Red Hat Security Advisory: opentelemetry-collector security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2025-22868 — golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws CVE-2025-27144 — go-jose: Go JOSE's Parsing Vulnerable to Denial of Service CVE-2025-29786 — github.com/expr-lang/expr: Memory Exhaustion in Expr Parser with Unrestricted Input CVE-2025-30204 — golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing
🎯 Affected products6
- Red Hat Enterprise Linux AppStream (v. 9)
- opentelemetry-collector-0:0.107.0-8.el9_6.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- opentelemetry-collector-0:0.107.0-8.el9_6.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- opentelemetry-collector-0:0.107.0-8.el9_6.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- opentelemetry-collector-0:0.107.0-8.el9_6.src as a component of Red Hat Enterprise Linux AppStream (v. 9)
- opentelemetry-collector-0:0.107.0-8.el9_6.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this vulnerability, it is recommended to pre-validate any payloads passed to `go-jose` to check that they do not contain an excessive amount of `.` characters. Workaround: As a workaround, applications can pre-validate that payloads being passed to Go JOSE do not contain an excessive number of `.` characters. Workaround: To mitigate this vulnerability, it is recommended to impose an input size restriction before parsing (i.e. validating or limiting the length of expression strings that the application will accept). Ensuring no unbounded-length expressions are fed into the parser will prevent the parser from constructing a very large AST and avoid the potential memory exhaustion issue. Workaround: Red Hat Product Security does not have a recommended mitigation at this time.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2025:7407
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2347423
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348366
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2352914
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2354195
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_7407.json