VDB
RHSA-2025%3A16595
RHSA-2025%3A16595
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in the golang-jwt implementation of JSON Web Tokens (JWT). In affected versions, a malicious request with specially crafted Authorization header data may trigger an excessive consumption of resources on the host system. This issue can cause significant performance degradation or an application crash, leading to a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/rhacm2/volsync-rhel9@sha256:f665abbb8dd8989c3ee3bfe62381806e33cdb8b63d49e9fc39c6f00e5af0e7bd_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | registry.redhat.io/rhacm2/volsync-rhel9@sha256:f665abbb8dd8989c3ee3bfe62381806e33cdb8b63d49e9fc39c6f00e5af0e7bd_arm64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:f665abbb8dd8989c3ee3bfe62381806e33cdb8b63d49e9fc39c6f00e5af0e7bd_arm64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:f665abbb8dd8989c3ee3bfe62381806e33cdb8b63d49e9fc39c6f00e5af0e7bd_arm64 |
| Red Hat | registry.redhat.io/rhacm2/volsync-rhel9@sha256:a69d63610ff0140e4d66c3c93a265b00783bfbc72702669cc6a5eb66494b0f11_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, registry.redhat.io/rhacm2/volsync-rhel9@sha256:a69d63610ff0140e4d66c3c93a265b00783bfbc72702669cc6a5eb66494b0f11_s390x, * |
| Red Hat | registry.redhat.io/rhacm2/volsync-rhel9@sha256:a69d63610ff0140e4d66c3c93a265b00783bfbc72702669cc6a5eb66494b0f11_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, registry.redhat.io/rhacm2/volsync-rhel9@sha256:a69d63610ff0140e4d66c3c93a265b00783bfbc72702669cc6a5eb66494b0f11_s390x, registry.redhat.io/rhacm2/volsync-rhel9@sha256:a69d63610ff0140e4d66c3c93a265b00783bfbc72702669cc6a5eb66494b0f11_s390x |
| Red Hat | registry.redhat.io/rhacm2/volsync-rhel9@sha256:2a327b9b391105704e0df7c7eeb53f70b2c50c5532fc0b2f58b91bcdb471f2f7_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | registry.redhat.io/rhacm2/volsync-rhel9@sha256:2a327b9b391105704e0df7c7eeb53f70b2c50c5532fc0b2f58b91bcdb471f2f7_ppc64le, registry.redhat.io/rhacm2/volsync-rhel9@sha256:2a327b9b391105704e0df7c7eeb53f70b2c50c5532fc0b2f58b91bcdb471f2f7_ppc64le, registry.redhat.io/rhacm2/volsync-rhel9@sha256:2a327b9b391105704e0df7c7eeb53f70b2c50c5532fc0b2f58b91bcdb471f2f7_ppc64le |
| Red Hat | registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:32cd9b5812506656ff9ff1c2c9fdacde44f179313ea2bfbbc18564fee635ca67_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:32cd9b5812506656ff9ff1c2c9fdacde44f179313ea2bfbbc18564fee635ca67_amd64, registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:32cd9b5812506656ff9ff1c2c9fdacde44f179313ea2bfbbc18564fee635ca67_amd64, registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:32cd9b5812506656ff9ff1c2c9fdacde44f179313ea2bfbbc18564fee635ca67_amd64 |
| Red Hat | registry.redhat.io/rhacm2/volsync-rhel9@sha256:d2226b5ec3e213aa92b18bf0d8c2d4d0f277fcbf7ad0c5b2fcbbfa72cf256269_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | registry.redhat.io/rhacm2/volsync-rhel9@sha256:d2226b5ec3e213aa92b18bf0d8c2d4d0f277fcbf7ad0c5b2fcbbfa72cf256269_amd64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:d2226b5ec3e213aa92b18bf0d8c2d4d0f277fcbf7ad0c5b2fcbbfa72cf256269_amd64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:d2226b5ec3e213aa92b18bf0d8c2d4d0f277fcbf7ad0c5b2fcbbfa72cf256269_amd64 |
| Red Hat | registry.redhat.io/rhacm2/volsync-rhel9@sha256:f665abbb8dd8989c3ee3bfe62381806e33cdb8b63d49e9fc39c6f00e5af0e7bd_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | registry.redhat.io/rhacm2/volsync-rhel9@sha256:f665abbb8dd8989c3ee3bfe62381806e33cdb8b63d49e9fc39c6f00e5af0e7bd_arm64, registry.redhat.io/rhacm2/volsync-rhel9@sha256:f665abbb8dd8989c3ee3bfe62381806e33cdb8b63d49e9fc39c6f00e5af0e7bd_arm64, * |
| Red Hat | registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:32cd9b5812506656ff9ff1c2c9fdacde44f179313ea2bfbbc18564fee635ca67_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, *, registry.redhat.io/rhacm2/volsync-operator-bundle@sha256:32cd9b5812506656ff9ff1c2c9fdacde44f179313ea2bfbbc18564fee635ca67_amd64 |
| Red Hat | registry.redhat.io/rhacm2/volsync-rhel9@sha256:2a327b9b391105704e0df7c7eeb53f70b2c50c5532fc0b2f58b91bcdb471f2f7_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | *, registry.redhat.io/rhacm2/volsync-rhel9@sha256:2a327b9b391105704e0df7c7eeb53f70b2c50c5532fc0b2f58b91bcdb471f2f7_ppc64le, registry.redhat.io/rhacm2/volsync-rhel9@sha256:2a327b9b391105704e0df7c7eeb53f70b2c50c5532fc0b2f58b91bcdb471f2f7_ppc64le |
| Red Hat | registry.redhat.io/rhacm2/volsync-rhel9@sha256:d2226b5ec3e213aa92b18bf0d8c2d4d0f277fcbf7ad0c5b2fcbbfa72cf256269_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14 | registry.redhat.io/rhacm2/volsync-rhel9@sha256:d2226b5ec3e213aa92b18bf0d8c2d4d0f277fcbf7ad0c5b2fcbbfa72cf256269_amd64, *, * |
Timeline
- Sep 24, 2025 CVE Published
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- May 16, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:16595 advisory
- https://access.redhat.com/security/cve/CVE-2025-30204 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_16595.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2354195 issue
- https://www.cve.org/CVERecord?id=CVE-2025-30204 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-30204 advisory
- https://github.com/golang-jwt/jwt/commit/0951d184286dece21f73c85673fd308786ffe9c3 advisory
- https://github.com/golang-jwt/jwt/security/advisories/GHSA-mh63-6h87-95cp advisory
- https://pkg.go.dev/vuln/GO-2025-3553 advisory