Red Hat released container-image and platform updates across its Kubernetes portfolio to remediate vulnerabilities in Go dependencies, chiefly CVE-2024-45337 in golang.org/x/crypto/ssh and CVE-2024-45338 in golang.org/x/net/html. The SSH issue can enable authorization bypass when applications misuse ssh.ServerConfig.PublicKeyCallback; the HTML flaw involves non-linear parsing of case-insensitive content. Affected products include OpenShift Container Platform 4.15 and 4.18, Advanced Cluster Management 2.9.6, Multicluster Global Hub 1.2 and 1.3, Gatekeeper 3.14 and 3.15, OpenShift Data Foundation 4.15, VolSync 0.10 and 0.11, and Advanced Cluster Security (RHACS) 4.4 and 4.5.
Several releases also address CVE-2024-53259, a quic-go denial-of-service flaw in which forged ICMP Packet Too Large messages can disrupt established QUIC connections, and RHACS 4.6.2 fixes go-git argument injection (CVE-2025-21613) and malicious Git-server reply denial of service (CVE-2025-21614). Red Hat recommends upgrading affected platforms and container images through their supported release channels, including deployments on x86_64, aarch64, ppc64le, and s390x where applicable; RHACS customers should move to 4.4.8, 4.5.6, or 4.6.2 according to their release stream.

See affected versions and whether adversaries are exploiting it.
17 events from the most recent confirmed update back to the earliest known activity.
Important advisory RHSA-2025:3542 released updated OpenShift Data Foundation 4.15 images for RHEL 9, fixing CVE-2024-45337 and CVE-2024-45338 and upgrading Ceph to RHCEPH-7.1z3 in ODF 4.15.13.
Important advisory RHSA-2024:6121 updated OpenShift Container Platform 4.18 packages and images to fix CVE-2024-45337 and Helm secret-exposure flaw CVE-2019-25210.
Red Hat issued Important advisory RHSA-2025:1468 for RHACS 4.4.8, remediating an npm XSS flaw, the go-git argument-injection and denial-of-service flaws, and the Go SSH and HTML parsing vulnerabilities.
Important advisory RHSA-2025:1334 provided RHACS 4.5.6 images fixing CVE-2024-11831, CVE-2024-45337, CVE-2024-45338, CVE-2025-21613, and CVE-2025-21614.
Red Hat issued Important advisory RHSA-2025:1331 for Gatekeeper v3.17.1, remediating CVE-2024-45337 and CVE-2024-45338. The update also added controlled audit and webhook containerArguments support and default admission-control namespace exemptions.
Red Hat issued Important advisory RHSA-2025:1332 for Gatekeeper 3.15.3, remediating CVE-2024-45337 and CVE-2024-45338 and adding configurable container arguments and default namespace exemptions.
Important advisory RHSA-2025:1333 released Gatekeeper 3.14.3 with fixes for CVE-2024-45337 and CVE-2024-45338, configurable audit and webhook container arguments, and default admission-control namespace exemptions.
Critical advisory RHSA-2025:0907 delivered RHACS 4.6.2 images fixing CVE-2024-45338 and the go-git flaws CVE-2025-21613 and CVE-2025-21614; it also corrected Scanner V2 and roxctl defects.
Red Hat issued Important advisory RHSA-2025:0645, updating OpenShift Container Platform 4.15 packages and images to remediate CVE-2024-45337 and CVE-2024-45338.
Red Hat issued Important advisory RHSA-2025:0679 for Advanced Cluster Management for Kubernetes 2.10.7 on RHEL 9, providing updated container images that fix CVE-2024-45337 and CVE-2024-45338 along with additional CVEs and product defects.
Important advisory RHSA-2025:0577 delivered Multicluster Global Hub 1.3.2 images, including fixes for CVE-2024-45337 and CVE-2024-45338.
Red Hat issued Important advisory RHSA-2025:0576 for Advanced Cluster Management for Kubernetes 2.9.6, providing updated images that remediate CVE-2024-45337 and CVE-2024-45338.
Important advisory RHSA-2025:0560 released Multicluster Global Hub 1.2.1 container images and fixed the golang.org/x/crypto/ssh authorization-bypass issue CVE-2024-45337 and golang.org/x/net/html parsing flaw CVE-2024-45338.
Red Hat issued Important advisory RHSA-2025:0386 for VolSync 0.10.2 images, remediating CVE-2024-53259, CVE-2024-45337, and CVE-2024-45338 for Advanced Cluster Management deployments on RHEL 9.
Red Hat issued Important advisory RHSA-2025:0385 for VolSync 0.11.1 on RHEL 9, fixing CVE-2024-53259 in quic-go and CVE-2024-45337 and CVE-2024-45338 in Go components.
Red Hat addressed CVE-2024-53259 for Ansible Automation Platform 2.5 through advisory RHSA-2024:10766.
The quic-go project fixed CVE-2024-53259, an off-path ICMP Packet Too Large injection vulnerability that could disrupt established QUIC connections, in version 0.48.2.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
16 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.