RHSA-2025:16040HighCVSS 7.5
Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.0.5
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-54588 — envoyproxy/envoy: Use after free in DNS cache CVE-2025-55162 — envoyproxy/envoy: oAuth2 Filter Signout route will not clear cookies because of missing "secure;" flag
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2025:16040
- externalhttps://access.redhat.com/security/cve/CVE-2025-54588
- externalhttps://access.redhat.com/security/cve/CVE-2025-55162
- externalhttps://access.redhat.com/security/cve/cve-2025-54588
- externalhttps://access.redhat.com/security/cve/cve-2025-55162
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_16040.json