RHSA-2025:0664: Moderate: Release of OpenShift Serverless Logic 1.35.0 security update & enhancements
Moderate: Release of OpenShift Serverless Logic 1.35.0 security update & enhancements
Other sources
This release includes security, bug fixes, and enhancements.Security Fix(es): com.graphql-java/graphql-java: Allocation of Resources Without Limits or Throttling in GraphQL Java (CVE-2024-40094) openshift-serverless-1-logic-rhel8-operator-container: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON (CVE-2024-24786) path-to-regexp: Backtracking regular expressions cause ReDoS (CVE-2024-45296) For more details about the security issues, including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE pages listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:0664?
The severity of RHSA-2025:0664 is classified as moderate.
How do I fix RHSA-2025:0664?
To fix RHSA-2025:0664, update your OpenShift Serverless to the latest version available.
What are the main enhancements in RHSA-2025:0664?
RHSA-2025:0664 includes security fixes, bug fixes, and enhancements to the OpenShift Serverless Logic.
Which products are affected by RHSA-2025:0664?
RHSA-2025:0664 affects Red Hat OpenShift Serverless, Red Hat OpenShift Serverless for ARM, and Red Hat OpenShift Serverless for IBM Power.
What security issue is addressed in RHSA-2025:0664?
RHSA-2025:0664 addresses the allocation of resources without limits or throttling in GraphQL Java.