Red Hat released Important updates for Red Hat OpenShift Data Foundation (ODF) 4.14.18 and 4.15.14 on Red Hat Enterprise Linux 9, delivering refreshed container images and upgrading Ceph to RHCEPH-7.1z4. The updates affect x86_64, aarch64, ppc64le, and s390x deployments and also resolve an MDSCacheUsageHigh alert issue in the 4.15 stream.
The releases remediate vulnerabilities in bundled dependencies, including CVE-2024-39249, a regular-expression denial-of-service flaw in Node.js async autoinject; CVE-2024-29041, which can let malformed URLs bypass Express redirect allowlists; and CVE-2024-29180, a webpack-dev-middleware path-traversal issue that could disclose files. The advisories also address cross-site scripting, prototype-pollution, file-disclosure, and additional denial-of-service and memory-consumption flaws; Red Hat advises customers to apply applicable prior errata before upgrading.

See affected versions and whether adversaries are exploiting it.
14 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2025:1865 for updated OpenShift Data Foundation 4.15 container images on RHEL 9. The update remediated sensitive URL logging, prototype pollution, improper input validation, SSH authorization-bypass, and non-linear HTML parsing vulnerabilities across supported architectures.
Red Hat issued Important advisory RHSA-2025:1824, providing updated OpenShift Data Foundation 4.17 container images for RHEL 9. The update remediated node-gettext prototype pollution, PostCSS input-validation, Go SSH authorization-bypass, HTML parsing, and Kubernetes kubelet node-denial-of-service vulnerabilities.
Red Hat issued Important advisory RHSA-2025:1829 for updated OpenShift Data Foundation 4.16 container images on RHEL 9. The update remediated vulnerabilities including sensitive-information logging, prototype pollution, improper input validation, an SSH authorization bypass, and non-linear HTML parsing.
CVE-2023-44270 affects PostCSS versions before 8.4.31, where attacker-controlled CSS parsed as comments can subsequently be emitted as CSS rules or properties. Red Hat remediated the issue through advisories spanning OpenShift Container Platform, Service Mesh, Dev Spaces, Data Foundation, and OpenShift GitOps.
Red Hat issued Important advisory RHSA-2024:6755, providing updated OpenShift Data Foundation 4.16.2 container images for RHEL 9. The update addressed multiple dependency vulnerabilities, including CVE-2024-29180, and fixed PVC-mount, backing-store upgrade, disaster-recovery synchronization, and console issues.
OSIDB Bzimport reported CVE-2024-39249 to Red Hat as Bug 2295035. The flaw can cause regular-expression denial of service while nodejs-async's autoinject function parses functions.
Red Hat addressed CVE-2024-21528, a node-gettext addTranslations() prototype-pollution vulnerability caused by inadequate input sanitization, for RHODF 4.18 on RHEL 9 through RHSA-2025:2652.
CVE-2024-41818 is a regular-expression denial-of-service flaw in fast-xml-parser's currency.js value parser; crafted input can cause excessive processing and degrade availability. The issue was fixed in fast-xml-parser 4.4.1, and Red Hat remediated it through advisories for RHEL-9-CNV-4.16 and RHODF 4.14, 4.16, and 4.17.
CVE-2024-37890 allows an HTTP request exceeding server.maxHeadersCount to crash affected ws servers, causing denial of service. Upstream fixed the issue in ws 8.17.1 and backported fixes to versions 7.5.10, 6.2.3, and 5.2.4.
CVE-2024-28176 affects jose JWE decryption interfaces that decompress plaintext after decryption; crafted JWE input can cause excessive CPU or memory use and denial of service. The jose project fixed the issue in versions 2.0.7 and 4.15.5, and Red Hat tracked and remediated affected packages and products.
Red Hat published Important advisory RHSA-2025:8544 with updated OpenShift Data Foundation 4.15.14 container images for RHEL 9. It addressed numerous dependency vulnerabilities, including file disclosure, malformed-URL handling, XSS, prototype pollution, and denial-of-service flaws, and upgraded Ceph to RHCEPH-7.1z4.
Red Hat published Important advisory RHSA-2025:8551 with updated OpenShift Data Foundation 4.14.18 container images for RHEL 9. The update remediated multiple bundled-component vulnerabilities, including CVE-2024-29180, CVE-2024-29041, and CVE-2024-39249, and upgraded Ceph to RHCEPH-7.1z4.
Express versions before 4.19.0 and pre-release 5.0 alpha and beta versions were documented as susceptible to redirect-allowlist bypasses through malformed URLs passed to res.location() or res.redirect(). The issue was fixed in Express 4.19.2 and 5.0.0-beta.3.
webpack-dev-middleware versions before 5.3.4, 6.1.2, and 7.1.0 were documented as allowing encoded path traversal that could disclose arbitrary files from a developer machine. Upstream corrected URL unescaping and normalization in versions 5.3.4, 6.1.2, and 7.1.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
14 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.