Red Hat disclosed and remediated CVE-2025-65637, a Moderate-severity denial-of-service flaw in the Go logging library github.com/sirupsen/logrus. The bug is triggered when applications use Entry.Writer() to process a single-line payload larger than 64 KB with no newline characters, causing Go's internal bufio.Scanner to raise a "token too long" error, close the writer pipe, and leave the logging interface unusable. Red Hat said the issue can disrupt logging and degrade application availability, though exploitation depends on a specific non-default usage pattern and affects availability rather than confidentiality or integrity.
The vendor published fixes across multiple downstream products and package streams in 2026, including updated Logrus versions 1.8.3, 1.9.1, and 1.9.3 or later that chunk oversized input so logging continues even when an error occurs. Red Hat advisories covered affected RHEL 8 components such as osbuild-composer under RHSA-2026:2687, as well as Red Hat OpenStack Services on OpenShift 18.0.18 under RHSA-2026:7885, where the Logrus flaw was addressed alongside CVE-2025-68121 in crypto/tls. Updated RPM and SRPM packages were released for impacted RHEL and OpenShift-related environments.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Unity Linux 20 published security advisory UTSA-2026-102702 warning that the skopeo package is affected by CVE-2025-65637, a denial-of-service flaw in github.com/sirupsen/logrus. The advisory recommended updating skopeo on affected hosts to remediate the issue.
Red Hat published RHSA-2026:7885 for golang-github-openstack-k8s-operators-os-diff in Red Hat OpenStack Services on OpenShift 18.0.18, fixing CVE-2025-65637 and CVE-2025-68121. Updated RPM and SRPM packages were released for affected x86_64 products.
Red Hat listed CVE-2025-65637 as fixed for Red Hat Enterprise Linux 8 container-tools:rhel8 under advisory RHSA-2026:3428.
Red Hat published RHSA-2026:2687 to fix CVE-2025-65637 in osbuild-composer for multiple RHEL 8.6 support channels, providing updated packages version 46.3-5.el8_6. The advisory covered x86_64 and ppc64le offerings including AUS, TUS, and SAP-related services.
OSIDB recorded the vulnerability description for CVE-2025-65637, a denial-of-service flaw in github.com/sirupsen/logrus triggered by oversized single-line payloads passed to Entry.Writer().
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.