RHSA-2026:7885MediumCVSS 7.5

Red Hat Security Advisory: Red Hat OpenStack Services on OpenShift 18.0.18 (golang-github-openstack-k8s-operators-os-diff) security update

Published
April 29, 2026
Last Modified
August 13, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-65637 — github.com/sirupsen/logrus: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption

🎯 Affected products6

  • 9Base-RHOSO-TOOLS-18
  • Red Hat OpenStack Services on OpenShift 18.0
  • golang-github-openstack-k8s-operators-os-diff-0:0.1.1-18.0.20260225161428.32d52e7.el9ost.src as a component of 9Base-RHOSO-TOOLS-18
  • golang-github-openstack-k8s-operators-os-diff-0:0.1.1-18.0.20260225161428.32d52e7.el9ost.src as a component of Red Hat OpenStack Services on OpenShift 18.0
  • golang-github-openstack-k8s-operators-os-diff-0:0.1.1-18.0.20260225161428.32d52e7.el9ost.x86_64 as a component of 9Base-RHOSO-TOOLS-18
  • golang-github-openstack-k8s-operators-os-diff-0:0.1.1-18.0.20260225161428.32d52e7.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.

🔗 References (5)