VDB
RHSA-2026%3A2120
RHSA-2026%3A2120
PUBLISHED
CVSS 7.5 HIGH
A denial-of-service vulnerability in github.com/sirupsen/logrus occurs when Entry.Writer() processes a single-line payload larger than 64KB with no newline characters. Due to a limitation in Go’s internal bufio.Scanner, the read operation fails with a “token too long” error, causing the underlying writer pipe to close. In affected versions, this leaves the Writer interface unusable and can disrupt logging functionality, potentially degrading application availability.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:ebe04fb1c865dbeacc2fd00c6dd8e6e5a8e2c90ad335fe001d2459ffc81ffeb8_arm64 as a component of Red Hat OpenShift Container Platform 4.2 | * |
| Red Hat | registry.redhat.io/openshift4/ose-secrets-store-csi-driver-rhel9-operator@sha256:713d2ff54624ab57df7d28d0cc5fa9a0a58da205b82ff1d10b89b70efddb98dd_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | * |
| Red Hat | registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:d323dd3a28593457c220b8bdd6d86267db0f47609e309b665fd2fd43ff652617_amd64 as a component of Red Hat OpenShift Container Platform 4.20 | registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:d323dd3a28593457c220b8bdd6d86267db0f47609e309b665fd2fd43ff652617_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-local-storage-mustgather-rhel9@sha256:d95afe2859f8534fe7f8c4daf0d222465c77b9a2584b5db045084cdfbf8cf1f6_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | * |
| Red Hat | registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel9@sha256:e57cbd7f0dbd1f50322bbdc1ae5d450e9f91a5ddc09b801a1b9872599c4b4ecc_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | * |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-rdma-cni-rhel9@sha256:35c83eedeaede88cd2f076a8df7d9df295f14eabb99e2c0aa1b9a92841a9d776_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | * |
| Red Hat | registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9-operator@sha256:d7e4e4513237c984b80f7be2c1db5d55396e193e6c41619f1e59794d0c844b70_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | * |
| Red Hat | registry.redhat.io/openshift4/ose-ptp-rhel9@sha256:17e86ada4c15eb9c44cc03cb317f90f17fc1eb501d50a360a10cee53e5c33f28_arm64 as a component of Red Hat OpenShift Container Platform 4.2 | * |
| Red Hat | registry.redhat.io/openshift4/ose-local-storage-mustgather-rhel9@sha256:c061c1e85ae29991987870cc86cea2c4352d5331db7eea75fb25084586f995ca_amd64 as a component of Red Hat OpenShift Container Platform 4.2 | * |
| Red Hat | registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9@sha256:fc5d915e64272224056620687c383536da952efa0680805b6e902c11ba9bcaca_ppc64le as a component of Red Hat OpenShift Container Platform 4.20 | registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9@sha256:fc5d915e64272224056620687c383536da952efa0680805b6e902c11ba9bcaca_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel9-operator@sha256:4c2180815553539ee086cb3d60a52d860dafcb9398b76f8f162dc91becf34979_amd64 as a component of Red Hat OpenShift Container Platform 4.2 | * |
| Red Hat | registry.redhat.io/openshift4/ose-vertical-pod-autoscaler-rhel9-operator@sha256:6edf147a4600608528be509bb0262007538a90db734fcd63a5f7ffd396c78ca4_arm64 as a component of Red Hat OpenShift Container Platform 4.20 | registry.redhat.io/openshift4/ose-vertical-pod-autoscaler-rhel9-operator@sha256:6edf147a4600608528be509bb0262007538a90db734fcd63a5f7ffd396c78ca4_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-secrets-store-csi-mustgather-rhel9@sha256:5f899ae2d728d6a78d7b8f6c32f54280ae875c7417a8a53a43b7c06bbef0239e_arm64 as a component of Red Hat OpenShift Container Platform 4.2 | * |
| Red Hat | registry.redhat.io/openshift4/pf-status-relay-rhel9-operator@sha256:8f85eec5710b56726b98936ad647307fe869e0ff9cd43cbe7698d6006eb55f0e_amd64 as a component of Red Hat OpenShift Container Platform 4.20 | * |
| Red Hat | registry.redhat.io/openshift4/ose-vertical-pod-autoscaler-rhel9-operator@sha256:b0c5f319cd3fd6de887f546d28edd450420ae7b2551720d46bf2b0ec8786e2eb_s390x as a component of Red Hat OpenShift Container Platform 4.2 | * |
| Red Hat | registry.redhat.io/openshift4/ose-local-storage-mustgather-rhel9@sha256:c061c1e85ae29991987870cc86cea2c4352d5331db7eea75fb25084586f995ca_amd64 as a component of Red Hat OpenShift Container Platform 4.20 | registry.redhat.io/openshift4/ose-local-storage-mustgather-rhel9@sha256:c061c1e85ae29991987870cc86cea2c4352d5331db7eea75fb25084586f995ca_amd64 |
| Red Hat | registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:b62a123a8cdb4a01c77234c6cd05b2b115233aba0512f0159434b6ba6b82675e_amd64 as a component of Red Hat OpenShift Container Platform 4.20 | registry.redhat.io/openshift4/kube-compare-artifacts-rhel9@sha256:b62a123a8cdb4a01c77234c6cd05b2b115233aba0512f0159434b6ba6b82675e_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9@sha256:fc5d915e64272224056620687c383536da952efa0680805b6e902c11ba9bcaca_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | * |
| Red Hat | registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:cb8b553c388bddf8439e3dee347a0d8e0e4d7ae166b51121122b1611a25d5afe_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | * |
| Red Hat | registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel9-operator@sha256:914275ef263188e04cb26f1e924f993d0dbbd6327c27393d9c77bc9ab056dbdd_ppc64le as a component of Red Hat OpenShift Container Platform 4.20 | * |
…and 334 more
Timeline
- Feb 11, 2026 CVE Published
- May 11, 2026 Security Advisory
- May 13, 2026 CVE Updated
- May 15, 2026 Distribution Patch
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
References
- https://access.redhat.com/security/cve/CVE-2025-65637 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-65637 advisory
- https://github.com/mjuanxd/logrus-dos-poc exploit
- https://github.com/sirupsen/logrus/pull/1376 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.8.3 advisory
- https://access.redhat.com/errata/RHSA-2026:2120 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2120.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418900 issue
- https://www.cve.org/CVERecord?id=CVE-2025-65637 advisory
- https://github.com/mjuanxd/logrus-dos-poc/blob/main/README.md exploit
- https://github.com/sirupsen/logrus/issues/1370 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.1 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.3 advisory
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSIRUPSENLOGRUS-5564391 advisory