VDB
RHSA-2026%3A3423
RHSA-2026%3A3423
PUBLISHED
CVSS 7.5 HIGH
A denial-of-service vulnerability in github.com/sirupsen/logrus occurs when Entry.Writer() processes a single-line payload larger than 64KB with no newline characters. Due to a limitation in Go’s internal bufio.Scanner, the read operation fails with a “token too long” error, causing the underlying writer pipe to close. In affected versions, this leaves the Writer interface unusable and can disrupt logging functionality, potentially degrading application availability.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:e35c17b8b70f3e582db8f777263d66d3707d77dbbd41322b7093cf2cc3d059c5_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:e35c17b8b70f3e582db8f777263d66d3707d77dbbd41322b7093cf2cc3d059c5_amd64, * |
| Red Hat | registry.redhat.io/openshift4/kubernetes-nmstate-rhel8-operator@sha256:6d9652b2131b7e1f9e2b09672d3d2d65892aac6a93a7229e34f844cee6db5ee9_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, * |
| Red Hat | registry.redhat.io/openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:6d4155fdd7e45b4316aa6ff5677c267bf92b248cd49066e008c15fb68d7d8005_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/ose-vertical-pod-autoscaler-rhel8@sha256:6d4155fdd7e45b4316aa6ff5677c267bf92b248cd49066e008c15fb68d7d8005_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-ptp@sha256:5cb0c870efaa79739c9b86baaa56d6804efd6e4633cfcf13903cf4e28eebe69e_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/ose-ptp@sha256:5cb0c870efaa79739c9b86baaa56d6804efd6e4633cfcf13903cf4e28eebe69e_amd64, * |
| Red Hat | registry.redhat.io/openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:6a092634d46e34e977d1996b406a04113e96151ae748c86d072d99fb908b0479_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/ose-kubernetes-nmstate-handler-rhel8@sha256:6a092634d46e34e977d1996b406a04113e96151ae748c86d072d99fb908b0479_amd64 |
| Red Hat | registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:7257c9ca2422562951f34a98cb5db835677c6e930a5304de2cc652e707367a2c_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, * |
| Red Hat | registry.redhat.io/openshift4/metallb-rhel8-operator@sha256:6243a19168e4992ba6003225909ba0e70dd7b6fa87f4c0adfd50ec814848b89f_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/metallb-rhel8-operator@sha256:6243a19168e4992ba6003225909ba0e70dd7b6fa87f4c0adfd50ec814848b89f_amd64 |
| Red Hat | registry.redhat.io/openshift4/kubernetes-nmstate-rhel8-operator@sha256:6d9652b2131b7e1f9e2b09672d3d2d65892aac6a93a7229e34f844cee6db5ee9_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/kubernetes-nmstate-rhel8-operator@sha256:6d9652b2131b7e1f9e2b09672d3d2d65892aac6a93a7229e34f844cee6db5ee9_amd64 |
| Red Hat | registry.redhat.io/openshift4/metallb-rhel8@sha256:9e50d03c3f35d9fe4e5d2ae4f83209c471ce419c3e638a9347280565a91a49a2_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/metallb-rhel8@sha256:9e50d03c3f35d9fe4e5d2ae4f83209c471ce419c3e638a9347280565a91a49a2_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-operator@sha256:9145298ce20136804eaa64256dcb2b5ef89bbd42952c20e9e22cac3fa33e8657_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, * |
| Red Hat | registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel8@sha256:a7ecca6aebbb55bda5a4bcfeffb8a2ef43a4a0790f8016a7a9dc72aa43b37d88_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel8@sha256:a7ecca6aebbb55bda5a4bcfeffb8a2ef43a4a0790f8016a7a9dc72aa43b37d88_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-local-storage-diskmaker-rhel9@sha256:b13c73b6352017ad732185343816796594e4ba7baea63cfe1e845854dc02ba8d_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, registry.redhat.io/openshift4/ose-local-storage-diskmaker-rhel9@sha256:b13c73b6352017ad732185343816796594e4ba7baea63cfe1e845854dc02ba8d_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-egress-dns-proxy@sha256:cfcb508f953ef1672a84efc72c83a81901c4d266945c3cd16a438ede9ae6a735_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, * |
| Red Hat | registry.redhat.io/openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:e83a6d458e9be7296c680ca9bc84de3a4fd71e2e9dcb05107c728f13afc0fbb1_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:e83a6d458e9be7296c680ca9bc84de3a4fd71e2e9dcb05107c728f13afc0fbb1_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel8@sha256:b81141de7e002f52dabf732bf14c8f975274460ed2cae21b0cc58061b1b7ec02_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel8@sha256:b81141de7e002f52dabf732bf14c8f975274460ed2cae21b0cc58061b1b7ec02_amd64 |
| Red Hat | registry.redhat.io/openshift4/frr-rhel8@sha256:898e9ca5ae3c5ea5745aaa6c5d4cdd5163dff0afefbc59603fb0ba786688b894_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/frr-rhel8@sha256:898e9ca5ae3c5ea5745aaa6c5d4cdd5163dff0afefbc59603fb0ba786688b894_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:03ad66f11814550bf26abf180719a85f061c9309bceea0d22346a13b65bf9909_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:03ad66f11814550bf26abf180719a85f061c9309bceea0d22346a13b65bf9909_amd64, * |
| Red Hat | registry.redhat.io/openshift4/ose-ptp-operator@sha256:5c72d9db36e7596bf2ab5f3d010aca92aa3f7edb999d4dab3b257d5505faa22f_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/ose-ptp-operator@sha256:5c72d9db36e7596bf2ab5f3d010aca92aa3f7edb999d4dab3b257d5505faa22f_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-webhook@sha256:4b371b8bb9a7cd3c9868dcbfea878c7df046eff80a980d3ccab79d44d63715d7_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/ose-sriov-network-webhook@sha256:4b371b8bb9a7cd3c9868dcbfea878c7df046eff80a980d3ccab79d44d63715d7_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:e83a6d458e9be7296c680ca9bc84de3a4fd71e2e9dcb05107c728f13afc0fbb1_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, registry.redhat.io/openshift4/ose-csi-driver-shared-resource-mustgather-rhel8@sha256:e83a6d458e9be7296c680ca9bc84de3a4fd71e2e9dcb05107c728f13afc0fbb1_amd64 |
…and 56 more
Timeline
- Mar 5, 2026 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 13, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2026:3423 advisory
- https://access.redhat.com/security/cve/CVE-2025-65637 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_3423.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418900 issue
- https://www.cve.org/CVERecord?id=CVE-2025-65637 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-65637 advisory
- https://github.com/mjuanxd/logrus-dos-poc exploit
- https://github.com/mjuanxd/logrus-dos-poc/blob/main/README.md exploit
- https://github.com/sirupsen/logrus/issues/1370 advisory
- https://github.com/sirupsen/logrus/pull/1376 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.8.3 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.1 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.3 advisory
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSIRUPSENLOGRUS-5564391 advisory