Red Hat issued security updates across OpenShift Container Platform (OCP), OpenShift API for Data Protection (OADP), Migration Toolkit for Containers, OpenShift Logging, and OpenShift Virtualization to remediate denial-of-service, memory-consumption, argument-injection, information-disclosure, and authorization-bypass risks. A recurring issue is CVE-2024-45338 in golang.org/x/net/html, whose non-linear parsing behavior can enable denial of service; it was addressed in OCP 4.17.16, OADP 1.3.7, OpenShift Logging 6.0.6, OpenShift Virtualization 4.16.7, and MTC 1.8.7. OCP 4.16.23 and 4.17.3 also fixed CVE-2024-24786, in which malformed JSON can cause an infinite loop in golang-protobuf processing.
OADP 1.4.5 additionally remediates Go-library flaws that could permit authorization bypass, HTTP request smuggling, memory-exhaustion denial of service, SSH key-exchange denial of service, and go-git argument injection. The go-git issue, CVE-2025-21613, affects versions before 5.13.0 when the file transport shells out to Git binaries and can allow attacker-controlled git-upload-pack flags. Red Hat directs affected administrators to apply prerequisite errata and upgrade through the appropriate OpenShift release channel or product-specific update procedures across supported RHEL 8 and RHEL 9 architectures.

See affected versions and whether adversaries are exploiting it.
40 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-severity RHSA-2025:11396 for OpenShift API for Data Protection 1.4.5, addressing authorization bypass, go-git argument injection, denial-of-service, memory-consumption, and HTTP request-smuggling vulnerabilities.
Red Hat issued Important-severity RHSA-2025:9646 for OpenShift API for Data Protection 1.3.7, fixing vulnerabilities in golang.org/x/net/html, golang.org/x/oauth2/jws, and golang-jwt/jwt.
Red Hat issued Important-severity RHSA-2025:8510 for MTC 1.8.7, remediating five denial-of-service or excessive-memory-consumption flaws in dependencies and fixing migration-plan, OADP compatibility, and Velero AWS-plugin backup issues.
Red Hat issued Important-severity RHSA-2025:3973 with OpenShift Virtualization 4.16.7 images, fixing Go net/http 100-continue denial of service and non-linear HTML parsing in golang.org/x/net/html.
Red Hat issued Important-severity RHSA-2025:3132 for Logging for Red Hat OpenShift 6.0.6, fixing Go JOSE parsing and golang.org/x/net/html denial-of-service flaws and resolving collector CrashLoopBackOff behavior.
Red Hat issued Important-severity advisory RHSA-2025:1870 for osp-director-operator-container in Red Hat OpenStack Platform 17.1 for RHEL 9. The update provides updated director container images to remediate go-git URL-field argument injection (CVE-2025-21613) and malicious Git-server reply denial of service (CVE-2025-21614).
Red Hat issued Important-severity RHSA-2024:6122 for OpenShift Container Platform 4.18.1, updating container images to address eight vulnerabilities including go-git URL argument injection and denial of service issues.
Red Hat issued Important-severity advisory RHSA-2025:0401 for Grafana on RHEL 8, releasing version 9.2.10-21.el8_10. The update fixes go-git URL-field argument injection (CVE-2025-21613) and denial of service through malicious Git-server replies (CVE-2025-21614).
Red Hat issued Moderate-severity RHSA-2024:8434 with updated OpenShift Container Platform 4.17.3 images and packages, fixing CVE-2024-24786, which could cause protojson.Unmarshal to loop indefinitely on malformed JSON.
Red Hat issued Moderate-severity RHSA-2024:3722 for OpenShift Container Platform 4.17.0, fixing CVE-2024-6104, which could log sensitive URL information, and CVE-2024-24789 in Go archive/zip handling of certain ZIP files.
Red Hat issued Important-severity advisory RHSA-2024:5200, releasing OpenShift Container Platform 4.12.63 images that fix issues including JWT issuer-validation bypass, a kernel route-management use-after-free, SSH prefix truncation, and sensitive URL logging.
Red Hat issued Important-severity RHSA-2024:5054 for OpenShift Virtualization 4.16.1 on RHEL 9. The updated images remediate CVE-2024-41818, a fast-xml-parser regular-expression denial of service flaw, and CVE-2024-24786, an infinite-loop denial of service flaw in golang-protobuf protojson unmarshaling.
Red Hat issued Moderate-severity advisory RHSA-2024:3790, releasing OADP 1.3.2 for RHEL 9. The update fixes five Go flaws involving multipart-form memory exhaustion, redirect header and cookie forwarding, X.509 verification panics, email display-name parsing, and HTML template escaping.
Red Hat issued Moderate-severity advisory RHSA-2024:1925 for Migration Toolkit for Containers 1.8.3 on RHEL 8 x86_64. The update fixes axios cookie data exposure (CVE-2023-45857), golang-protobuf protojson infinite-loop denial of service (CVE-2024-24786), and two MTC backup and controller-installation bugs.
Red Hat issued Important-severity RHSA-2023:3624 for Migration Toolkit for Containers 1.7.10 on RHEL 8 x86_64. The update remediated five Go flaws, including memory/resource-consumption denial of service, a go/parser infinite loop, and html/template JavaScript handling issues, and fixed Direct Volume Migration rsync problems.
Anten Skrabec reported CVE-2023-24540, a high-severity html/template sanitization flaw involving JavaScript whitespace characters outside the recognized set in templates containing actions. Go fixed the issue in versions 1.19.9 and 1.20.4, with fixes committed to the master, Go 1.19, and Go 1.20 branches.
Pedro Sampaio reported CVE-2023-24537, in which Go parsing functions can enter an infinite loop when processing //line directives with extremely large line numbers. Integer overflow causes the denial-of-service condition; the issue is tracked upstream as golang/go#59180 and #59274.
Red Hat issued RHSA-2023:1174 for OpenShift API for Data Protection 1.1 on RHEL 8, remediating CVE-2022-2879. The flaw in Go archive/tar Reader.Read could allow a crafted archive to exhaust memory or trigger a runtime panic.
Red Hat issued Important-severity RHSA-2023:0934 for Migration Toolkit for Applications 6.0.1 on x86_64. The update remediated eight vulnerabilities, including loader-utils prototype pollution and ReDoS, Apache Commons BCEL arbitrary bytecode generation, Go HTTP/2 memory exhaustion, and prototype-pollution flaws in qs and JSON5.
Red Hat issued Moderate-severity advisory RHSA-2023:0693, providing Migration Toolkit for Containers 1.7.7 for RHEL 8 x86_64. The update remediated multiple async and Go vulnerabilities and fixed Velero pod crashes that could leave migrations stuck in the Backup Phase.
Red Hat issued Moderate-severity RHSA-2023:0328 for RHEL 9, updating go-toolset and golang to version 1.18.9-1.el9_1. The update remediated CVE-2022-2879 archive/tar memory consumption, CVE-2022-2880 ReverseProxy query forwarding, and CVE-2022-41715 regular-expression parsing memory use, and fixed ppc64le linking and s390x crypto-test issues.
Red Hat issued Moderate-severity RHSA-2023:0264 for Logging Subsystem 5.6.0 on RHEL 8. The update fixed nine vulnerabilities, including loader-utils prototype pollution, Jackson deeply nested-data denial of service, and multiple Go flaws affecting archive/tar, ReverseProxy, regexp parsing, HTTP/2 handling, and URL path normalization.
Red Hat issued Moderate-severity RHSA-2022:8781 for OpenShift Logging Subsystem 5.5.5 on RHEL 8. The update remediated Jackson, loader-utils, and Go denial-of-service flaws, including CVE-2022-2879, CVE-2022-2880, CVE-2022-41715, and Go net/http GOAWAY error handling.
Vipul Nair reported CVE-2022-37603, a regular-expression denial-of-service vulnerability in webpack loader-utils 2.0.0. Processing an attacker-controlled url value through the interpolateName function could trigger the vulnerable regular-expression behavior.
Red Hat issued RHSA-2022:7129 for RHEL 8 git-lfs, remediating CVE-2022-32189 in Go's math/big package. A too-short encoded message supplied to Float.GobDecode or Rat.GobDecode could trigger a panic and denial of service.
Red Hat published CVE-2022-41715, a Moderate-severity denial-of-service flaw in Go regular-expression parsing that could cause excessive memory use when applications compile attacker-controlled expressions. Go mitigated the issue by limiting parsing of an individual regular expression to a 256 MB memory footprint and rejecting expressions exceeding that limit.
Red Hat published CVE-2022-2880, a Moderate-severity HTTP request-smuggling flaw in Go's net/http/httputil ReverseProxy. The issue could forward malformed raw query parameters for inconsistent downstream interpretation; Go fixed it by sanitizing forwarded parameters when the reverse proxy has parsed the outbound request form.
Red Hat published CVE-2022-27664, a Moderate-severity denial-of-service flaw in Go's net/http HTTP/2 implementation. A fatal error that preempts shutdown can leave a closing HTTP/2 connection hung, consuming resources and reducing availability; Red Hat subsequently issued fixes across affected RHEL and OpenShift-related components.
Red Hat published CVE-2022-1705, a Moderate-severity HTTP request-smuggling vulnerability in Go's net/http HTTP/1 client. Invalid Transfer-Encoding headers indicating chunked encoding could be accepted and enable request smuggling when an intermediate server also improperly accepts the header.
CVE-2021-43797 affects Netty's netty-codec-http package, which accepted unauthorized control characters at the beginning or end of HTTP requests. The inconsistent request interpretation could enable HTTP request smuggling; Netty corrected the issue in netty-codec-http 4.1.72.Final, and Red Hat issued fixes for supported products.
Red Hat addressed the Go net/http/httputil ReverseProxy query-parameter-smuggling flaw, CVE-2022-2880, for Red Hat Developer Tools through advisory RHSA-2023:0445.
Red Hat released an Important-severity update for OpenShift Container Platform 4.16.36 with updated RPM packages and container images. The release remediates go-git URL-field argument injection (CVE-2025-21613) and denial of service via malicious Git-server replies (CVE-2025-21614).
Red Hat released an Important-severity OpenShift Container Platform 4.17.14 update with updated RPM packages and container images. The release fixes CVE-2024-45337, an SSH authorization-bypass issue, and CVE-2024-45338, a non-linear HTML parsing flaw.
Red Hat released an Important-severity OpenShift Container Platform 4.17.16 update fixing Python path traversal, rsync information disclosure, golang.org/x/net/html parsing, and Unbound denial-of-service vulnerabilities.
Red Hat released a Moderate-severity OpenShift Container Platform 4.16.23 update with container images and a fix for CVE-2024-24786, an infinite-loop condition in golang-protobuf protojson.Unmarshal.
go-git versions before 5.13.0 were vulnerable to argument injection when using the file transport protocol, allowing arbitrary git-upload-pack flag values; version 5.13.0 fixed the issue.
Red Hat closed its bug record for CVE-2022-32189, the Go math/big decoding panic denial-of-service flaw. The closure noted that product-specific remediation updates would continue to be reflected on the CVE page.
Red Hat closed its bug record for CVE-2022-32149, a denial-of-service flaw in golang.org/x/text/language where crafted Accept-Language headers could cause excessive ParseAcceptLanguage processing. The issue was fixed upstream in golang.org/x/text 0.3.8 and had been addressed in multiple Red Hat product advisories.
Red Hat released Moderate-severity OpenShift Container Platform 4.12.0 updates for RHEL 8 and RHEL 9 across supported architectures. The update remediated ten vulnerabilities, including Go archive/tar memory exhaustion (CVE-2022-2879), Go HTTP proxy and header-handling flaws, Prometheus denial of service, Vault CRL validation, and an OpenShift etcd gRPC proxy birthday-attack issue.
Go remediated CVE-2022-2879, in which archive/tar Reader.Read accepted unbounded file-header blocks that could cause memory exhaustion or application panics. The fix limits processed header blocks to 1 MiB and was committed to the master, Go 1.18, and Go 1.19 branches.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
42 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.