CVE-2025-14243
published 2026-04-08CVE-2025-14243: A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email…
PriorityP434medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.29%
20.7th percentile
A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | mirror_registry_for_red_hat_openshift | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v9gq-365f-qxxw: A flaw was found in the OpenShift Mirror Registry
ghsa_unreviewed·2026-04-08
CVE-2025-14243 [MEDIUM] CWE-209 GHSA-v9gq-365f-qxxw: A flaw was found in the OpenShift Mirror Registry
A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation.
Red Hat
mirror-registry: OpenShift Mirror Registry: User enumeration via authentication error messages
vendor_redhat·2026-04-08·CVSS 5.3
CVE-2025-14243 [MEDIUM] CWE-209 mirror-registry: OpenShift Mirror Registry: User enumeration via authentication error messages
mirror-registry: OpenShift Mirror Registry: User enumeration via authentication error messages
A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Package: openshift/mirror-registry-rhel8 (mirror registry for Red Hat OpenShift) - Will not fix
Package: openshift/mirror-registry-rhel8 (mirror registry for Red Hat OpenShift 2) - Affected
No detection rules found.
No public exploits indexed.
2026-04-08
Published