VDB

RHSA-2026%3A3099

RHSA-2026%3A3099 PUBLISHED CVSS 7.5 HIGH

A denial-of-service vulnerability in github.com/sirupsen/logrus occurs when Entry.Writer() processes a single-line payload larger than 64KB with no newline characters. Due to a limitation in Go’s internal bufio.Scanner, the read operation fails with a “token too long” error, causing the underlying writer pipe to close. In affected versions, this leaves the Writer interface unusable and can disrupt logging functionality, potentially degrading application availability.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatregistry.redhat.io/openshift4/topology-aware-lifecycle-manager-rhel8-operator@sha256:08102fd8113e0918879abdb779c758557340361de34f77618cadf55885a74cdf_amd64 as a component of Red Hat OpenShift Container Platform 4.12*, *
Red Hatregistry.redhat.io/openshift4/topology-aware-lifecycle-manager-operator-bundle@sha256:e75d4418ee7f040083a35cba0e4b8526127c978ae8eb83da533ae15452f5f3f9_amd64 as a component of Red Hat OpenShift Container Platform 4.12*, *
Red Hatregistry.redhat.io/openshift4/topology-aware-lifecycle-manager-precache-rhel8@sha256:f9163bac864ad181dbbc88749cb7909a9a7c99fde367a6a1c02918e5a8320885_amd64 as a component of Red Hat OpenShift Container Platform 4.12*, registry.redhat.io/openshift4/topology-aware-lifecycle-manager-precache-rhel8@sha256:f9163bac864ad181dbbc88749cb7909a9a7c99fde367a6a1c02918e5a8320885_amd64
Red Hatregistry.redhat.io/openshift4/topology-aware-lifecycle-manager-recovery-rhel8@sha256:867b01c6b9a63d90bbe6d9a889b86a5448e7784d11599d6a034a3aab81218207_amd64 as a component of Red Hat OpenShift Container Platform 4.12registry.redhat.io/openshift4/topology-aware-lifecycle-manager-recovery-rhel8@sha256:867b01c6b9a63d90bbe6d9a889b86a5448e7784d11599d6a034a3aab81218207_amd64
Red Hatregistry.redhat.io/openshift4/topology-aware-lifecycle-manager-rhel8-operator@sha256:08102fd8113e0918879abdb779c758557340361de34f77618cadf55885a74cdf_amd64 as a component of Red Hat OpenShift Container Platform 4.12registry.redhat.io/openshift4/topology-aware-lifecycle-manager-rhel8-operator@sha256:08102fd8113e0918879abdb779c758557340361de34f77618cadf55885a74cdf_amd64
Red Hatregistry.redhat.io/openshift4/topology-aware-lifecycle-manager-operator-bundle@sha256:e75d4418ee7f040083a35cba0e4b8526127c978ae8eb83da533ae15452f5f3f9_amd64 as a component of Red Hat OpenShift Container Platform 4.12registry.redhat.io/openshift4/topology-aware-lifecycle-manager-operator-bundle@sha256:e75d4418ee7f040083a35cba0e4b8526127c978ae8eb83da533ae15452f5f3f9_amd64
Red Hatregistry.redhat.io/openshift4/topology-aware-lifecycle-manager-recovery-rhel8@sha256:867b01c6b9a63d90bbe6d9a889b86a5448e7784d11599d6a034a3aab81218207_amd64 as a component of Red Hat OpenShift Container Platform 4.12*, registry.redhat.io/openshift4/topology-aware-lifecycle-manager-recovery-rhel8@sha256:867b01c6b9a63d90bbe6d9a889b86a5448e7784d11599d6a034a3aab81218207_amd64
Red Hatregistry.redhat.io/openshift4/topology-aware-lifecycle-manager-precache-rhel8@sha256:f9163bac864ad181dbbc88749cb7909a9a7c99fde367a6a1c02918e5a8320885_amd64 as a component of Red Hat OpenShift Container Platform 4.12registry.redhat.io/openshift4/topology-aware-lifecycle-manager-precache-rhel8@sha256:f9163bac864ad181dbbc88749cb7909a9a7c99fde367a6a1c02918e5a8320885_amd64

Timeline

  • Feb 23, 2026 CVE Published
  • Apr 29, 2026 Distribution Patch
  • Apr 29, 2026 Distribution Patch
  • Apr 29, 2026 Security Advisory
  • Apr 29, 2026 Security Advisory
  • May 13, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›