VDB
RHSA-2025:0783
RHSA-2025:0783
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in golang.org/x/net/html. This flaw allows an attacker to craft input to the parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This issue can cause a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | odf4/cephcsi-rhel9@sha256:f3d8c9e20bbb0e6198e75f9e43e3202a1c0d544916edf8bd0f8d1972aef2d3c3_s390x as a component of RHODF 4.16 for RHEL 9 | *, *, * |
| Red Hat | odf4/odr-cluster-operator-bundle@sha256:b2001d35131d7e51fc0e2a02c86fc9ce9dcf833d1c7958d42f0aa70731dd4d08_s390x as a component of RHODF 4.16 for RHEL 9 | *, *, * |
| Red Hat | odf4/ocs-operator-bundle@sha256:88a7095400493903bd2df6b5ddc1e629a9286db6d8a180d2cd395f16b3e6e886_ppc64le as a component of RHODF 4.16 for RHEL 9 | *, *, * |
| Red Hat | odf4/odf-must-gather-rhel9@sha256:1cad0fbcc7146417853677c49fa9b1389ab8c274667208e5e35def8b6a741283_amd64 as a component of RHODF 4.16 for RHEL 9 | odf4/odf-must-gather-rhel9@sha256:1cad0fbcc7146417853677c49fa9b1389ab8c274667208e5e35def8b6a741283_amd64 |
| Red Hat | odf4/odf-csi-addons-sidecar-rhel9@sha256:311a882ed3300b40f40985549ceb3dde78a641da3efed632932075a140688570_s390x as a component of RHODF 4.16 for RHEL 9 | odf4/odf-csi-addons-sidecar-rhel9@sha256:311a882ed3300b40f40985549ceb3dde78a641da3efed632932075a140688570_s390x |
| Red Hat | odf4/ocs-metrics-exporter-rhel9@sha256:510c076c42564181e0dbf8e42c2d4445a9435a7c271625efb7ebbb5a25286c8a_amd64 as a component of RHODF 4.16 for RHEL 9 | *, *, * |
| Red Hat | odf4/odr-hub-operator-bundle@sha256:227f57d2484030db7832b06e2faf627da3b6f2354a570d41138be4547970b890_ppc64le as a component of RHODF 4.16 for RHEL 9 | *, *, * |
| Red Hat | odf4/mcg-rhel9-operator@sha256:4d1b0885a032eb0386b52dc2e4b63269805be8b72e723b3eb47c064bfae52eba_arm64 as a component of RHODF 4.16 for RHEL 9 | odf4/mcg-rhel9-operator@sha256:4d1b0885a032eb0386b52dc2e4b63269805be8b72e723b3eb47c064bfae52eba_arm64 |
| Red Hat | odf4/ocs-operator-bundle@sha256:3012cee1ce523cbd10a9e9ab51ac05aaff26e627567cdbb73d5c338731563f1d_s390x as a component of RHODF 4.16 for RHEL 9 | *, *, * |
| Red Hat | odf4/odf-multicluster-operator-bundle@sha256:35ec37b855a9d89ae5cdc475e086ec9c6110c3e095c3853f15884afcce983adf_s390x as a component of RHODF 4.16 for RHEL 9 | odf4/odf-multicluster-operator-bundle@sha256:35ec37b855a9d89ae5cdc475e086ec9c6110c3e095c3853f15884afcce983adf_s390x |
| Red Hat | odf4/mcg-core-rhel9@sha256:9e7ebf4fe650f9d5c878dfc2198cc508490c183c4a3465599e34dc70f3b70f8d_s390x as a component of RHODF 4.16 for RHEL 9 | odf4/mcg-core-rhel9@sha256:9e7ebf4fe650f9d5c878dfc2198cc508490c183c4a3465599e34dc70f3b70f8d_s390x |
| Red Hat | odf4/odf-operator-bundle@sha256:b4097595f23e4b61dd089979becd35160c9569accac73c8d887717ff21bcba19_ppc64le as a component of RHODF 4.16 for RHEL 9 | *, *, * |
| Red Hat | odf4/odf-operator-bundle@sha256:884d9589f14d72f1aa67f8c1f197dca8865f6d9386f6826672978442ca361123_s390x as a component of RHODF 4.16 for RHEL 9 | *, *, * |
| Red Hat | odf4/odf-multicluster-console-rhel9@sha256:ef2c518c580fb92679d42c9e29de4f3ebac2b8e18d855a836e229f1a92f2ca32_s390x as a component of RHODF 4.16 for RHEL 9 | odf4/odf-multicluster-console-rhel9@sha256:ef2c518c580fb92679d42c9e29de4f3ebac2b8e18d855a836e229f1a92f2ca32_s390x |
| Red Hat | odf4/cephcsi-rhel9@sha256:45e01453d7b4b355a0fb100239523064e297006786113cf98875999c2e37c09f_amd64 as a component of RHODF 4.16 for RHEL 9 | odf4/cephcsi-rhel9@sha256:45e01453d7b4b355a0fb100239523064e297006786113cf98875999c2e37c09f_amd64 |
| Red Hat | odf4/odf-multicluster-rhel9-operator@sha256:91c0694dd13b64a6569f7d0eb08b00c605b2c2c9563db8a227432949897eecb0_amd64 as a component of RHODF 4.16 for RHEL 9 | odf4/odf-multicluster-rhel9-operator@sha256:91c0694dd13b64a6569f7d0eb08b00c605b2c2c9563db8a227432949897eecb0_amd64 |
| Red Hat | odf4/odf-console-rhel9@sha256:6ce1c5953079d4f8fd1b402862aacb50b50c527ac22c67d1361eda62cfd5a65e_s390x as a component of RHODF 4.16 for RHEL 9 | * |
| Red Hat | odf4/rook-ceph-rhel9-operator@sha256:6f2c0a3a974bddd27a814ca29831638c09d2a146e00fd5b44b8e8bab795001cc_s390x as a component of RHODF 4.16 for RHEL 9 | *, *, * |
| Red Hat | odf4/odf-csi-addons-sidecar-rhel9@sha256:d7460455a3620b3f2f74bea1f1c0a8ce41ed26803abb83dac3b0e900463631aa_ppc64le as a component of RHODF 4.16 for RHEL 9 | *, *, * |
| Red Hat | odf4/odf-must-gather-rhel9@sha256:56c0e1cdd666d462927bb7896fb8205e789be27af76924e99a4fd0e2d1f92299_s390x as a component of RHODF 4.16 for RHEL 9 | odf4/odf-must-gather-rhel9@sha256:56c0e1cdd666d462927bb7896fb8205e789be27af76924e99a4fd0e2d1f92299_s390x |
…and 179 more
Timeline
- Jan 28, 2025 CVE Published
- May 15, 2026 Security Advisory
- Jul 5, 2026 Distribution Patch
- Jul 5, 2026 Distribution Patch
- Jul 5, 2026 Security Advisory
- Jul 5, 2026 Security Advisory
- Jul 19, 2026 CVE Updated
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2330689 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://pkg.go.dev/vuln/GO-2024-3333 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-52798 advisory
- https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-rhx6-c78j-4q9w advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-52798 advisory
- https://access.redhat.com/errata/RHSA-2025:0783 advisory
- https://issues.redhat.com/browse/DFBUGS-1343 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_0783.json advisory
- https://access.redhat.com/security/cve/CVE-2024-45338 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-45338 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45338 advisory
- https://go.dev/cl/637536 advisory
- https://go.dev/issue/70906 advisory
- https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJ advisory
- https://access.redhat.com/security/cve/CVE-2024-52798 advisory
- https://github.com/pillarjs/path-to-regexp/commit/f01c26a013b1889f0c217c643964513acf17f6a4 advisory