-
Vulnerability
-
Resolution: Done
-
Critical
-
ACM 2.13.0
-
Security & Compliance
-
False
-
-
False
-
-
-
Critical
-
None
Description of problem:
Unexpected memory consumption during token parsing in golang.org/x/oauth2
https://docs.google.com/spreadsheets/d/1UqwOA6KAhfS2NtMGRk6og8EuUh3up9iPxLxDKPuflGw/edit?gid=1743374624#gid=1743374624
Affected business continuity repos:
- volsync-addon-controller
- cluster-backup-operator
- is cloned by
-
ACM-19412 CVE-2025-22869 for business continuity no tracker components
-
- Resolved
-
-
ACM-19415 CVE-2025-22868 for business continuity no tracker components [rhacm-2.12.z]
-
- Resolved
-
-
ACM-19419 [ACM 2.11.z] CVE-2025-22868 for business continuity no tracker components
-
- Resolved
-
-
ACM-19421 [ACM 2.10.z] CVE-2025-22868 for business continuity no tracker components
-
- Resolved
-
-
ACM-19503 [ACM 2.9.z] CVE-2025-22868 for business continuity no tracker components
-
- Resolved
-