VDB
RHSA-2026%3A4483
RHSA-2026%3A4483
PUBLISHED
CVSS 7.5 HIGH
A denial-of-service vulnerability in github.com/sirupsen/logrus occurs when Entry.Writer() processes a single-line payload larger than 64KB with no newline characters. Due to a limitation in Go’s internal bufio.Scanner, the read operation fails with a “token too long” error, causing the underlying writer pipe to close. In affected versions, this leaves the Writer interface unusable and can disrupt logging functionality, potentially degrading application availability.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:29c4191663786135c85cea2ceabf69d0c3cfa5c0950f3573541c12f0b7cdf0b2_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-rhel9-operator@sha256:2d6e851095c3571074010590c0dc60b11c37064155acb875b841377b22c7762b_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | *, *, registry.redhat.io/openshift4/ose-sriov-network-rhel9-operator@sha256:2d6e851095c3571074010590c0dc60b11c37064155acb875b841377b22c7762b_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel9@sha256:a5e887059affe9143b92b7cab384df40a37c94fa84dd30c71f691deeac733ea8_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-metrics-exporter-rhel9@sha256:22761c3c8a577959a77b6256ab173aee854a99147e052d8b70c3d04eced4e778_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | registry.redhat.io/openshift4/ose-vertical-pod-autoscaler-rhel9@sha256:837638647d530df3105b82ab86bff5fb98206df2f3d643889461009888bc509e_s390x as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-vertical-pod-autoscaler-rhel9@sha256:837638647d530df3105b82ab86bff5fb98206df2f3d643889461009888bc509e_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-config-daemon-rhel9@sha256:c45f89a148b69bbe6e1bfcc6811d60020a7b8e5a9c5bec175b99e21c9ffe5589_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | registry.redhat.io/openshift4/ose-local-storage-rhel9-operator@sha256:07dccdd5ac8911abfddb2184458c515cab4c66b690b159a54b2ecbc91025c52e_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-local-storage-rhel9-operator@sha256:07dccdd5ac8911abfddb2184458c515cab4c66b690b159a54b2ecbc91025c52e_amd64 |
| Red Hat | registry.redhat.io/openshift4/metallb-rhel9-operator@sha256:d1b37fda5529d1586ccabcce3e1629401134c426cc2039c616356973283e162b_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9-operator@sha256:61f7a55b1c1920c59980087a92543f2576eeb9e6d4ed101a69957ef554682431_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9-operator@sha256:61f7a55b1c1920c59980087a92543f2576eeb9e6d4ed101a69957ef554682431_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel9-operator@sha256:ae97317255d1570cedddd60c2e280a28d4cca7baed3d8cd53e62b0a8a235914f_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-secrets-store-csi-driver-rhel9-operator@sha256:79ee5a91916a3d008e3d8c2a873721a1090e2c206ec799b941ba6d7a9318ce5b_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-vertical-pod-autoscaler-rhel9-operator@sha256:d5bacb85191913ff33418f1a2d6daaec7f35207bf6245a8c47473e596e11d732_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, registry.redhat.io/openshift4/ose-vertical-pod-autoscaler-rhel9-operator@sha256:d5bacb85191913ff33418f1a2d6daaec7f35207bf6245a8c47473e596e11d732_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-local-storage-rhel9-operator@sha256:71a89af9bc184ede0aaef6af802500a46ce4243d1934751a675a53c598614784_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | *, registry.redhat.io/openshift4/ose-local-storage-rhel9-operator@sha256:71a89af9bc184ede0aaef6af802500a46ce4243d1934751a675a53c598614784_ppc64le, * |
| Red Hat | registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:b15c02495beffcd62cf444742668eae80f0aa4a2e50d366d8901a2a0b8ff6c22_ppc64le as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ingress-node-firewall-rhel9@sha256:b15c02495beffcd62cf444742668eae80f0aa4a2e50d366d8901a2a0b8ff6c22_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-dpu-daemon-rhel9@sha256:0dba31b9630e9e7ea28aefdd4c838cee8998942c0cb60c828824362f68b823f5_s390x as a component of Red Hat OpenShift Container Platform 4.16 | registry.redhat.io/openshift4/ose-dpu-daemon-rhel9@sha256:0dba31b9630e9e7ea28aefdd4c838cee8998942c0cb60c828824362f68b823f5_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-metrics-exporter-rhel9@sha256:e5366aa1b82a8e592fd464fd07c4173dd80f9f3f73853329433623dc37c25079_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | * |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-metrics-exporter-rhel9@sha256:22761c3c8a577959a77b6256ab173aee854a99147e052d8b70c3d04eced4e778_amd64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:23f9cf3b520672cafdedad3a306d7451ab6deda2af5deb3aabc054d4a5c70fe0_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, * |
| sirupsen | logrus | |
| Red Hat | registry.redhat.io/openshift4/ose-kubernetes-nmstate-handler-rhel9@sha256:b710902f48395fb883b725a39d8b1f6f448f9a559cdd19983e11af492efab7a1_arm64 as a component of Red Hat OpenShift Container Platform 4.16 | *, *, registry.redhat.io/openshift4/ose-kubernetes-nmstate-handler-rhel9@sha256:b710902f48395fb883b725a39d8b1f6f448f9a559cdd19983e11af492efab7a1_arm64 |
…and 329 more
Timeline
- Mar 19, 2026 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 28, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2026:4483 advisory
- https://access.redhat.com/security/cve/CVE-2025-65637 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_4483.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418900 issue
- https://www.cve.org/CVERecord?id=CVE-2025-65637 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-65637 advisory
- https://github.com/mjuanxd/logrus-dos-poc exploit
- https://github.com/mjuanxd/logrus-dos-poc/blob/main/README.md exploit
- https://github.com/sirupsen/logrus/issues/1370 advisory
- https://github.com/sirupsen/logrus/pull/1376 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.8.3 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.1 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.3 advisory
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSIRUPSENLOGRUS-5564391 advisory