{"id":"CVE-2025-14243","title":"A flaw was found in the OpenShift Mirror Registry","summary":"A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account cre…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-209"],"vendor":"redhat","product":"mirror_registry_for_red_hat_openshift","affected":["mirror_registry_for_red_hat_openshift","mirror_registry_for_red_hat_openshift = 2.0"],"published":"2026-04-08","updated":"2026-07-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-14243","references":[{"url":"https://access.redhat.com/security/cve/CVE-2025-14243","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2419829","label":"secalert@redhat.com"}],"tags":["nvd"],"epss":0.00287,"epssPercentile":0.21487,"ingestedAt":"2026-07-26T00:06:14.933Z","slug":"CVE-2025-14243","body":"## Overview\n\nA flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation.\n\n## Affected\n\n- `mirror_registry_for_red_hat_openshift`\n- `mirror_registry_for_red_hat_openshift = 2.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}