Red Hat shipped a series of OpenShift Container Platform security updates across supported release streams, including 4.12.86, 4.13.64, 4.17.50, and 4.19.25, to remediate multiple flaws in bundled components. The fixes cover CVE-2025-9230 in OpenSSL, an out-of-bounds read and write in CMS password-based encryption handling that can crash applications or corrupt memory; CVE-2025-6176 in Scrapy, where brotli decompression can trigger denial of service through excessive memory consumption; CVE-2025-52881 in runc and opencontainers-selinux, which can enable container escape and denial of service; and CVE-2025-61726 in Go's net/url package, which can cause memory exhaustion during query parsing.
Red Hat rated the OpenShift 4.17 and 4.19 releases as Important because of the container escape and resource-exhaustion risks, while updates for 4.12 and 4.13 were published with Low security impact despite bundling fixes for OpenSSL, Scrapy/brotli, libssh, glib, and libpng issues. The advisories affect deployments on RHEL 8 and RHEL 9 across x86_64, ppc64le, s390x, and aarch64, and Red Hat urged customers to upgrade through the appropriate OpenShift release channels using the CLI or web console.

See real exploitation activity before you spend the cycle.
11 events from the most recent confirmed update back to the earliest known activity.
Red Hat released OpenShift Container Platform 4.15.62 as an Important security and bug-fix update for the 4.15 stream. The advisory remediated CVE-2025-6176 in Scrapy, CVE-2025-15467 in OpenSSL, CVE-2025-66293 in libpng, CVE-2024-28757 in expat, and CVE-2025-13601 in glib across supported architectures.
Red Hat released OpenShift Container Platform 4.12.86 as a bug-fix and security update rated Low impact. The release addressed CVE-2025-9230 in OpenSSL, CVE-2025-6176 in Scrapy/python-brotli, CVE-2025-66293 in libpng, and CVE-2025-69419 in OpenSSL.
Red Hat released OpenShift Container Platform 4.13.64 as a bug-fix and security update for the 4.13 stream. The advisory included fixes for CVE-2025-9230 in OpenSSL, CVE-2025-6176 in Scrapy/brotli, and additional bundled-component vulnerabilities.
Red Hat issued RHSA-2026:3416 for OpenShift Container Platform 4.17.50 with Important security impact. The release fixed CVE-2025-52881 in runc/opencontainers/selinux and CVE-2025-61726 in golang net/url.
Red Hat issued RHSA-2026:3391 for OpenShift Container Platform 4.19.25 and rated it Important. The update fixed CVE-2025-52881 in runc/opencontainers-selinux and CVE-2025-61726 in Go's net/url package.
Red Hat documented CVE-2025-6176 as a Scrapy brotli decompression-bomb denial-of-service issue affecting versions up to 2.13.2. The record states a remote server can crash vulnerable Scrapy clients with less than 80 GB of available memory.
Red Hat released OpenShift Container Platform 4.16.54 as an Important security and bug-fix update. The release addressed CVE-2025-11561 in sssd and CVE-2025-4953 in podman across supported architectures.
Red Hat released OpenShift Container Platform 4.17.45 with Important security impact. The update remediated CVE-2025-11561 in SSSD and CVE-2025-4953 in Podman and included refreshed container images and package fixes.
Red Hat released OpenShift Container Platform 4.13.62 as a bug-fix and security update for the 4.13 stream. The update fixed CVE-2025-4953 in podman, CVE-2025-5318 in libssh, and multiple runc flaws including CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881.
Red Hat documented CVE-2025-9230 as an OpenSSL flaw in CMS password-based encryption handling that can trigger out-of-bounds reads and writes during decryption of crafted messages. The issue affects OpenSSL 3.5, 3.4, 3.3, 3.2, 3.0, and 1.1.1, while OpenSSL FIPS modules are not affected.
The Scrapy denial-of-service flaw later tracked as CVE-2025-6176 was described in OSIDB Bzimport. The record notes the import occurred on 2025-10-31 01:01:20 UTC.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.