VDB
RHSA-2026%3A3418
RHSA-2026%3A3418
PUBLISHED
CVSS 7.5 HIGH
A denial-of-service vulnerability in github.com/sirupsen/logrus occurs when Entry.Writer() processes a single-line payload larger than 64KB with no newline characters. Due to a limitation in Go’s internal bufio.Scanner, the read operation fails with a “token too long” error, causing the underlying writer pipe to close. In affected versions, this leaves the Writer interface unusable and can disrupt logging functionality, potentially degrading application availability.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/openshift4/ose-openstack-cinder-csi-driver-rhel9-operator@sha256:3b08e48db6358666f4986db54fa3a4d2b08832b073d840739363e44d6f9c81d2_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-openstack-cinder-csi-driver-rhel9-operator@sha256:3b08e48db6358666f4986db54fa3a4d2b08832b073d840739363e44d6f9c81d2_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-csi-driver-shared-resource-rhel9-operator@sha256:a0b2561bb59c7072d937cb504ae5ae6f843cde55fe8e79bdd9f50d94b6e8e63c_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-csi-driver-shared-resource-rhel9-operator@sha256:a0b2561bb59c7072d937cb504ae5ae6f843cde55fe8e79bdd9f50d94b6e8e63c_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9-operator@sha256:fdececfef26d5955d3d29002e00e566fe49fa922357b91b3edd1277f035564dc_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-cluster-autoscaler-rhel9-operator@sha256:fdececfef26d5955d3d29002e00e566fe49fa922357b91b3edd1277f035564dc_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-multus-networkpolicy-rhel9@sha256:b2187a50041fe840d35ad0157107334585d812782d3d4012b0d587308a0064d1_s390x as a component of Red Hat OpenShift Container Platform 4.17 | *, registry.redhat.io/openshift4/ose-multus-networkpolicy-rhel9@sha256:b2187a50041fe840d35ad0157107334585d812782d3d4012b0d587308a0064d1_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-service-ca-rhel9-operator@sha256:8bd8e0369a8fcaa833c8899947ba6fc343ba2216c842db92a3f69d5b71fe21e9_s390x as a component of Red Hat OpenShift Container Platform 4.17 | *, * |
| Red Hat | registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel9@sha256:b01fd1e681906a5e223b41b6599b0abaedd2a0e3dc0a23235a8a9b735a34a181_s390x as a component of Red Hat OpenShift Container Platform 4.17 | *, registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel9@sha256:b01fd1e681906a5e223b41b6599b0abaedd2a0e3dc0a23235a8a9b735a34a181_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-container-networking-plugins-rhel9@sha256:43c40e3f8ec30d849747244abd3a4f46432339c54b9fb32bc380aa705384bc1b_ppc64le as a component of Red Hat OpenShift Container Platform 4.17 | * |
| Red Hat | registry.redhat.io/openshift4/ose-oauth-apiserver-rhel9@sha256:f1412d078e2eeb4c64b17d4e061d9beceb1806f82300c439c3fe13299c24134e_s390x as a component of Red Hat OpenShift Container Platform 4.17 | *, registry.redhat.io/openshift4/ose-oauth-apiserver-rhel9@sha256:f1412d078e2eeb4c64b17d4e061d9beceb1806f82300c439c3fe13299c24134e_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-prometheus-node-exporter-rhel9@sha256:c2f2339475c3187fd52046ad35193b628e051be00646fa3491a8d3b794259da0_s390x as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-prometheus-node-exporter-rhel9@sha256:c2f2339475c3187fd52046ad35193b628e051be00646fa3491a8d3b794259da0_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-libvirt-machine-controllers-rhel9@sha256:8236cd0a52238d1bcac4046d1e6db765ce1213cf47d88152491d2882ed8ff5ce_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-libvirt-machine-controllers-rhel9@sha256:8236cd0a52238d1bcac4046d1e6db765ce1213cf47d88152491d2882ed8ff5ce_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-csi-driver-manila-rhel9@sha256:c123e9da0e85d44f770edada9261e8f02b8450a54f2cb96a1610a33f3d686323_ppc64le as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-csi-driver-manila-rhel9@sha256:c123e9da0e85d44f770edada9261e8f02b8450a54f2cb96a1610a33f3d686323_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-openstack-cloud-controller-manager-rhel9@sha256:5b75fe5f9058a9835abea192209aea00706f46a6269ce0727dfa77abd1a75713_amd64 as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-openstack-cloud-controller-manager-rhel9@sha256:5b75fe5f9058a9835abea192209aea00706f46a6269ce0727dfa77abd1a75713_amd64 |
| Red Hat | registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:e9dbfb764480da30fb861226dbc04704a2c4ff3973646ae5f73484596c1e388f_s390x as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:e9dbfb764480da30fb861226dbc04704a2c4ff3973646ae5f73484596c1e388f_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-telemeter-rhel9@sha256:4e73559823143daf944b165f1ec95bb75f4d7de1da32e2082343b9853fa3917e_ppc64le as a component of Red Hat OpenShift Container Platform 4.17 | *, registry.redhat.io/openshift4/ose-telemeter-rhel9@sha256:4e73559823143daf944b165f1ec95bb75f4d7de1da32e2082343b9853fa3917e_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-ingress-rhel9-operator@sha256:bccde88d743e2ba289620b3508b5208a4094792ea1c6c98d7a8a125173e8d35f_amd64 as a component of Red Hat OpenShift Container Platform 4.17 | *, * |
| Red Hat | registry.redhat.io/openshift4/ose-gcp-cluster-api-controllers-rhel9@sha256:bc351993eb862299ebc9a2311eee479dc36c8f2189ce1c8925318ef4fa070c7e_ppc64le as a component of Red Hat OpenShift Container Platform 4.17 | *, * |
| Red Hat | registry.redhat.io/openshift4/openshift-route-controller-manager-rhel9@sha256:e93e52fe4577db0bf46b088c488e313d1f2bf7e42f01fb55c743c4bd2beea9e4_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | *, * |
| Red Hat | registry.redhat.io/openshift4/ose-oauth-server-rhel9@sha256:38dad6ec6873d568cdc40acfce084be7c7be0b28c794084f89b02b3ac8b9a3c2_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | * |
| Red Hat | registry.redhat.io/openshift4/ose-cli-rhel9@sha256:13ac9f25572cc1e4313a14da217915e9fa891b2cf637966d42ef36c27fd3fb1e_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-cli-rhel9@sha256:13ac9f25572cc1e4313a14da217915e9fa891b2cf637966d42ef36c27fd3fb1e_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-haproxy-router-rhel9@sha256:ad52e414d79e33b419cfc81d0fea8616e0751d82d33307ddca062ad86e4298db_arm64 as a component of Red Hat OpenShift Container Platform 4.17 | registry.redhat.io/openshift4/ose-haproxy-router-rhel9@sha256:ad52e414d79e33b419cfc81d0fea8616e0751d82d33307ddca062ad86e4298db_arm64, * |
…and 1268 more
Timeline
- Mar 4, 2026 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 13, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2026:3418 advisory
- https://access.redhat.com/security/cve/CVE-2025-65637 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3418.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418900 issue
- https://www.cve.org/CVERecord?id=CVE-2025-65637 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-65637 advisory
- https://github.com/mjuanxd/logrus-dos-poc exploit
- https://github.com/mjuanxd/logrus-dos-poc/blob/main/README.md exploit
- https://github.com/sirupsen/logrus/issues/1370 advisory
- https://github.com/sirupsen/logrus/pull/1376 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.8.3 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.1 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.3 advisory
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSIRUPSENLOGRUS-5564391 advisory