First published: Wed Apr 02 2025(Updated: )
An update is now available for the Red Hat build of Cryostat 4 on RHEL 9.<br>Security Fix(es):<br><li> golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws (CVE-2025-22868)</li> <li> golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Cryostat |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2025:3503 relates to unexpected memory consumption issues in the affected libraries.
To fix RHSA-2025:3503, apply the latest security update for Red Hat Cryostat on RHEL 9.
RHSA-2025:3503 addresses vulnerabilities in golang.org/x/oauth2/jws and golang-jwt/jwt that lead to excessive memory allocation.
RHSA-2025:3503 affects the Red Hat build of Cryostat operating on RHEL 9.
As of now, there are no publicly available known exploits specifically for RHSA-2025:3503.