VDB

RHSA-2025%3A15872

RHSA-2025%3A15872 PUBLISHED CVSS 7.5 HIGH

A flaw was found in the golang-jwt implementation of JSON Web Tokens (JWT). In affected versions, a malicious request with specially crafted Authorization header data may trigger an excessive consumption of resources on the host system. This issue can cause significant performance degradation or an application crash, leading to a denial of service.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatregistry.redhat.io/rhacm2/volsync-rhel9@sha256:45062a944d954154413191d2678924296122ff595da5facf7d4b3d127887032e_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13*, registry.redhat.io/rhacm2/volsync-rhel9@sha256:45062a944d954154413191d2678924296122ff595da5facf7d4b3d127887032e_s390x, registry.redhat.io/rhacm2/volsync-rhel9@sha256:45062a944d954154413191d2678924296122ff595da5facf7d4b3d127887032e_s390x
Red Hatregistry.redhat.io/rhacm2/volsync-rhel9@sha256:e3ea8237c2dc7ca0443c06e432c66a5938ce360733887ceb0d4accaf2e1852f1_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13registry.redhat.io/rhacm2/volsync-rhel9@sha256:e3ea8237c2dc7ca0443c06e432c66a5938ce360733887ceb0d4accaf2e1852f1_ppc64le, registry.redhat.io/rhacm2/volsync-rhel9@sha256:e3ea8237c2dc7ca0443c06e432c66a5938ce360733887ceb0d4accaf2e1852f1_ppc64le, registry.redhat.io/rhacm2/volsync-rhel9@sha256:e3ea8237c2dc7ca0443c06e432c66a5938ce360733887ceb0d4accaf2e1852f1_ppc64le
Red Hatregistry.redhat.io/rhacm2/volsync-rhel9@sha256:dec387317abbe8f550227d41a8b5cf48b054c31d077c818de7cc6b927e04295d_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13registry.redhat.io/rhacm2/volsync-rhel9@sha256:dec387317abbe8f550227d41a8b5cf48b054c31d077c818de7cc6b927e04295d_amd64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:dec387317abbe8f550227d41a8b5cf48b054c31d077c818de7cc6b927e04295d_amd64, *
Red Hatregistry.redhat.io/rhacm2/volsync-rhel9@sha256:0aab427ffab7d0adc213f28ff5d3b046a1e452c40fd74f62741fef7e1ed7c1b5_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13registry.redhat.io/rhacm2/volsync-rhel9@sha256:0aab427ffab7d0adc213f28ff5d3b046a1e452c40fd74f62741fef7e1ed7c1b5_arm64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:0aab427ffab7d0adc213f28ff5d3b046a1e452c40fd74f62741fef7e1ed7c1b5_arm64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:0aab427ffab7d0adc213f28ff5d3b046a1e452c40fd74f62741fef7e1ed7c1b5_arm64
Red Hatregistry.redhat.io/rhacm2/volsync-rhel9@sha256:e3ea8237c2dc7ca0443c06e432c66a5938ce360733887ceb0d4accaf2e1852f1_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13registry.redhat.io/rhacm2/volsync-rhel9@sha256:e3ea8237c2dc7ca0443c06e432c66a5938ce360733887ceb0d4accaf2e1852f1_ppc64le, registry.redhat.io/rhacm2/volsync-rhel9@sha256:e3ea8237c2dc7ca0443c06e432c66a5938ce360733887ceb0d4accaf2e1852f1_ppc64le, registry.redhat.io/rhacm2/volsync-rhel9@sha256:e3ea8237c2dc7ca0443c06e432c66a5938ce360733887ceb0d4accaf2e1852f1_ppc64le
Red Hatregistry.redhat.io/rhacm2/volsync-rhel9@sha256:0aab427ffab7d0adc213f28ff5d3b046a1e452c40fd74f62741fef7e1ed7c1b5_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13*, *, registry.redhat.io/rhacm2/volsync-rhel9@sha256:0aab427ffab7d0adc213f28ff5d3b046a1e452c40fd74f62741fef7e1ed7c1b5_arm64
Red Hatregistry.redhat.io/rhacm2/volsync-operator-bundle@sha256:7de09e5394985cdec87f5afab65b3343b8a37c0eb7f778774b21933ae69d691c_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:7de09e5394985cdec87f5afab65b3343b8a37c0eb7f778774b21933ae69d691c_amd64, *, *
Red Hatregistry.redhat.io/rhacm2/volsync-rhel9@sha256:dec387317abbe8f550227d41a8b5cf48b054c31d077c818de7cc6b927e04295d_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13registry.redhat.io/rhacm2/volsync-rhel9@sha256:dec387317abbe8f550227d41a8b5cf48b054c31d077c818de7cc6b927e04295d_amd64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:dec387317abbe8f550227d41a8b5cf48b054c31d077c818de7cc6b927e04295d_amd64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:dec387317abbe8f550227d41a8b5cf48b054c31d077c818de7cc6b927e04295d_amd64
Red Hatregistry.redhat.io/rhacm2/volsync-operator-bundle@sha256:7de09e5394985cdec87f5afab65b3343b8a37c0eb7f778774b21933ae69d691c_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:7de09e5394985cdec87f5afab65b3343b8a37c0eb7f778774b21933ae69d691c_amd64, registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:7de09e5394985cdec87f5afab65b3343b8a37c0eb7f778774b21933ae69d691c_amd64, registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:7de09e5394985cdec87f5afab65b3343b8a37c0eb7f778774b21933ae69d691c_amd64
Red Hatregistry.redhat.io/rhacm2/volsync-rhel9@sha256:45062a944d954154413191d2678924296122ff595da5facf7d4b3d127887032e_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13*, registry.redhat.io/rhacm2/volsync-rhel9@sha256:45062a944d954154413191d2678924296122ff595da5facf7d4b3d127887032e_s390x, registry.redhat.io/rhacm2/volsync-rhel9@sha256:45062a944d954154413191d2678924296122ff595da5facf7d4b3d127887032e_s390x

Timeline

  • Sep 15, 2025 CVE Published
  • Apr 24, 2026 Distribution Patch
  • Apr 24, 2026 Distribution Patch
  • Apr 24, 2026 Security Advisory
  • Apr 24, 2026 Security Advisory
  • May 16, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›