Red Hat released Important-rated updates for Advanced Cluster Management for Kubernetes 2.11.5 and Multicluster Engine for Kubernetes 2.6.5 that remediate CVE-2024-55565, a Nano ID (nanoid) flaw caused by mishandling non-integer values. The releases also address CVE-2024-45337 in golang.org/x/crypto/ssh and CVE-2024-45338 in golang.org/x/net/html, delivering refreshed container images for supported RHEL 9 deployments across x86_64, ARM64, IBM Power, and IBM Z/LinuxONE architectures.
Affected Nano ID versions prior to 5.0.9—including the vulnerable 3.x line before 3.3.8—should be replaced with fixed builds. Red Hat has issued related errata for OpenShift, OpenShift AI, Ansible Automation Platform, OpenShift Dev Spaces, OpenShift Service Mesh, and Kubernetes management products; administrators should apply prerequisite errata where specified and upgrade through the applicable Red Hat release channels and installation guidance.

See real exploitation activity before you spend the cycle.
16 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2025:1116 for OpenShift Container Platform 4.13.55. The release updated container images to remediate five vulnerabilities, including Go HTTP/2 denial-of-service flaws, a Python tempfile path-traversal issue, and sensitive-URL logging in go-retryablehttp.
Red Hat released RHSA-2025:1331, RHSA-2025:1332, and RHSA-2025:1333 to remediate CVE-2024-45337 in affected Gatekeeper 3.17, 3.15, and 3.14 components for RHEL 9.
Red Hat recorded CVE-2024-45337, an authorization-bypass issue in golang.org/x/crypto/ssh caused by unsafe use of ServerConfig.PublicKeyCallback. The issue is fixed in golang.org/x/crypto v0.31.0.
Red Hat addressed CVE-2024-55565 in RHODF 4.18 for RHEL 9 through RHSA-2025:2652.
Red Hat addressed CVE-2024-55565 in OpenShift Service Mesh 2.5 for RHEL 8 through RHSA-2025:1051.
Red Hat addressed CVE-2024-55565 in OpenShift Dev Spaces 3 Containers through RHSA-2025:0892.
Red Hat addressed CVE-2024-55565 in Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 through RHSA-2025:0851.
Red Hat issued RHSA-2025:0875 to address CVE-2024-55565 in OpenShift Container Platform 4.17.
Red Hat issued Important-rated RHSA-2025:0785 for Advanced Cluster Management for Kubernetes 2.11.5 GA images on RHEL 9 x86_64. It fixed CVE-2024-55565, CVE-2024-45337, and CVE-2024-45338.
Red Hat issued Important-rated RHSA-2025:0778 for Multicluster Engine for Kubernetes 2.6.5 GA images. The update remediated CVE-2024-55565 as well as CVE-2024-45337 and CVE-2024-45338.
Red Hat addressed CVE-2024-55565 in Multicluster Engine for Kubernetes 2.7 for RHEL 8 and RHEL 9 through RHSA-2025:0723.
Red Hat addressed CVE-2024-55565 in OpenShift Container Platform 4.17 through RHSA-2025:0654.
Red Hat addressed CVE-2024-55565 in Ansible Automation Platform 2.5 for RHEL 8 and RHEL 9 through RHSA-2025:0340.
Red Hat addressed CVE-2024-55565 in Red Hat OpenShift AI/RHODF 4.16 for RHEL 9 through RHSA-2025:0082.
Red Hat addressed CVE-2024-55565 in Red Hat OpenShift AI/RHODF 4.17 for RHEL 9 through RHSA-2025:0079.
The nanoid issue, tracked as CVE-2024-55565, was reported upstream through JupyterLab issue 17056. nanoid versions before 5.0.9 mishandle non-integer values; version 3.3.8 is also identified as fixed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.