VDB
RHSA-2026%3A0715
RHSA-2026%3A0715
PUBLISHED
CVSS 7.5 HIGH
A denial-of-service vulnerability in github.com/sirupsen/logrus occurs when Entry.Writer() processes a single-line payload larger than 64KB with no newline characters. Due to a limitation in Go’s internal bufio.Scanner, the read operation fails with a “token too long” error, causing the underlying writer pipe to close. In affected versions, this leaves the Writer interface unusable and can disrupt logging functionality, potentially degrading application availability.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/openshift4/ose-baremetal-runtimecfg-rhel9@sha256:e39f7e9d8034b32f918fb3eb1adcd89b248e4d879734bcdd5860595b4dc33d93_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-baremetal-runtimecfg-rhel9@sha256:e39f7e9d8034b32f918fb3eb1adcd89b248e4d879734bcdd5860595b4dc33d93_arm64, * |
| Red Hat | registry.redhat.io/openshift4/ose-cli-rhel9@sha256:a2f4cf9accdf41e869afac3801881f2c523c1b94cb401e4c618f41c315cc5f47_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-cli-rhel9@sha256:a2f4cf9accdf41e869afac3801881f2c523c1b94cb401e4c618f41c315cc5f47_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-machine-config-rhel9-operator@sha256:02a280b798b4c457a6d18c50a6ec77c1d3da0f89d6949332ecf2ad7e87dffd77_s390x as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-machine-config-rhel9-operator@sha256:02a280b798b4c457a6d18c50a6ec77c1d3da0f89d6949332ecf2ad7e87dffd77_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-machine-api-rhel9-operator@sha256:007bc9793a3de6738670ea13750957fddb35ce26a760b09076bf271611dc1746_amd64 as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-machine-api-rhel9-operator@sha256:007bc9793a3de6738670ea13750957fddb35ce26a760b09076bf271611dc1746_amd64, * |
| Red Hat | registry.redhat.io/openshift4/ose-cloud-credential-rhel9-operator@sha256:4a5eaaae62d4fb97d4ccc0adc87d1006af402ecea6e13748eb7c833b33304e5e_s390x as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-cloud-credential-rhel9-operator@sha256:4a5eaaae62d4fb97d4ccc0adc87d1006af402ecea6e13748eb7c833b33304e5e_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-network-metrics-daemon-rhel9@sha256:a4c6ef8049e4cae2db1076c1fe9652e5e463e475c2e47ae57cadac77b85c1b3a_amd64 as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-network-metrics-daemon-rhel9@sha256:a4c6ef8049e4cae2db1076c1fe9652e5e463e475c2e47ae57cadac77b85c1b3a_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-operator-framework-tools-rhel9@sha256:397024bdbb37bb9cb2b1d8c44e6558b61cb9485a7e6603cabf58ae7d44092291_amd64 as a component of Red Hat OpenShift Container Platform 4.17 | *, * |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:a7f24a2e05287cf3d1c086ae2a16db546500d37d85ed31ad5592c789054aaff3_s390x as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9@sha256:a7f24a2e05287cf3d1c086ae2a16db546500d37d85ed31ad5592c789054aaff3_s390x, * |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-olm-rhel9-operator@sha256:7a9743ed6e059ff052017942a0a414538e85a67154f0bf8bd11f31e50c8cb413_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-cluster-olm-rhel9-operator@sha256:7a9743ed6e059ff052017942a0a414538e85a67154f0bf8bd11f31e50c8cb413_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-operator-lifecycle-manager-rhel9@sha256:a1d4cf42bceb3e6a4815dc7f665a3a577d6fe06db8f9eaec973da25a81f20344_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-operator-lifecycle-manager-rhel9@sha256:a1d4cf42bceb3e6a4815dc7f665a3a577d6fe06db8f9eaec973da25a81f20344_arm64, * |
| Red Hat | registry.redhat.io/openshift4/ose-gcp-workload-identity-federation-webhook-rhel9@sha256:b203ab7839940fa0a8218de3e3602d75f8ee5343f6d6ee018a4a98de985544f8_ppc64le as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-gcp-workload-identity-federation-webhook-rhel9@sha256:b203ab7839940fa0a8218de3e3602d75f8ee5343f6d6ee018a4a98de985544f8_ppc64le, * |
| Red Hat | registry.redhat.io/openshift4/ose-network-interface-bond-cni-rhel9@sha256:aff446d777c5efdd99ee146eccad6d2509d68852f790750a7f6b50ae2cf36186_ppc64le as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-network-interface-bond-cni-rhel9@sha256:aff446d777c5efdd99ee146eccad6d2509d68852f790750a7f6b50ae2cf36186_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-machine-api-provider-openstack-rhel9@sha256:cd9ee1dc64badca69a5aa6519d2b952b4d542160cc2cee970c499d67daf758ff_amd64 as a component of Red Hat OpenShift Container Platform 4.17 | *, registry.redhat.io/openshift4/ose-machine-api-provider-openstack-rhel9@sha256:cd9ee1dc64badca69a5aa6519d2b952b4d542160cc2cee970c499d67daf758ff_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-coredns-rhel9@sha256:ef6420d4046616c139ad5040590810fe216223526ff3a505b4a590bd37c7c869_amd64 as a component of Red Hat OpenShift Container Platform 4.17 | *, registry.redhat.io/openshift4/ose-coredns-rhel9@sha256:ef6420d4046616c139ad5040590810fe216223526ff3a505b4a590bd37c7c869_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-prometheus-rhel9-operator@sha256:8344a6b4e10728c7e56538c3ab5f61f63bb7bd1e9ee66eb9ad32dfb107a9ecb8_amd64 as a component of Red Hat OpenShift Container Platform 4.17 | * |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9-operator@sha256:c18f66b13e348a8302275d33df04d882a29269f8406e679ed3d99d7b3ed1f47b_amd64 as a component of Red Hat OpenShift Container Platform 4.17 | * |
| Red Hat | registry.redhat.io/openshift4/ose-installer-rhel9@sha256:abb50e95c2f02f979d84e96a2241c8dfef2c02ff3f60f5a721b06ce77b9ccb91_amd64 as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-installer-rhel9@sha256:abb50e95c2f02f979d84e96a2241c8dfef2c02ff3f60f5a721b06ce77b9ccb91_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-policy-controller-rhel9@sha256:d5018226c990212b9f0281f7bd4b9d6f1567e7c6dfdc9c92481a2ed2013b691f_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-cluster-policy-controller-rhel9@sha256:d5018226c990212b9f0281f7bd4b9d6f1567e7c6dfdc9c92481a2ed2013b691f_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-etcd-rhel9@sha256:30707e3e89ba622dd33caed26fdbcacb8fc53a395ff82bf1bbae7ee1402c062d_ppc64le as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-etcd-rhel9@sha256:30707e3e89ba622dd33caed26fdbcacb8fc53a395ff82bf1bbae7ee1402c062d_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-csi-external-attacher-rhel9@sha256:928a3bfb73ef2297dffe4a01d7d828bad20cd7dafbf8f20116e640a487ced903_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-csi-external-attacher-rhel9@sha256:928a3bfb73ef2297dffe4a01d7d828bad20cd7dafbf8f20116e640a487ced903_arm64, * |
…and 1296 more
Timeline
- Jan 22, 2026 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 13, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2026:0715 advisory
- https://access.redhat.com/security/cve/CVE-2025-65637 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_0715.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418900 issue
- https://www.cve.org/CVERecord?id=CVE-2025-65637 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-65637 advisory
- https://github.com/mjuanxd/logrus-dos-poc exploit
- https://github.com/mjuanxd/logrus-dos-poc/blob/main/README.md exploit
- https://github.com/sirupsen/logrus/issues/1370 advisory
- https://github.com/sirupsen/logrus/pull/1376 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.8.3 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.1 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.3 advisory
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSIRUPSENLOGRUS-5564391 advisory