VDB
RHSA-2026%3A7253
RHSA-2026%3A7253
PUBLISHED
CVSS 7.5 HIGH
A denial-of-service vulnerability in github.com/sirupsen/logrus occurs when Entry.Writer() processes a single-line payload larger than 64KB with no newline characters. Due to a limitation in Go’s internal bufio.Scanner, the read operation fails with a “token too long” error, causing the underlying writer pipe to close. In affected versions, this leaves the Writer interface unusable and can disrupt logging functionality, potentially degrading application availability.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/openshift4/ose-operator-sdk-rhel8@sha256:71a87ce3f532552ec18029a7b03f502853e75a6e95ada408fb5d5ccaaa9a5873_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, registry.redhat.io/openshift4/ose-operator-sdk-rhel8@sha256:71a87ce3f532552ec18029a7b03f502853e75a6e95ada408fb5d5ccaaa9a5873_amd64, * |
| Red Hat | registry.redhat.io/openshift4/kubernetes-nmstate-rhel8-operator@sha256:1a9ad9d63bc9092c92ed45597a9dac0838bf9cc1a31bd35d056f511b6f85197e_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, registry.redhat.io/openshift4/kubernetes-nmstate-rhel8-operator@sha256:1a9ad9d63bc9092c92ed45597a9dac0838bf9cc1a31bd35d056f511b6f85197e_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-config-daemon@sha256:15736c5c451b31b46fb38f180f337940eecb0347bb4064340e6ca8dbaf0d5c3e_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ptp-must-gather-rhel8@sha256:d56a29fbce15d3d0c97f0509f84debd5c4a3ffa22f1e10b8ea3234bc5636b7f9_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/kubernetes-nmstate-rhel8-operator@sha256:1a9ad9d63bc9092c92ed45597a9dac0838bf9cc1a31bd35d056f511b6f85197e_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/kubernetes-nmstate-rhel8-operator@sha256:1a9ad9d63bc9092c92ed45597a9dac0838bf9cc1a31bd35d056f511b6f85197e_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:b2ff49b60f3e24d650a8475f703922c1d2ef699071f8cc0b4e5e47cac72d47cc_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, registry.redhat.io/openshift4/ose-vertical-pod-autoscaler-rhel8-operator@sha256:b2ff49b60f3e24d650a8475f703922c1d2ef699071f8cc0b4e5e47cac72d47cc_amd64, * |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-capacity@sha256:53dc9db905c62d566792dde9a00c79a310eaa72bcd336001fa2971c92a3c1c35_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/ose-cluster-capacity@sha256:53dc9db905c62d566792dde9a00c79a310eaa72bcd336001fa2971c92a3c1c35_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-egress-router@sha256:0be6c10bf50993f7f5c3d28d0f6580570bf4eada8e92c04c3e045245eb1c4246_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, registry.redhat.io/openshift4/ose-egress-router@sha256:0be6c10bf50993f7f5c3d28d0f6580570bf4eada8e92c04c3e045245eb1c4246_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-infiniband-cni@sha256:0015885387d303273c36a4dae19c48839de96b32fe59c3c0133e535942b6be72_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | * |
| Red Hat | registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:53a8b1f5ce447d6759b99d1c05a8cc92166c2f8011e4a1b58acb2b23dd492af3_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/ose-gcp-filestore-csi-driver-rhel8-operator@sha256:53a8b1f5ce447d6759b99d1c05a8cc92166c2f8011e4a1b58acb2b23dd492af3_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-config-daemon@sha256:15736c5c451b31b46fb38f180f337940eecb0347bb4064340e6ca8dbaf0d5c3e_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | * |
| Red Hat | registry.redhat.io/openshift4/frr-rhel8@sha256:db42dfe62fcf51d68767cc00b214d80af082fb20d480f9efd86bdff0c5126364_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | * |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-webhook@sha256:e6705fc366af4fcd0f8a39fc4d93f8b4c1b10d992260f459f0787a0d19b2a641_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/ose-sriov-network-webhook@sha256:e6705fc366af4fcd0f8a39fc4d93f8b4c1b10d992260f459f0787a0d19b2a641_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-nfd-operator@sha256:8759bfcc424793409364fb1b3f4568dd5e23f4509cd8d7f6974fc3224ddb203a_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/ose-cluster-nfd-operator@sha256:8759bfcc424793409364fb1b3f4568dd5e23f4509cd8d7f6974fc3224ddb203a_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-operator@sha256:666ab87e49959766d0744e8395aacd54f06579066207ee8d5baf417ee030f058_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, registry.redhat.io/openshift4/ose-sriov-network-operator@sha256:666ab87e49959766d0744e8395aacd54f06579066207ee8d5baf417ee030f058_amd64, * |
| Red Hat | registry.redhat.io/openshift4/ose-ansible-operator@sha256:bfeadf450453601556e47c0133d2020e1fa31f6faef86d3addb53435cb10ab3c_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/ose-ansible-operator@sha256:bfeadf450453601556e47c0133d2020e1fa31f6faef86d3addb53435cb10ab3c_amd64, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-webhook@sha256:e6705fc366af4fcd0f8a39fc4d93f8b4c1b10d992260f459f0787a0d19b2a641_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-cloud-event-proxy@sha256:00ac1d6e19468af785164348cdf75db6b2a8e6a2262e9f48d1edf81b320b444b_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | registry.redhat.io/openshift4/ose-cloud-event-proxy@sha256:00ac1d6e19468af785164348cdf75db6b2a8e6a2262e9f48d1edf81b320b444b_amd64 |
| Red Hat | registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:a338c8934f713453c1444d2843c1b68ff55958f56ca8a0bc66aad7befe5a0101_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-local-storage-mustgather-rhel9@sha256:2a3d8859889e2594262e01d08cf14f3b70f67e327a9bddb68ec732a37ce95e26_amd64 as a component of Red Hat OpenShift Container Platform 4.13 | *, registry.redhat.io/openshift4/ose-local-storage-mustgather-rhel9@sha256:2a3d8859889e2594262e01d08cf14f3b70f67e327a9bddb68ec732a37ce95e26_amd64, * |
…and 58 more
Timeline
- Apr 16, 2026 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 28, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2026:7253 advisory
- https://access.redhat.com/security/cve/CVE-2025-65637 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_7253.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418900 issue
- https://www.cve.org/CVERecord?id=CVE-2025-65637 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-65637 advisory
- https://github.com/mjuanxd/logrus-dos-poc exploit
- https://github.com/mjuanxd/logrus-dos-poc/blob/main/README.md exploit
- https://github.com/sirupsen/logrus/issues/1370 advisory
- https://github.com/sirupsen/logrus/pull/1376 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.8.3 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.1 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.3 advisory
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSIRUPSENLOGRUS-5564391 advisory