Red Hat released updated OpenTelemetry Collector packages for RHEL 9 and RHEL 10 to remediate denial-of-service and memory-exhaustion vulnerabilities in bundled Go dependencies. The updates address CVE-2025-27144 in Go JOSE parsing, CVE-2025-22868, CVE-2025-29786, and CVE-2025-30204; the RHEL 9 advisory also covers CVE-2024-45336, which could expose sensitive HTTP headers through a cross-domain redirect. Fixed packages are opentelemetry-collector-0.107.0-8.el9_6 for RHEL 9 and opentelemetry-collector-0.107.0-9.el10_0 for RHEL 10, across x86_64, s390x, ppc64le, and aarch64 systems.
The same vulnerable dependencies affected Red Hat OpenShift products. OpenShift Container Platform 4.17.22 fixes the Go JOSE parsing DoS issue, while Logging for OpenShift 5.9.13 addresses denial-of-service and local-file-inclusion flaws in Net::IMAP, Rack::Static, Go JOSE, and golang-jwt/jwt. Red Hat also shipped updated OpenShift Container Platform 4.14.51 and OpenShift Data Foundation images, including fixes for CVE-2025-30204; administrators should apply the relevant RHEL package, OpenShift release, logging-stack, and container-image updates through supported channels.

See affected versions and whether adversaries are exploiting it.
14 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2025:8299 for OpenShift Container Platform 4.15.52. The update remediated CVE-2025-22868, a golang.org/x/oauth2/jws token-parsing flaw that can cause unexpected memory consumption, along with product bug fixes.
Red Hat issued Moderate advisory RHSA-2025:4712 for OpenShift Container Platform 4.18.13, updating packages and container images across supported architectures. The release remediated CVE-2025-27144, a Go JOSE parsing denial-of-service vulnerability, and included operational fixes such as correcting oc-mirror error handling and DHCP CNI overflow.
Red Hat issued Important advisory RHSA-2025:7479 for opentelemetry-collector on RHEL 10, releasing version 0.107.0-9.el10_0. The update addressed CVE-2025-27144, CVE-2025-22868, CVE-2025-29786, and CVE-2025-30204.
Red Hat issued Important advisory RHSA-2025:7407 for the Red Hat build of OpenTelemetry Collector on RHEL 9, providing fixed version 0.107.0-8.el9_6. It remediated Go JOSE, OAuth2/JWS, Expr parser, and jwt-go denial-of-service or memory-exhaustion vulnerabilities.
Red Hat issued Important advisory RHSA-2025:4511 with updated RHODF-4.18-RHEL-9 container images. The update remediated flaws in Express, npm-serialize-javascript, http-proxy-middleware, Go JOSE, OAuth2/JWS, Go SSH, and jwt-go.
Red Hat issued Important advisory RHSA-2025:4177 for OpenShift Container Platform 4.14.51. The release addressed excessive JWT-header memory allocation, a Helm YAML-content panic, a Linux USB-audio out-of-bounds read, and cross-namespace secret exposure through the Bare Metal Operator BMCEventSubscription CRD.
Red Hat issued Important advisory RHSA-2025:3906 for Logging for Red Hat OpenShift 5.9.13. Updated logging images remediated Net::IMAP memory-exhaustion DoS, Rack::Static local file inclusion, and Go JOSE and jwt-go parsing issues.
Red Hat issued Important advisory RHSA-2025:3335 for opentelemetry-collector on RHEL 9, supplying version 0.107.0-8.el9_5. The update addressed a Go net/http cross-domain redirect header-disclosure issue and DoS or memory-exhaustion flaws in go-jose, oauth2/jws, and Expr.
Red Hat issued Moderate advisory RHSA-2025:3061 for OpenShift Container Platform 4.17.22, remediating CVE-2025-27144, a denial-of-service vulnerability in Go JOSE parsing.
Red Hat issued Important advisory RHSA-2025:2652 with updated ODF 4.18.0 RHEL 9 images. It fixed vulnerabilities including node-gettext prototype pollution, cross-spawn ReDoS, an SSH authorization-bypass condition, and a Kubernetes kubelet node DoS issue.
Red Hat issued RHSA-2025:0892, an Important advisory releasing OpenShift Dev Spaces 3.18.0. The update remediated vulnerabilities in cross-spawn, PostCSS, golang.org/x/crypto, golang.org/x/net, DOMPurify, and nanoid.
Red Hat reported Bug 2319884 for CVE-2024-21536, a denial-of-service flaw in http-proxy-middleware in which requests to certain paths can trigger an unhandled promise rejection and crash a Node.js server.
Red Hat addressed CVE-2024-45336, in which Go's HTTP client could restore sensitive headers after a cross-domain redirect followed by a same-domain redirect. Fixes were issued across affected RHEL, OpenShift Service Mesh, Advanced Cluster Management, Satellite Client, RHOL, and Kubernetes-management products through multiple RHSA advisories.
Red Hat addressed CVE-2025-29786, an Expr parser memory-exhaustion denial-of-service flaw, for Red Hat Enterprise Linux 9.4 Extended Update Support through RHSA-2025:3593. Expr 1.17.0 added AST-node and parsing-memory limits to prevent unbounded expressions from exhausting process memory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
16 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.