Red Hat released Important-rated OpenShift Container Platform updates for versions 4.15, 4.16, 4.17, and 4.18, including 4.15.50, 4.16.33, 4.17.25, 4.18.8, and 4.18.9. The releases remediate CVE-2025-30204, a high-severity denial-of-service flaw in golang-jwt/jwt where JWT header parsing can cause excessive memory allocation from attacker-controlled tokens containing numerous period characters. Fixed upstream versions are 4.5.2 and 5.2.2.
The updates also address CVE-2024-11218, a Podman/Buildah race condition that can enable container breakout, plus flaws in GRUB2, libxml2, Jinja2, BIND, and go-jose. Several releases fix CVE-2025-29781, in which the Bare Metal Operator's BMCEventSubscription custom resource could expose secrets across namespaces. Red Hat advises affected organizations to upgrade clusters through their applicable OpenShift release channels using the OpenShift CLI or web console across supported RHEL 8 and RHEL 9 platforms.

See real exploitation activity before you spend the cycle.
22 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2025:11669, releasing OpenShift Container Platform 4.14.54 container images for RHEL 8 and RHEL 9. The update remediated CVE-2024-45338 in golang.org/x/net/html, CVE-2025-22868 in golang.org/x/oauth2/jws, CVE-2025-30204 in golang-jwt/jwt, and CVE-2024-6104 in go-retryablehttp.
Red Hat issued Important-rated RHSA-2025:9259 for OpenShift Container Platform 4.15.53. The update provides revised container images and packages that fix the golang-jwt/jwt excessive-memory-allocation vulnerability CVE-2025-30204, along with non-security fixes.
Red Hat issued Important-rated RHSA-2025:9541 for Submariner 0.17.6 in Red Hat Advanced Cluster Management for Kubernetes 2.10. The update remediated CVE-2025-22868 in golang.org/x/oauth2/jws and CVE-2025-30204 in golang-jwt/jwt, and provided updated Submariner container images.
Red Hat issued RHSA-2025:8390 for Multicluster Engine for Kubernetes 2.4.9, providing updated General Availability container images. The Low-impact update fixes the golang-jwt/jwt memory-allocation flaw CVE-2025-30204 and the golang.org/x/oauth2/jws memory-consumption flaw CVE-2025-22868.
Red Hat issued Important-rated RHSA-2025:4422 and released OpenShift Container Platform 4.15.50. The release fixed seven vulnerabilities, including libxslt use-after-free flaws, a GRUB2 out-of-bounds write, CVE-2025-30204, and the Bare Metal Operator secret-exposure flaw CVE-2025-29781.
Red Hat issued Important-rated RHSA-2025:4473 for Multicluster Engine for Kubernetes 2.5.9, providing updated General Availability container images across supported architectures. The update remediated CVE-2025-22868 in golang.org/x/oauth2/jws and CVE-2025-30204 in golang-jwt/jwt, both involving excessive memory consumption during attacker-controlled token parsing.
Red Hat issued Important-rated RHSA-2025:4008, releasing OpenShift Container Platform 4.16.39 for RHEL 9 architectures. The update fixed the Bare Metal Operator cross-namespace secret-exposure flaw CVE-2025-29781 and the golang-jwt/jwt excessive-memory-allocation flaw CVE-2025-30204.
Red Hat issued Important-rated RHSA-2025:4019, releasing OpenShift Container Platform 4.18.10 for RHEL 8 and RHEL 9. The update remediated CVE-2025-30204 in golang-jwt/jwt as well as vulnerabilities in Helm, DOMPurify, and the Linux kernel ALSA USB-audio subsystem.
Red Hat issued Important-rated RHSA-2025:3790, releasing OpenShift Container Platform 4.15.49 for RHEL 8 and RHEL 9. The update fixed CVE-2025-22868 in golang.org/x/oauth2/jws, which could cause unexpected memory consumption during token parsing, and CVE-2025-30204 in golang-jwt/jwt.
Red Hat issued Important-rated RHSA-2025:3775 for OpenShift Container Platform 4.18.9. The update remediated vulnerabilities in BIND, libxml2, Jinja2, golang-jwt/jwt, go-jose, and the Bare Metal Operator, including CVE-2025-29781, which could expose secrets from other namespaces.
Red Hat issued Important-rated RHSA-2025:3798 for OpenShift Container Platform 4.17.25. The release fixed the Podman/Buildah container-breakout issue, golang-jwt/jwt memory-allocation flaw, libxml use-after-free, and Bare Metal Operator cross-namespace secret exposure.
Red Hat issued Important-rated RHSA-2025:3577 for OpenShift Container Platform 4.18.8. It addressed CVE-2024-11218 in Podman/Buildah, CVE-2025-0624 in GRUB2, CVE-2025-30204 in golang-jwt/jwt, and additional vulnerabilities.
Red Hat issued RHSA-2025:3503 to remediate the golang-jwt/jwt denial-of-service vulnerability CVE-2025-30204 in listed Cryostat 4 on RHEL 9 components. The update covered Cryostat agent, database, dashboard, console plugin, operator, OAuth proxy, reports, storage, and related container components.
Red Hat reported CVE-2025-30204, a high-severity denial-of-service flaw in golang-jwt/jwt parsing. Malicious JWT input containing numerous period characters could cause excessive memory allocation through strings.Split processing.
Red Hat issued Important-rated RHSA-2025:0830 for OpenShift Container Platform 4.16.33. The update remediated the Podman/Buildah container-breakout flaw CVE-2024-11218 and Jinja2 sandbox-breakout vulnerabilities CVE-2024-56201 and CVE-2024-56326.
Tej Rathi reported CVE-2024-24786, a medium-severity denial-of-service flaw in Go protobuf's protojson and internal JSON encoding components. Crafted invalid JSON could cause protojson.Unmarshal to loop indefinitely when processing messages with google.protobuf.Any or when DiscardUnknown is enabled.
Red Hat released Important-rated RHSA-2025:8560 for OpenShift Container Platform 4.18.17 on RHEL 8 and RHEL 9. The update remediates the golang-jwt/jwt resource-exhaustion vulnerability CVE-2025-30204 and resolves several platform defects.
Red Hat released Important-rated OpenShift Container Platform 4.17.33, fixing the golang-jwt/jwt excessive-memory-allocation denial-of-service flaw CVE-2025-30204. The update also lists CVE-2025-31205 and CVE-2025-31257 and resolves several OpenShift functional defects.
Red Hat released Important-rated OpenShift Container Platform 4.18.11 with updated packages and container images for supported RHEL 8 and RHEL 9 architectures. The update fixes CRI-O cross-namespace checkpoint-restore issue CVE-2024-8676, Go JOSE parsing denial-of-service flaw CVE-2025-27144, and golang-jwt/jwt memory-exhaustion flaw CVE-2025-30204.
Red Hat released Important-rated OpenShift Container Platform 4.17.27 with revised packages and container images for supported architectures. The update fixes the golang-jwt/jwt excessive-memory-allocation flaw CVE-2025-30204 and golang-protobuf protojson.Unmarshal infinite-loop flaw CVE-2024-24786.
Red Hat documented CVE-2025-27144, in which Go JOSE 4.x before 4.0.5 could allocate excessive memory when parsing compact JWS or JWE tokens containing many period characters. Red Hat distributed fixes through advisories for OpenShift, RHEL 9 and 10, and related products.
Red Hat released Important-rated OpenShift Container Platform 4.17.24 with updated packages and container images for supported RHEL 8 and RHEL 9 architectures. The update remediates CVE-2025-30204 in golang-jwt/jwt, which can cause excessive memory allocation while parsing JWT headers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
24 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.