VDB
RHSA-2026%3A3099
RHSA-2026%3A3099
PUBLISHED
CVSS 7.5 HIGH
A denial-of-service vulnerability in github.com/sirupsen/logrus occurs when Entry.Writer() processes a single-line payload larger than 64KB with no newline characters. Due to a limitation in Go’s internal bufio.Scanner, the read operation fails with a “token too long” error, causing the underlying writer pipe to close. In affected versions, this leaves the Writer interface unusable and can disrupt logging functionality, potentially degrading application availability.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/openshift4/topology-aware-lifecycle-manager-rhel8-operator@sha256:08102fd8113e0918879abdb779c758557340361de34f77618cadf55885a74cdf_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, * |
| Red Hat | registry.redhat.io/openshift4/topology-aware-lifecycle-manager-operator-bundle@sha256:e75d4418ee7f040083a35cba0e4b8526127c978ae8eb83da533ae15452f5f3f9_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, * |
| Red Hat | registry.redhat.io/openshift4/topology-aware-lifecycle-manager-precache-rhel8@sha256:f9163bac864ad181dbbc88749cb7909a9a7c99fde367a6a1c02918e5a8320885_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, registry.redhat.io/openshift4/topology-aware-lifecycle-manager-precache-rhel8@sha256:f9163bac864ad181dbbc88749cb7909a9a7c99fde367a6a1c02918e5a8320885_amd64 |
| Red Hat | registry.redhat.io/openshift4/topology-aware-lifecycle-manager-recovery-rhel8@sha256:867b01c6b9a63d90bbe6d9a889b86a5448e7784d11599d6a034a3aab81218207_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | registry.redhat.io/openshift4/topology-aware-lifecycle-manager-recovery-rhel8@sha256:867b01c6b9a63d90bbe6d9a889b86a5448e7784d11599d6a034a3aab81218207_amd64 |
| Red Hat | registry.redhat.io/openshift4/topology-aware-lifecycle-manager-rhel8-operator@sha256:08102fd8113e0918879abdb779c758557340361de34f77618cadf55885a74cdf_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | registry.redhat.io/openshift4/topology-aware-lifecycle-manager-rhel8-operator@sha256:08102fd8113e0918879abdb779c758557340361de34f77618cadf55885a74cdf_amd64 |
| Red Hat | registry.redhat.io/openshift4/topology-aware-lifecycle-manager-operator-bundle@sha256:e75d4418ee7f040083a35cba0e4b8526127c978ae8eb83da533ae15452f5f3f9_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | registry.redhat.io/openshift4/topology-aware-lifecycle-manager-operator-bundle@sha256:e75d4418ee7f040083a35cba0e4b8526127c978ae8eb83da533ae15452f5f3f9_amd64 |
| Red Hat | registry.redhat.io/openshift4/topology-aware-lifecycle-manager-recovery-rhel8@sha256:867b01c6b9a63d90bbe6d9a889b86a5448e7784d11599d6a034a3aab81218207_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, registry.redhat.io/openshift4/topology-aware-lifecycle-manager-recovery-rhel8@sha256:867b01c6b9a63d90bbe6d9a889b86a5448e7784d11599d6a034a3aab81218207_amd64 |
| Red Hat | registry.redhat.io/openshift4/topology-aware-lifecycle-manager-precache-rhel8@sha256:f9163bac864ad181dbbc88749cb7909a9a7c99fde367a6a1c02918e5a8320885_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | registry.redhat.io/openshift4/topology-aware-lifecycle-manager-precache-rhel8@sha256:f9163bac864ad181dbbc88749cb7909a9a7c99fde367a6a1c02918e5a8320885_amd64 |
Timeline
- Feb 23, 2026 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 13, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2026:3099 advisory
- https://access.redhat.com/security/cve/CVE-2025-65637 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3099.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418900 issue
- https://www.cve.org/CVERecord?id=CVE-2025-65637 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-65637 advisory
- https://github.com/mjuanxd/logrus-dos-poc exploit
- https://github.com/mjuanxd/logrus-dos-poc/blob/main/README.md exploit
- https://github.com/sirupsen/logrus/issues/1370 advisory
- https://github.com/sirupsen/logrus/pull/1376 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.8.3 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.1 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.3 advisory
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSIRUPSENLOGRUS-5564391 advisory