Red Hat released security updates across OpenShift Container Platform (OCP) 4.12 through 4.16 and OpenShift Serverless, remediating vulnerabilities in bundled Go, Linux kernel, glibc, OpenTelemetry, BIND, Ironic, Gunicorn, Werkzeug, and related components. The issues include HTTP/2 and multipart-form memory-exhaustion denial of service—such as CVE-2023-45288 and CVE-2023-45290—sensitive URL data written to logs (CVE-2024-6104), cluster-monitoring credential leakage, unauthenticated local access and data exposure in OpenStack Ironic, and an SSH prefix-truncation attack. OpenShift 4.16.0 addressed 16 vulnerabilities, while the 4.14.39 update also fixed a glibc iconv out-of-bounds write that may allow remote code execution.
Affected organizations should update OCP container images and packages through their supported release channels using the OpenShift CLI or web console, prioritizing deployed 4.12, 4.14, 4.15, and 4.16 clusters. The advisories cover RHEL 8 and RHEL 9 deployments across x86_64, s390x, ppc64le, and aarch64 where applicable; OpenShift Serverless 1.33.0 also updates Serverless Operator components for OCP 4.12–4.16. Red Hat separately updated the RHEL 9 Go toolchain to version golang-1.21.9-2.el9_4, addressing HTTP processing, certificate-verification, redirect-forwarding, template escaping, and cryptographic flaws that affect Go-based workloads and platform components.

See real exploitation activity before you spend the cycle.
61 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2025:9759 for OpenShift Container Platform 4.14.53, providing updated container images and packages for RHEL 8 and RHEL 9. The update remediated CVE-2024-45497, which could let an OpenShift build overwrite node pull credentials, and CVE-2025-22868, an oauth2/jws token-parsing memory-consumption flaw.
Red Hat issued Moderate advisory RHSA-2025:0029 for OpenShift Container Platform 4.14.44, supplying updated packages and container images. The release remediated the OpenTelemetry otelgrpc metric-cardinality denial-of-service flaw CVE-2023-47108 and the go-retryablehttp sensitive-URL logging flaw CVE-2024-6104.
Red Hat issued RHSA-2024:11293 to remediate the OpenTelemetry otelgrpc metric-cardinality memory-exhaustion flaw, CVE-2023-47108, in listed Multicluster Engine for Kubernetes 2.6 components for RHEL 8 and RHEL 9.
Red Hat issued Important advisory RHSA-2024:8235, releasing OpenShift Container Platform 4.14.39 images. The update fixed Go and OpenTelemetry denial-of-service issues, a glibc iconv out-of-bounds write that could enable remote code execution, SSH prefix truncation, and an OpenStack Ironic data-exposure flaw.
Red Hat issued RHSA-2024:8040 to remediate CVE-2024-6104 in Cluster Observability Operator 0.4 components for RHEL 8. The go-retryablehttp flaw could expose authentication information because insufficiently sanitized URLs were written to logs.
Red Hat issued Important advisory RHSA-2024:7594 for OpenShift Container Platform 4.15.36, providing updated container images. The release remediated CVE-2024-2961, a glibc iconv out-of-bounds write that may allow remote code execution, and CVE-2024-44082, an OpenStack Ironic crafted-image data-exposure flaw.
Red Hat issued Moderate advisory RHSA-2024:7184 for OpenShift Container Platform 4.14.38, supplying updated container images and packages. The update addressed denial-of-service flaws in goproxy, OpenTelemetry otelgrpc, and golang-protobuf JSON unmarshalling, plus sensitive URL logging in go-retryablehttp.
Red Hat issued Important advisory RHSA-2024:6642 for OpenShift Container Platform 4.12.65. It remediated Go HTTP/2 denial of service, BIND database slowdown and SIG(0) CPU-exhaustion flaws, and sensitive URL exposure through go-retryablehttp logs.
Red Hat issued Moderate advisory RHSA-2024:6409 for OpenShift Container Platform 4.15.31. The update addressed denial-of-service flaws in Go HTTP/2, OpenTelemetry gRPC metrics, and protobuf JSON unmarshalling, as well as go-retryablehttp sensitive URL logging.
CVE-2024-44082 was reported after the OpenStack community identified that Ironic's use of qemu-img without an explicitly specified image format could process unsafe untrusted-image data. A specially crafted image could allow an authenticated user to access potentially sensitive data.
Red Hat issued RHSA-2024:5808 and RHSA-2024:5810 for OpenShift Container Platform 4.12.64, supplying container images and RPM updates. The combined release addressed Go multipart-form memory exhaustion, sensitive URL data written to logs, incorrect net/netip IPv4-mapped IPv6 behavior, and a Werkzeug issue that could allow code execution on a developer machine.
Red Hat issued Important advisory RHSA-2024:5433 for OpenShift Container Platform 4.14.35. The release addressed a Linux kernel route-management use-after-free flaw, OpenTelemetry and Go denial-of-service issues, an SSH prefix-truncation issue, and sensitive URL logging in go-retryablehttp.
Red Hat issued Moderate advisory RHSA-2024:4872, releasing OpenShift Serverless 1.33.1 for OpenShift Container Platform 4.12 through 4.16. The update fixed Go DNS parsing, ZIP handling, and IPv4-mapped IPv6 issues, plus sensitive URL logging in go-retryablehttp.
Red Hat issued Important advisory RHSA-2024:4484, releasing OpenShift Container Platform 4.13.45 container images. The update remediated Go HTTP/2 denial of service, an OpenShift Telemetry JWT issuer-validation bypass, regreSSHion, SSH prefix truncation, and jose-go compressed-data handling flaws.
Red Hat issued Critical advisory RHSA-2024:0041 for OpenShift Container Platform 4.16.0. Updated images addressed 16 vulnerabilities, including flaws that could leak files or credentials, cause denial of service, expose secrets, or enable SSH prefix-truncation attacks.
Patrick Del Bello reported CVE-2024-6104, an information-disclosure flaw in HashiCorp go-retryablehttp before 0.7.7 that logged unsanitized URLs and could expose embedded HTTP Basic Authentication credentials. Version 0.7.7 remediated the issue.
Red Hat issued Moderate advisory RHSA-2024:4028 for OpenShift Serverless 1.33.0, supported on OpenShift 4.12 through 4.16. The release fixed vulnerabilities in Go components, Quarkus Core, Netty HTTP codec, and jose-go, including CVE-2024-24785.
Red Hat issued Important advisory RHSA-2024:3713 for OpenShift Container Platform 4.12.59, providing updated packages and container images for supported RHEL 8 and RHEL 9 architectures. The update remediated CVE-2024-1135, a Gunicorn Transfer-Encoding HTTP request-smuggling flaw, alongside other listed CVEs and OpenShift operational fixes.
Red Hat issued RHBA-2024:3413 updating the dpdk-base container image for OpenShift Container Platform 4.12 on RHEL 8 x86_64. The update addressed four glibc netgroup-cache vulnerabilities (CVE-2024-33599 through CVE-2024-33602), and Red Hat advised users to upgrade and rebuild dependent images.
Red Hat issued RHBA-2024:3390 updating the Windows Machine Config Operator container image for OpenShift Container Platform 4.12 on RHEL 8 x86_64. The image addressed four glibc netgroup-cache flaws (CVE-2024-33599 through CVE-2024-33602) and six additional CVEs; Red Hat advised customers to upgrade and rebuild dependent images.
Red Hat issued Important advisory RHSA-2024:2875, releasing OpenShift Container Platform 4.13.42 images. It remediated Go HTTP/2 denial of service, Gunicorn request smuggling, jose-go compressed-data handling, and unauthenticated local Ironic API access.
Red Hat issued Important advisory RHSA-2024:2782 for OpenShift Container Platform 4.12.57. The update addressed Go HTTP/2 denial of service, a cluster-monitoring-operator credential leak, an osin timing discrepancy, and unauthenticated local access to the Ironic API.
Red Hat issued Important advisory RHSA-2024:2668 for OpenShift Container Platform 4.14.24, supplying updated packages and container images for RHEL 8 and RHEL 9. The update remediated CVE-2023-45288, a Go HTTP/2 CONTINUATION-frame denial-of-service flaw, and CVE-2024-31463, which allowed unauthenticated local access to the OpenStack Ironic API.
Red Hat issued Important advisory RHSA-2024:2068 for OpenShift Container Platform 4.15.11. The updated container images remediated CVE-2023-45288, a Go HTTP/2 CONTINUATION-frame denial-of-service flaw, and CVE-2024-31463, which allowed unauthenticated local access to the OpenStack Ironic API.
Red Hat issued Important advisory RHSA-2024:2562, providing golang-1.21.9-2.el9_4 for RHEL 9. The update remediated seven Go and golang-fips issues, including HTTP/2 and multipart-form denial-of-service flaws, redirect data forwarding, and certificate-verification panics.
Red Hat issued Important advisory RHSA-2024:1897 for OpenShift Container Platform 4.14.22, providing updated packages and images for RHEL 8 and RHEL 9. The update remediated CVE-2023-45288, a Go HTTP/2 CONTINUATION-frame denial-of-service flaw, and CVE-2024-1394, a golang-fips/openssl RSA encryption and decryption memory-leak issue.
Red Hat issued Important advisory RHSA-2024:1891 for OpenShift Container Platform 4.14.22, providing updated packages and container images. The update remediated go-git path-traversal/RCE and denial-of-service flaws, kubevirt-csi hosted-control-plane root-node access (CVE-2024-1725), an XSS flaw in golang.org/x/net/html, and the OpenTelemetry otelgrpc denial-of-service flaw.
Red Hat issued Important advisory RHSA-2024:1896 for OpenShift Container Platform 4.12.56 container images on RHEL 8 and RHEL 9. The update remediated go-git path-traversal/RCE and denial-of-service flaws (CVE-2023-49569 and CVE-2023-49568) and the Go HTTP resource-consumption denial-of-service flaw CVE-2023-39326.
Red Hat issued Important advisory RHSA-2024:1899 for OpenShift Container Platform 4.12.56, updating RPM packages to remediate CVE-2023-45288, an HTTP/2 CONTINUATION-frame denial-of-service flaw in Go.
Red Hat issued Important advisory RHSA-2024:1683, releasing OpenShift Container Platform 4.13.39 container images. The update remediated CVE-2023-45288, a Go HTTP/2 CONTINUATION-frame denial-of-service flaw that could exhaust resources.
Red Hat issued Important advisory RHSA-2024:1679, releasing OpenShift Container Platform 4.12.55 container images. The update remediated CVE-2023-45288, a Go HTTP/2 CONTINUATION-frame denial-of-service flaw that could exhaust resources.
Robb Gatica described a flaw in Go's html/template contextual auto-escaping: user-controlled data in errors returned by MarshalJSON could break escaping and permit unexpected template-content injection in subsequent actions.
Red Hat issued Critical advisory RHSA-2024:0766 for OpenShift Container Platform 4.15.0, providing updated packages and images. The release remediated OpenTelemetry otelhttp and otelgrpc metric-cardinality denial-of-service flaws, Go HTTP/2 stream-reset denial-of-service flaws, and the SSH Binary Packet Protocol prefix-truncation issue.
Red Hat issued Critical advisory RHSA-2024:0833, releasing OpenShift Container Platform 4.12.50 packages and container images for RHEL 8 and RHEL 9 architectures. The update remediated go-git path-traversal/RCE and denial-of-service flaws, Go HTTP/2 rapid stream-reset denial-of-service flaws, and the OpenTelemetry otelhttp metric-cardinality denial-of-service flaw.
Red Hat issued Critical advisory RHSA-2024:0880 for the OpenShift Serverless Client (kn), providing updated RHEL 8 RPMs for x86_64, ppc64le, and s390x. The update fixed go-git denial-of-service and path-traversal/RCE flaws (CVE-2023-49568 and CVE-2023-49569), a Go net/http resource-consumption denial of service (CVE-2023-39326), and the SSH Binary Packet Protocol prefix-truncation flaw (CVE-2023-48795).
Red Hat issued Critical advisory RHSA-2024:0741 for OpenShift Container Platform 4.13.33, providing updated container images and fixes for RHEL 8 and RHEL 9 architectures. The update remediated go-git path-traversal/RCE and denial-of-service flaws, Go HTTP/2 rapid stream-reset denial-of-service issues, go-yaml resource-exhaustion issues, and OpenTelemetry otelgrpc metric-cardinality denial of service.
Red Hat issued Critical advisory RHSA-2024:0642 for OpenShift Container Platform 4.14.11, providing updated container images for supported RHEL 8 and RHEL 9 architectures. The update remediated Go HTTP/2 rapid stream-reset flaws, go-git path-traversal/RCE and denial-of-service flaws, and OpenTelemetry otelhttp and otelgrpc metric-cardinality denial-of-service flaws.
Red Hat issued Critical advisory RHSA-2024:0641 for OpenShift Container Platform 4.14.11 RPM packages. The update remediated go-git path-traversal/remote-code-execution and denial-of-service flaws (CVE-2023-49569 and CVE-2023-49568) and the OpenTelemetry otelhttp denial-of-service flaw CVE-2023-45142.
Red Hat issued Important advisory RHSA-2024:0660 for OpenShift Container Platform 4.13.32, providing updated packages and container images. The update remediated Go net/http and x/net/http2 rapid stream-reset denial-of-service issues, including CVE-2023-39325 and CVE-2023-44487, and the OpenTelemetry otelhttp metric-cardinality denial-of-service flaw CVE-2023-45142.
Red Hat issued Moderate advisory RHSA-2024:0489 for OpenShift Container Platform 4.12.48, providing RPM packages and associated container images. The update remediated CVE-2023-47108, an OpenTelemetry otelgrpc unbounded metric-cardinality denial-of-service flaw.
Red Hat issued Moderate advisory RHSA-2024:0288 for OpenShift Container Platform 4.13.30. The RPM update remediated CVE-2023-47108, an OpenTelemetry otelgrpc unbounded metric-cardinality denial-of-service flaw, for supported RHEL 8 and RHEL 9 architectures.
Red Hat issued Moderate advisory RHSA-2024:0204 for OpenShift Container Platform 4.14.9. The update remediated OpenTelemetry otelhttp and otelgrpc metric-cardinality denial-of-service flaws, CVE-2023-45142 and CVE-2023-47108, and included platform bug fixes.
Pedro Sampaio reported Red Hat Bug 2258165 for CVE-2023-49568, a high-severity go-git vulnerability affecting versions before 5.11. A malicious Git server could send crafted responses that exhaust a go-git client's resources; go-git 5.11 fixed the issue.
Red Hat issued Important advisory RHSA-2023:7831 for OpenShift Container Platform 4.14.7. Updated packages and container images remediated Go HTTP/2 Rapid Reset denial of service (CVE-2023-39325) and OpenTelemetry otelhttp and otelgrpc metric-cardinality denial-of-service flaws (CVE-2023-45142 and CVE-2023-47108).
Red Hat issued RHSA-2023:4335 to remediate the Go multipart-form parsing denial-of-service flaw CVE-2023-24536 in affected CERT-MANAGER-1.10-RHEL-9 cert-manager operator bundle, operator, and Jetstack cert-manager container components.
Red Hat issued Important advisory RHSA-2023:4470 for Ansible Automation Platform 2.3 on RHEL 8 x86_64, updating openshift-clients. The update remediated ten Go vulnerabilities affecting HTTP/2, TLS handshakes, multipart and HTTP parsing, go/parser, and html/template handling, including CVE-2023-24536.
Red Hat released RHSA-2023:3167 to remediate CVE-2022-41725 in affected Cryostat 2 components for RHEL 8. The Go net/http and mime/multipart flaw could allow remote unauthenticated attackers to exhaust resources through crafted HTTP requests.
Pedro Sampaio reported CVE-2023-24536, in which multipart form inputs with very large numbers of parts could consume excessive CPU and memory in Go's net/http, net/textproto, and mime/multipart handling. Red Hat tracked the issue for EPEL and Fedora and issued fixes across products including RHEL, OpenShift, OpenStack Platform, and related automation and container offerings.
Avinash Hanwate reported CVE-2022-41724, in which oversized TLS handshake records could cause Go crypto/tls clients or servers to panic while constructing a response. A malicious TLS peer could crash affected TLS 1.3 clients, certain TLS 1.2 session-resumption clients, and TLS 1.3 servers requesting client certificates.
CVE-2022-41717 (GO-2022-1144) affects Go HTTP/2 servers whose cache of client-supplied HTTP header keys permits very large key names. An attacker could cause roughly 64 MiB of memory allocation per open connection and exhaust server memory; Red Hat tracked and remediated the issue across RHEL, OpenShift, OpenStack, and other products.
CVE-2022-41725 (GO-2023-1569) affects Go net/http and mime/multipart parsing: crafted multipart forms could exceed expected memory limits and create an unbounded number of temporary disk files. The fix improves ReadForm memory accounting and coalesces file parts into at most one temporary file; Red Hat issued fixes across affected RHEL, OpenShift, OpenStack, and related products.
Red Hat issued advisories for CVE-2024-34069 affecting Werkzeug's debugger across OpenShift Container Platform 4.12, 4.15, and 4.16, Red Hat OpenStack Platform 16.2 and 17.1, and Red Hat Ceph Storage 7.1. The flaw could enable code execution on a developer machine if an attacker satisfies multiple social-engineering and debugger-PIN prerequisites.
Red Hat released Important-rated OpenShift Container Platform 4.14.27 with updated container images for supported RHEL 8 and RHEL 9 architectures. The update addressed CVE-2023-45288, a Go HTTP/2 CONTINUATION-frame denial-of-service flaw, and CVE-2024-1135, a Gunicorn Transfer-Encoding request-smuggling flaw.
CVE-2023-47108 affects OpenTelemetry-Go Contrib before 0.46.0, whose default gRPC Unary Server Interceptor recorded attacker-controlled peer socket address and port labels with unbounded cardinality. Attackers could exhaust gRPC server memory through requests from varying addresses and ports; version 0.46.0 fixed the issue.
OpenShift Telemeter's issuer extraction assumed compact JWS serialization while go-jose accepted JSON-serialized JWS tokens, allowing a crafted token to cause acceptance of a forged issuer. The issue could permit unauthorized access or privilege escalation between servers sharing signing keys; Red Hat addressed it across OpenShift 4.12 through 4.16 advisories.
CVE-2024-47211 affects OpenStack Ironic image handling: image conversion can occur before checksum validation, potentially allowing a man-in-the-middle attacker to modify image data. Red Hat remediated the issue through advisories for OpenShift 4.16 and 4.17, OpenStack Services on OpenShift 18.0, and OpenStack Platform 17.1 for RHEL 9.
CVE-2023-45142 affects OpenTelemetry-Go Contrib's otelhttp handler, which could record attacker-controlled HTTP methods and User-Agent values as unbounded-cardinality metric labels and exhaust server memory. Version 0.44.0 constrained recognized method values and removed high-cardinality attributes; otelhttp.WithFilter() was documented as a configurable mitigation.
Red Hat issued advisories addressing CVE-2024-1135, a Gunicorn HTTP request-smuggling flaw involving conflicting Transfer-Encoding headers, for OpenStack Platform, Ansible Automation Platform, Satellite, and RHUI, in addition to OpenShift releases. The flaw could allow security-control bypasses, cache poisoning, session manipulation, and data exposure.
Red Hat released Important-rated OpenShift Container Platform 4.13.51 updates with packages and container images. The release remediated denial-of-service flaws in Go HTTP/2, OpenTelemetry otelhttp and otelgrpc, and QEMU NBD, along with go-retryablehttp sensitive URL logging, and included several operational and security-profile fixes.
Red Hat issued RHSA-2024:6406 to fix CVE-2024-34069 in affected OpenShift Container Platform 4.14 components. The Important-severity Werkzeug debugger CSRF flaw could enable code execution on a developer machine if exploitation prerequisites, including user interaction and debugger-PIN entry, were met.
Metal3 ironic-image was found to expose the OpenStack Ironic API without authentication when reverse-proxy mode is enabled, allowing host-networked pods or local users on a control-plane node to access localhost port 6388. Exploitation could let an attacker modify bare-metal machines; the issue was fixed in ironic-image 24.1.1 and also affected Ironic Inspector with lower attack potential.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
50 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.