/rhacm2/volsync-rhel9@sha256:e3ea8237c2dc7ca0443c06e432c66a5938ce360733887ceb0d4accaf2e1852f1_ppc64le |
| Red Hat | registry.redhat.io/rhacm2/volsync-rhel9@sha256:0aab427ffab7d0adc213f28ff5d3b046a1e452c40fd74f62741fef7e1ed7c1b5_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13 | *, *, registry.redhat.io/rhacm2/volsync-rhel9@sha256:0aab427ffab7d0adc213f28ff5d3b046a1e452c40fd74f62741fef7e1ed7c1b5_arm64 |
| Red Hat | registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:7de09e5394985cdec87f5afab65b3343b8a37c0eb7f778774b21933ae69d691c_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13 | registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:7de09e5394985cdec87f5afab65b3343b8a37c0eb7f778774b21933ae69d691c_amd64, *, * |
| Red Hat | registry.redhat.io/rhacm2/volsync-rhel9@sha256:dec387317abbe8f550227d41a8b5cf48b054c31d077c818de7cc6b927e04295d_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13 | registry.redhat.io/rhacm2/volsync-rhel9@sha256:dec387317abbe8f550227d41a8b5cf48b054c31d077c818de7cc6b927e04295d_amd64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:dec387317abbe8f550227d41a8b5cf48b054c31d077c818de7cc6b927e04295d_amd64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:dec387317abbe8f550227d41a8b5cf48b054c31d077c818de7cc6b927e04295d_amd64 |
| Red Hat | registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:7de09e5394985cdec87f5afab65b3343b8a37c0eb7f778774b21933ae69d691c_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13 | registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:7de09e5394985cdec87f5afab65b3343b8a37c0eb7f778774b21933ae69d691c_amd64, registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:7de09e5394985cdec87f5afab65b3343b8a37c0eb7f778774b21933ae69d691c_amd64, registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:7de09e5394985cdec87f5afab65b3343b8a37c0eb7f778774b21933ae69d691c_amd64 |
| Red Hat | registry.redhat.io/rhacm2/volsync-rhel9@sha256:45062a944d954154413191d2678924296122ff595da5facf7d4b3d127887032e_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13 | *, registry.redhat.io/rhacm2/volsync-rhel9@sha256:45062a944d954154413191d2678924296122ff595da5facf7d4b3d127887032e_s390x, registry.redhat.io/rhacm2/volsync-rhel9@sha256:45062a944d954154413191d2678924296122ff595da5facf7d4b3d127887032e_s390x |
Timeline
- Sep 15, 2025 CVE Published
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- May 16, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:15872 advisory
- https://access.redhat.com/security/cve/CVE-2025-30204 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_15872.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2354195 issue
- https://www.cve.org/CVERecord?id=CVE-2025-30204 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-30204 advisory
- https://github.com/golang-jwt/jwt/commit/0951d184286dece21f73c85673fd308786ffe9c3 advisory
- https://github.com/golang-jwt/jwt/security/advisories/GHSA-mh63-6h87-95cp advisory
- https://pkg.go.dev/vuln/GO-2025-3553 advisory