Resource exhaustion in jwt - CVE-2025-30204
Published: March 24, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources within the parse.ParseUnverified function when parsing authorization header. A remote attacker can send a specially crafted HTTP response to the application, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP6
Oracle Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Fedora
Red Hat Enterprise Linux Server - AUS
Server Applications Module
Basesystem Module
Containers Module
openSUSE Leap
Db2 Intelligence Center
DB2 Data Management Console
Guardium Data Security Center (GDSC)
Security QRadar EDR
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Storage Scale
Storage Ceph
Db2 Big SQL
Maximo Application Suite - Visual Inspection Component
Business Automation Insights
Netcool Operations Insight
IBM Fusion HCI
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
OpenShift Logging
IBM Maximo Application Suite
Submariner
IBM Observability with Instana
Multicluster GlobalHub
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
Cryostat
IBM Cloud Pak for Business Automation
watsonx.data
IBM Cloud Pak System
Multicluster Engine for Kubernetes
OpenShift Data Foundation (formerly OpenShift Container Storage)
Financial Transaction Manager
Splunk Enterprise
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
thrift (Red Hat package)
restic
opentelemetry-collector (Red Hat package)
ansible-collection-ansible-posix (Red Hat package)
rekor-debuginfo
rekor
libunwind (Red Hat package)
opentofu
amber-cli
rclone
liborc (Red Hat package)
nvml (Red Hat package)
oath-toolkit (Red Hat package)
gperftools (Red Hat package)
lttng-ust (Red Hat package)
golang-github-prometheus
etcdctl
etcd
protobuf (Red Hat package)
ansible-collection-community-general (Red Hat package)
cephadm-ansible (Red Hat package)
incus
libarrow (Red Hat package)
grafana (Red Hat package)
ceph (Red Hat package)
docker-stable-bash-completion
docker-stable-debuginfo
docker-stable
docker-stable-fish-completion
docker-stable-zsh-completion
docker-stable-rootless-extras
moby-engine
osbuild-composer (Red Hat package)
osbuild-composer-worker
osbuild-composer
osbuild-composer-core
re2 (Red Hat package)
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat Ceph Storage
How to mitigate CVE-2025-30204
Db2 Intelligence Center - update to 1.1.1.0
Netcool Operations Insight - update to 1.6.15
watsonx.data - update to 2.2
IBM Fusion HCI - update to 2.10.0
IBM Cloud Pak System - update to 2.3.6.1
Multicluster Engine for Kubernetes - addressed in versions 2.4.9, 2.5.9, 2.6.8, 2.8.3, 2.8.4
DB2 Data Management Console - update to 3.1.13.2
Financial Transaction Manager - addressed in versions 3.2.13 iFix4, 4.0.6.0 iFix5, 4.0.7.0
Guardium Data Security Center (GDSC) - update to 3.7.2
Security QRadar EDR - update to 3.12.18
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.3
Storage Scale - update to 5.2.3.3
OpenShift Logging - addressed in versions 5.9.13, 6.0.7, 6.0.12, 6.1.5, 6.2.7
Storage Ceph - update to 7.1z6
Db2 Big SQL - update to 8.2
Maximo Application Suite - Visual Inspection Component - addressed in versions 8.9.19, 9.0.16, 9.1.7
IBM Maximo Application Suite - addressed in versions 8.10.30, 8.11.27, 9.0.16, 9.1.5
Splunk Enterprise - addressed in versions 9.3.10, 9.4.9, 10.0.4, 10.2.1
Business Automation Insights - update to 25.0.0.0.1
thrift (Red Hat package) - addressed in versions 0.15.0-3.el9cp, 0.20.0-4.el10cp
Submariner - addressed in versions 0.17.6, 0.18.5, 0.19.4, 0.20.1
restic - update to 0.18.0-1.fc43
opentelemetry-collector (Red Hat package) - update to 0.107.0-8.el9_4
IBM Observability with Instana - update to 1.0.295
ansible-collection-ansible-posix (Red Hat package) - addressed in versions 1.2.0-1.3.el9ost, 2.0.0-1.el10cp
Multicluster GlobalHub - addressed in versions 1.2.3, 1.4.1
OpenShift API for Data Protection (OADP) - addressed in versions 1.3.7, 1.4.5
rekor-debuginfo - update to 1.3.10-150400.4.25.1
rekor - update to 1.3.10-150400.4.25.1
libunwind (Red Hat package) - addressed in versions 1.6.2-2.el9cp, 1.8.0-4.el10cp
Migration Toolkit for Containers - update to 1.8.7
opentofu - addressed in versions 1.9.1-1.fc43, 1.10.3-1.el9
amber-cli - update to 1.13.1+git20250329.c2e3bb8-150600.3.3.1
rclone - update to 1.70.2-1.fc43
liborc (Red Hat package) - update to 2.0.3-2.el10cp
nvml (Red Hat package) - update to 2.1.0-3.el10cp
oath-toolkit (Red Hat package) - addressed in versions 2.6.12-1.el9cp, 2.6.12-1.el10cp
gperftools (Red Hat package) - addressed in versions 2.9.1-5.el9cp, 2.9.1-5.el10cp
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.9.9, 2.10.8, 2.11.7, 2.13.3
lttng-ust (Red Hat package) - update to 2.13.7-5.el10cp
golang-github-prometheus - update to 2.55.1-1.fc43
etcdctl - update to 3.5.21-150000.7.12.1
etcd - update to 3.5.21-150000.7.12.1
protobuf (Red Hat package) - update to 3.19.6-12.el10
Red Hat OpenShift Dev Spaces - update to 3.21.0
Cryostat - update to 4.0.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.15.14, 4.17.7, 4.18
ansible-collection-community-general (Red Hat package) - addressed in versions 4.0.0-1.1.el9ost, 10.7.3-1.el10cp
cephadm-ansible (Red Hat package) - addressed in versions 4.1.4-1.el9cp, 4.1.4-1.el10cp
Red Hat OpenShift Container Platform - addressed in versions 4.12.76, 4.13.58, 4.14.50, 4.14.51, 4.14.52, 4.14.54, 4.15.49, 4.15.50, 4.15.53, 4.16.39, 4.17.24, 4.17.25, 4.17.26, 4.17.27, 4.18.8, 4.18.9, 4.18.10, 4.18.11, 4.18.17
incus - addressed in versions 6.12-1.fc41, 6.12-1.fc42
Red Hat Ceph Storage - addressed in versions 8.1, 9.0
libarrow (Red Hat package) - addressed in versions 9.0.0-10.el9cp, 15.0.2-3.el10cp
grafana (Red Hat package) - addressed in versions 9.0.9-6.el9_2, 10.2.6-9.el9_5, 10.2.6-11.el9_6
ceph (Red Hat package) - addressed in versions 20.1.0-144.el9cp, 20.1.0-144.el10cp
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF006, 24.0.1-IF005, 25.0.0-IF001
docker-stable-bash-completion - addressed in versions 24.0.9_ce-1.29.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.36.1, 24.0.9_ce-150000.1.39.1
docker-stable-debuginfo - addressed in versions 24.0.9_ce-1.29.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.36.1, 24.0.9_ce-150000.1.39.1
docker-stable - addressed in versions 24.0.9_ce-1.29.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.36.1, 24.0.9_ce-150000.1.39.1
docker-stable-fish-completion - addressed in versions 24.0.9_ce-150000.1.36.1, 24.0.9_ce-150000.1.39.1
docker-stable-zsh-completion - addressed in versions 24.0.9_ce-150000.1.36.1, 24.0.9_ce-150000.1.39.1
docker-stable-rootless-extras - addressed in versions 24.0.9_ce-150000.1.36.1, 24.0.9_ce-150000.1.39.1
moby-engine - update to 28.2.2-1.fc43
osbuild-composer (Red Hat package) - addressed in versions 46.3-3.el9_0, 75-3.el8_8, 76.1-1.el9_2, 101-3.el8_10, 101.3-1.el9_4, 118.2-1.el9_5
osbuild-composer-worker - addressed in versions 118.2-1.0.1, 132.2-1.0.1
osbuild-composer - addressed in versions 118.2-1.0.1, 132.2-1.0.1
osbuild-composer-core - addressed in versions 118.2-1.0.1, 132.2-1.0.1
re2 (Red Hat package) - addressed in versions 20211101-4.el9cp, 20211101-4.el10cp
External References
Related Security Bulletins
- Remote denial of service in Go JWT
- Red Hat Enterprise Linux 9 update for grafana
- Multiple vulnerabilities in Red Hat build of Cryostat 4 on RHEL 9
- Red Hat Enterprise Linux 9 update for grafana
- Red Hat Enterprise Linux 9 update for opentelemetry-collector
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Oracle Linux
- SUSE update for etcd
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Resource exhaustion in OpenShift Logging 6.0
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in OpenShift Logging 6.1
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- SUSE update for rekor
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Submariner 0.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Red Hat Enterprise Linux 9 update for osbuild-composer
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.5
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.10
- Fedora 41 update for incus
- Fedora 42 update for incus
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Red Hat Enterprise Linux 9 update for osbuild-composer
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.11
- Red Hat Enterprise Linux 9 update for osbuild-composer
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Submariner 0.18
- Red Hat Enterprise Linux 9 update for grafana
- Anolis OS update for osbuild-composer
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Red Hat Enterprise Linux 8 update for osbuild-composer
- Anolis OS update for osbuild-composer
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Red Hat Enterprise Linux 8 update for osbuild-composer
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Red Hat Enterprise Linux 9 update for osbuild-composer
- Fedora 43 update for moby-engine
- Multiple vulnerabilities in Multicluster GlobalHub 1.4
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.9
- Multiple vulnerabilities in IBM Fusion
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.13
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.15
- Multiple vulnerabilities in IBM Financial Transaction Manager (FTM) for RedHat OpenShift
- Multiple vulnerabilities in Submariner 0.20
- Resource exhaustion in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in IBM Security QRadar EDR
- IBM Watson Speech Services Cartridge for IBM Cloud Pak for golang-jwt
- Fedora 43 update for opentofu
- Multiple vulnerabilities in OpenShift Logging 5.9
- Multiple vulnerabilities in Multicluster GlobalHub 1.2
- Multiple vulnerabilities in Submariner 0.17
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- IBM watsonx.data update for golang-jwt
- Fedora 43 update for rclone
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Fedora 43 update for restic
- Fedora 43 update for golang-github-prometheus
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.4
- Multiple vulnerabilities in Red Hat Ceph Storage 8
- Fedora EPEL 9 update for opentofu
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in IBM Storage Ceph
- Multiple vulnerabilities in IBM Db2 Intelligence Center
- SUSE update for amber-cli
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.6
- Multiple vulnerabilities in IBM Business Automation Insights
- IBM Storage Scale update for golang-jwt
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.8
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Red Hat OpenShift Logging 6.2
- Multiple vulnerabilities in Red Hat OpenShift Logging 6.0
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.18
- Multiple vulnerabilities in IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat Multicluster Engine for Kubernetes 2.8
- IBM Db2 Big SQL on Cloud Pak for Data update for golang-jwt
- Multiple vulnerabilities in IBM DB2 Data Management Console
- Multiple vulnerabilities in Red Hat Ceph Storage 9
- Multiple vulnerabilities in IBM Cloud Pak System
- SUSE update for docker-stable
- SUSE update for docker-stable
- Multiple vulnerabilities in Splunk Enterprise
- SUSE update for docker-stable
- IBM Maximo Application Suite - Visual Inspection Component update for golang-jwt
- SUSE update for docker-stable
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.21