Resource exhaustion in Fulcio - CVE-2025-66506
Published: December 16, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources within the identity.extractIssuerURL() function when parsing untrusted arguments. A remote attacker can pass a specially crafted request with a malicious OIDC identity token to trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
watsonx.data
watsonx.data integration
OpenShift Pipelines
AI Inference Server Model Optimization Tools
AI Inference Server
How to mitigate CVE-2025-66506
watsonx.data - update to 2.3.1
watsonx.data integration - update to 5.3.1
OpenShift Pipelines - update to 0.21.0
AI Inference Server Model Optimization Tools - update to 3.2.5
AI Inference Server - update to 3.2.5
External References
Related Security Bulletins
- Denial of service in Fulcio
- Multiple vulnerabilities in Red Hat AI Inference Server Model Optimization Tools
- Multiple vulnerabilities in Red Hat AI Inference Server (TPU)
- Multiple vulnerabilities in Red Hat AI Inference Server (CUDA)
- Multiple vulnerabilities in Red Hat AI Inference Server (ROCm)
- Multiple vulnerabilities in Red Hat AI Inference Server (ROCm)
- Red Hat OpenShift Pipelines update for Fulcio
- IBM watsonx.data update for Fulcio
- Multiple vulnerabilities in IBM watsonx.data integration