VDB
RHSA-2025%3A2700
RHSA-2025%3A2700
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in golang.org/x/net/html. This flaw allows an attacker to craft input to the parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This issue can cause a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-sriov-network-operator@sha256:06aab1af6dae652c4b34988f1205d7f34a5286c53cf7d4fcdfb85780d2f4bdc5_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-sriov-network-operator@sha256:06aab1af6dae652c4b34988f1205d7f34a5286c53cf7d4fcdfb85780d2f4bdc5_amd64 |
| Red Hat | openshift4/ose-ptp@sha256:89adf6c15ec9852388bc487ca14a030f535b37bbbbbbe1f1a28567545ea9e25d_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-egress-http-proxy@sha256:06051a1bcf77d309fd3b45cb02bdb9188dabe7178bef67acea9418c18a1afe2a_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-egress-http-proxy@sha256:06051a1bcf77d309fd3b45cb02bdb9188dabe7178bef67acea9418c18a1afe2a_amd64 |
| Red Hat | openshift4/ose-operator-sdk-rhel8@sha256:276d6a725a9a10639b80fdfd0d3e9a02e533b29b34f17ae9ca7d79c38101700d_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-cluster-nfd-operator@sha256:57d91503c7b43c97032f3514846235438a821f379fe9c677f252e7ff8dfadd4f_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-cluster-nfd-operator@sha256:57d91503c7b43c97032f3514846235438a821f379fe9c677f252e7ff8dfadd4f_amd64 |
| Red Hat | openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:0911b143fe2aa04606ad459d07bf6e7ff72125d5057644e1cce05cad2273dab1_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-gcp-filestore-csi-driver-rhel8@sha256:ef2201a5db3b7c61ffc037160360b8063c779a9a464e9d7c0e41e01a70a17b03_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:81bfe4c9e4fd10ac13d3516b93ac1ae90b29aef5a5c4580839552e6f6562fb66_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-sriov-infiniband-cni@sha256:194234bd6ca1d42416aad5d79857cddfc0014940335e8e3c6f3bd90419df7883_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | * |
| Red Hat | openshift4/ptp-must-gather-rhel8@sha256:8ca281b46e92cd6ba13212ed74a9e60ba6f32d09bba2b52ef6a147f4d0e08705_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-operator-sdk-rhel8@sha256:276d6a725a9a10639b80fdfd0d3e9a02e533b29b34f17ae9ca7d79c38101700d_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-operator-sdk-rhel8@sha256:276d6a725a9a10639b80fdfd0d3e9a02e533b29b34f17ae9ca7d79c38101700d_amd64 |
| Red Hat | openshift4/ose-node-feature-discovery@sha256:095a201004ad04eef16723be42e445da35874b0e46bdcad0d547dee2066a5797_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:c43e0fe4dda196e5dd5c56393be519b5a7897e07bd89de77b4c980c564e13e92_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:c43e0fe4dda196e5dd5c56393be519b5a7897e07bd89de77b4c980c564e13e92_amd64 |
| Red Hat | openshift4/ose-sriov-dp-admission-controller@sha256:77d8fb5a04dee73cbae28016c24ad070726c23a011edf9ab650ce0414cf350bb_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-local-storage-operator@sha256:5ca97ea653819810088592d79eafdfde0d266daa4db26ead30b8fa6d2365c846_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-egress-dns-proxy@sha256:56126a7755ec108e51c063c0ddf6b59a5afff17b68dc9f8f37575510e2d2e19d_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:62f775433ee8bc7d58babaf274a35ead4e88349c9811de6dd38cd743ecc89baa_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:62f775433ee8bc7d58babaf274a35ead4e88349c9811de6dd38cd743ecc89baa_amd64 |
| Red Hat | openshift4/ose-sriov-dp-admission-controller@sha256:77d8fb5a04dee73cbae28016c24ad070726c23a011edf9ab650ce0414cf350bb_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | * |
| Red Hat | openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:ae9bd2beecf80057431f7815b8eca50545edb2501ba235cb9fce3743559f3abb_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | * |
| Red Hat | openshift4/ose-ansible-operator@sha256:96f9aacbf76f85d57a0145079b7c90dd460a984c54884838b3a42ef56bf32cc3_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | openshift4/ose-ansible-operator@sha256:96f9aacbf76f85d57a0145079b7c90dd460a984c54884838b3a42ef56bf32cc3_amd64 |
…and 65 more
Timeline
- Mar 20, 2025 CVE Published
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Jul 13, 2026 CVE Updated
References
- https://pkg.go.dev/vuln/GO-2024-3333 advisory
- https://access.redhat.com/errata/RHSA-2025:2700 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2333856 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_2700.json advisory
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-45338 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45338 advisory
- https://go.dev/cl/637536 advisory
- https://go.dev/issue/70906 advisory
- https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJ advisory
- https://access.redhat.com/security/cve/CVE-2024-56326 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-56326 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-56326 advisory
- https://github.com/pallets/jinja/commit/48b0687e05a5466a91cd5812d604fa37ad0943b4 advisory
- https://github.com/pallets/jinja/releases/tag/3.1.5 advisory
- https://github.com/pallets/jinja/security/advisories/GHSA-q2x7-8rv6-6q7h advisory