VDB
RHSA-2026%3A8431
RHSA-2026%3A8431
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in the net/url package in the Go standard library. The package does not enforce a limit on the number of unique query parameters it parses. A Go application using the net/http.Request.ParseForm method will try to process all parameters provided in the request. A specially crafted HTTP request containing a massive number of query parameters will cause the application to consume an excessive amount of memory, eventually causing the application to crash or become unresponsive, resulting in a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/openshift4/ose-local-storage-rhel9-operator@sha256:1c3e3c380e46f6a9031387239dc815d34815814dcf0be002122b50bd875eb3b8_amd64 as a component of Red Hat OpenShift Container Platform 4.2 | *, registry.redhat.io/openshift4/ose-local-storage-rhel9-operator@sha256:1c3e3c380e46f6a9031387239dc815d34815814dcf0be002122b50bd875eb3b8_amd64, * |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-webhook-rhel9@sha256:c9245ec1e6755680ef846a0fdfb98f4bedc8f0ea75effa2d2b2c8104674e456a_ppc64le as a component of Red Hat OpenShift Container Platform 4.20 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-clusterresourceoverride-rhel9-operator@sha256:48b052501b2997913a638f2b9f3a2ba3efca82e4abb18708d6d77028b4444e5e_amd64 as a component of Red Hat OpenShift Container Platform 4.20 | *, *, * |
| golang | Go | |
| Red Hat | registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:ef5f60098b7de71781948f49fce50393aadb54a2dc8a7b43b9ad1fb79a790c57_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:ef5f60098b7de71781948f49fce50393aadb54a2dc8a7b43b9ad1fb79a790c57_ppc64le, registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:ef5f60098b7de71781948f49fce50393aadb54a2dc8a7b43b9ad1fb79a790c57_ppc64le, registry.redhat.io/openshift4/ingress-node-firewall-rhel9-operator@sha256:ef5f60098b7de71781948f49fce50393aadb54a2dc8a7b43b9ad1fb79a790c57_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:51666d191490b1a1a28a75ebfc121705a5485dc069aefe78b4c0585749613008_arm64 as a component of Red Hat OpenShift Container Platform 4.2 | *, registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:51666d191490b1a1a28a75ebfc121705a5485dc069aefe78b4c0585749613008_arm64, registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:51666d191490b1a1a28a75ebfc121705a5485dc069aefe78b4c0585749613008_arm64 |
| Red Hat | registry.redhat.io/openshift4/pf-status-relay-rhel9-operator@sha256:0204237eff722e6c94aa9da2868447a66837ec8327d8afd8920f06cd8735e2e1_amd64 as a component of Red Hat OpenShift Container Platform 4.20 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-rdma-cni-rhel9@sha256:9ee55490f62eefede07e6b3bc518573eb4392ca21908017bd40f77baee375a23_arm64 as a component of Red Hat OpenShift Container Platform 4.20 | *, *, registry.redhat.io/openshift4/ose-sriov-rdma-cni-rhel9@sha256:9ee55490f62eefede07e6b3bc518573eb4392ca21908017bd40f77baee375a23_arm64 |
| Red Hat | registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:bc4220e76ffbb383a1083156e1b2b15fa43f3b2331ba88cb3bad167fb71e9491_arm64 as a component of Red Hat OpenShift Container Platform 4.2 | registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:bc4220e76ffbb383a1083156e1b2b15fa43f3b2331ba88cb3bad167fb71e9491_arm64, registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:bc4220e76ffbb383a1083156e1b2b15fa43f3b2331ba88cb3bad167fb71e9491_arm64, registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:bc4220e76ffbb383a1083156e1b2b15fa43f3b2331ba88cb3bad167fb71e9491_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-local-storage-diskmaker-rhel9@sha256:ad487ac7de4b160f662f618d648202eaddc551ecc19bba0c24ac2c8d356305dc_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | *, registry.redhat.io/openshift4/ose-local-storage-diskmaker-rhel9@sha256:ad487ac7de4b160f662f618d648202eaddc551ecc19bba0c24ac2c8d356305dc_ppc64le, registry.redhat.io/openshift4/ose-local-storage-diskmaker-rhel9@sha256:ad487ac7de4b160f662f618d648202eaddc551ecc19bba0c24ac2c8d356305dc_ppc64le |
| Red Hat | registry.redhat.io/openshift4/pf-status-relay-rhel9-operator@sha256:61f6fedc1850e7a6b4fa8cab80e276dbb00ad7e0606d8d8691751d46be28da6d_arm64 as a component of Red Hat OpenShift Container Platform 4.20 | registry.redhat.io/openshift4/pf-status-relay-rhel9-operator@sha256:61f6fedc1850e7a6b4fa8cab80e276dbb00ad7e0606d8d8691751d46be28da6d_arm64, registry.redhat.io/openshift4/pf-status-relay-rhel9-operator@sha256:61f6fedc1850e7a6b4fa8cab80e276dbb00ad7e0606d8d8691751d46be28da6d_arm64, * |
| Red Hat | registry.redhat.io/openshift4/ose-dpu-cni-rhel9@sha256:680d96a8500a994cdad6236100fb1a6cead09b7c9eb84a24f2c2f4796f4711f0_s390x as a component of Red Hat OpenShift Container Platform 4.20 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-capacity-rhel9@sha256:7e8f02fd96b3825f681c96b7768b6e79a0eee8669b554609dac6909400bc800b_amd64 as a component of Red Hat OpenShift Container Platform 4.2 | *, *, registry.redhat.io/openshift4/ose-cluster-capacity-rhel9@sha256:7e8f02fd96b3825f681c96b7768b6e79a0eee8669b554609dac6909400bc800b_amd64 |
| Red Hat | registry.redhat.io/openshift4/sriov-cni-rhel9@sha256:bc4220e76ffbb383a1083156e1b2b15fa43f3b2331ba88cb3bad167fb71e9491_arm64 as a component of Red Hat OpenShift Container Platform 4.20 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-rhel9-operator@sha256:f64bb77f25a652fef9070b80b88f9128e5ef3a7e5c47555a3474144bfede8c5e_ppc64le as a component of Red Hat OpenShift Container Platform 4.2 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-dp-admission-controller-rhel9@sha256:69273213f39430c6fb91e610cefedbf2347260f397d77e79375126fc58a2ba14_arm64 as a component of Red Hat OpenShift Container Platform 4.20 | registry.redhat.io/openshift4/ose-sriov-dp-admission-controller-rhel9@sha256:69273213f39430c6fb91e610cefedbf2347260f397d77e79375126fc58a2ba14_arm64, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-sriov-network-webhook-rhel9@sha256:e486f9e739805facb651e2e132b0a08dd0c3f3468b90de9c5c39f8c46759ebdc_amd64 as a component of Red Hat OpenShift Container Platform 4.2 | registry.redhat.io/openshift4/ose-sriov-network-webhook-rhel9@sha256:e486f9e739805facb651e2e132b0a08dd0c3f3468b90de9c5c39f8c46759ebdc_amd64, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-kubernetes-nmstate-handler-rhel9@sha256:f94716b18eb6d7ac67f63148a74492ceaf82e5c1c798f737551b0557b690855e_s390x as a component of Red Hat OpenShift Container Platform 4.20 | *, *, registry.redhat.io/openshift4/ose-kubernetes-nmstate-handler-rhel9@sha256:f94716b18eb6d7ac67f63148a74492ceaf82e5c1c798f737551b0557b690855e_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-cloud-event-proxy-rhel9@sha256:79ddf867b6c7dae491b5efa37cbe4abf20d1a47955e52c2ea307dafd2e72a7d2_amd64 as a component of Red Hat OpenShift Container Platform 4.20 | *, *, * |
| Red Hat | registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:d740657be6105af312e4268e9d7696f7ea2d24d4f6fc890af51cd6ce648634ef_s390x as a component of Red Hat OpenShift Container Platform 4.2 | registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:d740657be6105af312e4268e9d7696f7ea2d24d4f6fc890af51cd6ce648634ef_s390x, registry.redhat.io/openshift4/ose-node-feature-discovery-rhel9@sha256:d740657be6105af312e4268e9d7696f7ea2d24d4f6fc890af51cd6ce648634ef_s390x, * |
…and 519 more
Timeline
- Apr 22, 2026 CVE Published
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Aug 1, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2026:8431 advisory
- https://access.redhat.com/security/cve/CVE-2025-61726 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_8431.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2434432 issue
- https://www.cve.org/CVERecord?id=CVE-2025-61726 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-61726 advisory
- https://go.dev/cl/736712 advisory
- https://go.dev/issue/77101 advisory
- https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc advisory
- https://pkg.go.dev/vuln/GO-2026-4341 advisory