VDB

RHSA-2025%3A16595

RHSA-2025%3A16595 PUBLISHED CVSS 7.5 HIGH

A flaw was found in the golang-jwt implementation of JSON Web Tokens (JWT). In affected versions, a malicious request with specially crafted Authorization header data may trigger an excessive consumption of resources on the host system. This issue can cause significant performance degradation or an application crash, leading to a denial of service.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatregistry.redhat.io/rhacm2/volsync-rhel9@sha256:f665abbb8dd8989c3ee3bfe62381806e33cdb8b63d49e9fc39c6f00e5af0e7bd_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14registry.redhat.io/rhacm2/volsync-rhel9@sha256:f665abbb8dd8989c3ee3bfe62381806e33cdb8b63d49e9fc39c6f00e5af0e7bd_arm64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:f665abbb8dd8989c3ee3bfe62381806e33cdb8b63d49e9fc39c6f00e5af0e7bd_arm64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:f665abbb8dd8989c3ee3bfe62381806e33cdb8b63d49e9fc39c6f00e5af0e7bd_arm64
Red Hatregistry.redhat.io/rhacm2/volsync-rhel9@sha256:a69d63610ff0140e4d66c3c93a265b00783bfbc72702669cc6a5eb66494b0f11_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14*, registry.redhat.io/rhacm2/volsync-rhel9@sha256:a69d63610ff0140e4d66c3c93a265b00783bfbc72702669cc6a5eb66494b0f11_s390x, *
Red Hatregistry.redhat.io/rhacm2/volsync-rhel9@sha256:a69d63610ff0140e4d66c3c93a265b00783bfbc72702669cc6a5eb66494b0f11_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14*, registry.redhat.io/rhacm2/volsync-rhel9@sha256:a69d63610ff0140e4d66c3c93a265b00783bfbc72702669cc6a5eb66494b0f11_s390x, registry.redhat.io/rhacm2/volsync-rhel9@sha256:a69d63610ff0140e4d66c3c93a265b00783bfbc72702669cc6a5eb66494b0f11_s390x
Red Hatregistry.redhat.io/rhacm2/volsync-rhel9@sha256:2a327b9b391105704e0df7c7eeb53f70b2c50c5532fc0b2f58b91bcdb471f2f7_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14registry.redhat.io/rhacm2/volsync-rhel9@sha256:2a327b9b391105704e0df7c7eeb53f70b2c50c5532fc0b2f58b91bcdb471f2f7_ppc64le, registry.redhat.io/rhacm2/volsync-rhel9@sha256:2a327b9b391105704e0df7c7eeb53f70b2c50c5532fc0b2f58b91bcdb471f2f7_ppc64le, registry.redhat.io/rhacm2/volsync-rhel9@sha256:2a327b9b391105704e0df7c7eeb53f70b2c50c5532fc0b2f58b91bcdb471f2f7_ppc64le
Red Hatregistry.redhat.io/rhacm2/volsync-operator-bundle@sha256:32cd9b5812506656ff9ff1c2c9fdacde44f179313ea2bfbbc18564fee635ca67_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:32cd9b5812506656ff9ff1c2c9fdacde44f179313ea2bfbbc18564fee635ca67_amd64, registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:32cd9b5812506656ff9ff1c2c9fdacde44f179313ea2bfbbc18564fee635ca67_amd64, registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:32cd9b5812506656ff9ff1c2c9fdacde44f179313ea2bfbbc18564fee635ca67_amd64
Red Hatregistry.redhat.io/rhacm2/volsync-rhel9@sha256:d2226b5ec3e213aa92b18bf0d8c2d4d0f277fcbf7ad0c5b2fcbbfa72cf256269_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14registry.redhat.io/rhacm2/volsync-rhel9@sha256:d2226b5ec3e213aa92b18bf0d8c2d4d0f277fcbf7ad0c5b2fcbbfa72cf256269_amd64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:d2226b5ec3e213aa92b18bf0d8c2d4d0f277fcbf7ad0c5b2fcbbfa72cf256269_amd64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:d2226b5ec3e213aa92b18bf0d8c2d4d0f277fcbf7ad0c5b2fcbbfa72cf256269_amd64
Red Hatregistry.redhat.io/rhacm2/volsync-rhel9@sha256:f665abbb8dd8989c3ee3bfe62381806e33cdb8b63d49e9fc39c6f00e5af0e7bd_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14registry.redhat.io/rhacm2/volsync-rhel9@sha256:f665abbb8dd8989c3ee3bfe62381806e33cdb8b63d49e9fc39c6f00e5af0e7bd_arm64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:f665abbb8dd8989c3ee3bfe62381806e33cdb8b63d49e9fc39c6f00e5af0e7bd_arm64, *
Red Hatregistry.redhat.io/rhacm2/volsync-operator-bundle@sha256:32cd9b5812506656ff9ff1c2c9fdacde44f179313ea2bfbbc18564fee635ca67_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14*, *, registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:32cd9b5812506656ff9ff1c2c9fdacde44f179313ea2bfbbc18564fee635ca67_amd64
Red Hatregistry.redhat.io/rhacm2/volsync-rhel9@sha256:2a327b9b391105704e0df7c7eeb53f70b2c50c5532fc0b2f58b91bcdb471f2f7_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14*, registry.redhat.io/rhacm2/volsync-rhel9@sha256:2a327b9b391105704e0df7c7eeb53f70b2c50c5532fc0b2f58b91bcdb471f2f7_ppc64le, registry.redhat.io/rhacm2/volsync-rhel9@sha256:2a327b9b391105704e0df7c7eeb53f70b2c50c5532fc0b2f58b91bcdb471f2f7_ppc64le
Red Hatregistry.redhat.io/rhacm2/volsync-rhel9@sha256:d2226b5ec3e213aa92b18bf0d8c2d4d0f277fcbf7ad0c5b2fcbbfa72cf256269_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14registry.redhat.io/rhacm2/volsync-rhel9@sha256:d2226b5ec3e213aa92b18bf0d8c2d4d0f277fcbf7ad0c5b2fcbbfa72cf256269_amd64, *, *

Timeline

  • Sep 24, 2025 CVE Published
  • Apr 24, 2026 Distribution Patch
  • Apr 24, 2026 Distribution Patch
  • Apr 24, 2026 Security Advisory
  • Apr 24, 2026 Security Advisory
  • May 16, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›