RHSA-2026:6251HighCVSS 7.5
Red Hat Security Advisory: Red Hat OpenShift API for Data Protection
🔗 CVE IDs covered (2)
📋 Description
CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61728 — golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip
🎯 Affected products42
- OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:713a90e0460a0739f6a173413b7b4a4f007b9dc385a13d473eb90f42fc8488dc_amd64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:bd99a8ccfab255d8ec307f42d4d4f46c6a0422cd6bfb98bb69e80ad47f7aa66e_arm64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:c175aaa7d6090900667715414322689f61b1c2d8d6210390adef9f37513467ed_s390x as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:d24718a7e522d1307a42b93b13c3f9c6f4e9755af9f47569373e541bbe0c47d4_ppc64le as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:23a27c4df14f18ee490a8d3cff7e0f15fe8dba28888ec53999dfa1c2d8df8a17_ppc64le as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:4c69045f91a2852e87d6ae7e8c48dca5c0ac8be67cdb2f9c129d57e11a8422b4_s390x as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:9949e4981559a98a6b3891ef9c2b96eb0719d787eed3ace91a48b3263c0a84ff_amd64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:d0f7ec01f2f2ed714089b5f2be04d72bea0ca4ee5d361e679604e7cd0740e298_arm64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-operator-bundle@sha256:7bba26e14098763c7d2989489357246b8ba280ac88d84f9ddc688541b852a527_amd64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:172a3b54f5dd6281eba7ed472f5ae3b7f15587afc8b4dbd9153693a6334bc996_amd64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:63ee2618929f0be44bfd76e1f4ed406fcd1012c2e09ca461fa94c1188f1f13ba_ppc64le as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:9ab58d8f27c06affbe9081699babb8dcefa0d70fc2b0c0a7de8138acfaf83407_arm64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-rhel9-operator@sha256:ab31f7840924706ad94dd39362b2a45ec1410ba6d394519298954c511aae35e9_s390x as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:24af970befaecfcf1082f6f1c1a14d043db87c391cdb45cb4d81d63c05391f4f_ppc64le as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:66a95b0f76a04d62657b48241eb9f48c0b8e80b345db6189b7a5eb4ac8fb614b_s390x as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:9b0c1ba1c44c05d378ba9298438c45cb9f9a40823beb10bbd658f54dcc10b728_arm64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-aws-rhel9@sha256:ff6f3b3851e05dc1b6dfbf0daa6ccb7973b2baf7578c619af146d480da17074d_amd64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:2c93ea18feae62cf85a75c40782e79dd471bd1d814f919c62242c7e2d660b4c6_s390x as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:68b647ea6661c94de7ba2b42be7da4e5838000634037c2f624b6767b3eee506b_ppc64le as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:742dbbf5fb7f29c83b5b5aba4c60bb635cfb1e751232af35866ff8f4ff28301b_amd64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-gcp-rhel9@sha256:c92212fdcaeb3a88d67026d3b564960b0fae2e23a72f28ed6466307f7aa43c75_arm64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:8c095de3d93c13b4977624aad7f81bcd482109be69d0b58bef25ebd24d87b526_ppc64le as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:ad29bcd79d0adfc9ca0139b8c784166ecb2e680871fd321c55fd4eb4292c446d_arm64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:b1a147efb5adbd1f85a5e71ec9cfefb8996c8ad88ce181399a4fc49a43d146fd_amd64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-legacy-aws-rhel9@sha256:b8462006b53ba7db08e55cfc1e57b5a1fef4e407fbca3fcdd6fe25b9bb2b05c0_s390x as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:81780e7ae1aa0583ca1da814cc2ccf7312b6957fb141095896982de4df7930e7_ppc64le as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:a19c3cfecd1120e366c3aeff5157c1fa1487b4f97bc8a44513dc87e5193874af_amd64 as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:c46a5ca1980e56e18b670875e6598494539a7fef88fe5e7316e7e4c1f9c5b05b_s390x as a component of OpenShift API for Data Protection 1.4
- registry.redhat.io/oadp/oadp-velero-plugin-for-microsoft-azure-rhel9@sha256:c94eca74f3f6006a29717a7126da98bf44e5ecabfd2136c150036e6518a142c5_arm64 as a component of OpenShift API for Data Protection 1.4
- +12 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: To mitigate this vulnerability, implement a timeout in your archive/zip processing logic to abort the operation if it exceeds a few seconds, preventing the application from consuming an excessive amount of resources.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:6251
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61728
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/backup_and_restore/oadp-application-backup-and-restore
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_6251.json