VDB
RHSA-2026%3A4424
RHSA-2026%3A4424
PUBLISHED
CVSS 7.5 HIGH
A denial-of-service vulnerability in github.com/sirupsen/logrus occurs when Entry.Writer() processes a single-line payload larger than 64KB with no newline characters. Due to a limitation in Go’s internal bufio.Scanner, the read operation fails with a “token too long” error, causing the underlying writer pipe to close. In affected versions, this leaves the Writer interface unusable and can disrupt logging functionality, potentially degrading application availability.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/openshift4/ose-cluster-capacity@sha256:2ab0a2e723be163813f5f969a1463e4012a30177c254cf03b77d7eb65e4f6fa0_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | *, registry.redhat.io/openshift4/ose-cluster-capacity@sha256:2ab0a2e723be163813f5f969a1463e4012a30177c254cf03b77d7eb65e4f6fa0_amd64, * |
| Red Hat | OpenShift Container Platform | |
| Red Hat | registry.redhat.io/openshift4/ose-ptp-rhel9@sha256:4782f1723437c59002536197335e819d221e28a4b0c8f8cf5e00f92d1173bcbc_arm64 as a component of Red Hat OpenShift Container Platform 4.15 | registry.redhat.io/openshift4/ose-ptp-rhel9@sha256:4782f1723437c59002536197335e819d221e28a4b0c8f8cf5e00f92d1173bcbc_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-device-plugin-rhel9@sha256:dd2e5204c1ec7c990a3dd21382ebd49e1a6cec22c479b50eb7807f1b15824072_arm64 as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel9-operator@sha256:ea44833e9ff014095e43ce6562733f54b0a1f3b5f143d40663e0f99a42e23cad_arm64 as a component of Red Hat OpenShift Container Platform 4.15 | registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel9-operator@sha256:ea44833e9ff014095e43ce6562733f54b0a1f3b5f143d40663e0f99a42e23cad_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-egress-router@sha256:326143ef09eed68d9826bdaab2e6f5b9e5dd98c0e385594341efcaae5593bbf6_ppc64le as a component of Red Hat OpenShift Container Platform 4.15 | registry.redhat.io/openshift4/ose-egress-router@sha256:326143ef09eed68d9826bdaab2e6f5b9e5dd98c0e385594341efcaae5593bbf6_ppc64le, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-ansible-operator@sha256:4be06e16d0866035729261636be38ce84bc9365ff80617b6e168466c5252f473_ppc64le as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:e39cca039c3d6569b2dd0ca4a8ed6223286166620b6f0860918531fd661fcb3c_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | *, *, registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:e39cca039c3d6569b2dd0ca4a8ed6223286166620b6f0860918531fd661fcb3c_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-rhel9-operator@sha256:00741065883bc999aa8268c1bf46cf4cc8e6524782183b4d9ec26ef4553741a9_ppc64le as a component of Red Hat OpenShift Container Platform 4.15 | registry.redhat.io/openshift4/ose-sriov-network-rhel9-operator@sha256:00741065883bc999aa8268c1bf46cf4cc8e6524782183b4d9ec26ef4553741a9_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel9-operator@sha256:6ec505ef0a7d5aa5b0c53727920e1de6b4bfc1fffc770e70661ced254c12d669_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | *, registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel9-operator@sha256:6ec505ef0a7d5aa5b0c53727920e1de6b4bfc1fffc770e70661ced254c12d669_amd64, * |
| Red Hat | registry.redhat.io/openshift4/ose-secrets-store-csi-driver-rhel8-operator@sha256:fdb6da95949521f6f5259e0caef09c24bb9e95a29b287660ae652bb46d12e506_s390x as a component of Red Hat OpenShift Container Platform 4.15 | registry.redhat.io/openshift4/ose-secrets-store-csi-driver-rhel8-operator@sha256:fdb6da95949521f6f5259e0caef09c24bb9e95a29b287660ae652bb46d12e506_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-kubernetes-nmstate-handler-rhel9@sha256:e7b2589a41822cbb7d27438e88707a28965d1c2ad1211d9e50a6344d8557a802_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-vertical-pod-autoscaler-rhel9-operator@sha256:687fa49b0e792ceafb0d2d7967ead93d09f654cf58e50f456243737b727f0b4b_arm64 as a component of Red Hat OpenShift Container Platform 4.15 | registry.redhat.io/openshift4/ose-vertical-pod-autoscaler-rhel9-operator@sha256:687fa49b0e792ceafb0d2d7967ead93d09f654cf58e50f456243737b727f0b4b_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-egress-http-proxy@sha256:a1aa2213032d5c79d866f270a28fa3c180f342f8d0cdc220abe4ea3fa2903888_ppc64le as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-local-storage-mustgather-rhel9@sha256:11619ebbd7199deca3981f67ea0a63ea234f675a641e700a6c9e887116463657_s390x as a component of Red Hat OpenShift Container Platform 4.15 | registry.redhat.io/openshift4/ose-local-storage-mustgather-rhel9@sha256:11619ebbd7199deca3981f67ea0a63ea234f675a641e700a6c9e887116463657_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:c4be38777ffc19242e130e32ce8f31b27a9a545904ba5905fd58728fdca38d31_ppc64le as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:be3faf2de5c6600da97a988155901cb36a38d342b7d07025dbc508bee493f285_amd64 as a component of Red Hat OpenShift Container Platform 4.15 | registry.redhat.io/openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:be3faf2de5c6600da97a988155901cb36a38d342b7d07025dbc508bee493f285_amd64, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-local-storage-diskmaker-rhel9@sha256:f4fdeefd6189be64fd4ef082ee6e6a252318a6053bf38088735d8ce9bcdc876e_ppc64le as a component of Red Hat OpenShift Container Platform 4.15 | registry.redhat.io/openshift4/ose-local-storage-diskmaker-rhel9@sha256:f4fdeefd6189be64fd4ef082ee6e6a252318a6053bf38088735d8ce9bcdc876e_ppc64le, *, * |
| Red Hat | registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:06595094d2e7f5ad0e62a117a2b8d2bbd720515c042c61b66c426973a735e58e_arm64 as a component of Red Hat OpenShift Container Platform 4.15 | registry.redhat.io/openshift4/kubernetes-nmstate-rhel9-operator@sha256:06595094d2e7f5ad0e62a117a2b8d2bbd720515c042c61b66c426973a735e58e_arm64, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-vertical-pod-autoscaler-rhel9-operator@sha256:3b5d3ced65330a3653f59ce2c34dafc77a5bd8c1d8b5a1060b7936006fbe9310_ppc64le as a component of Red Hat OpenShift Container Platform 4.15 | *, *, * |
…and 299 more
Timeline
- Mar 19, 2026 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 28, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2026:4424 advisory
- https://access.redhat.com/security/cve/CVE-2025-65637 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_4424.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418900 issue
- https://www.cve.org/CVERecord?id=CVE-2025-65637 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-65637 advisory
- https://github.com/mjuanxd/logrus-dos-poc exploit
- https://github.com/mjuanxd/logrus-dos-poc/blob/main/README.md exploit
- https://github.com/sirupsen/logrus/issues/1370 advisory
- https://github.com/sirupsen/logrus/pull/1376 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.8.3 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.1 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.3 advisory
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSIRUPSENLOGRUS-5564391 advisory