---
id: CVE-2025-14243
title: A flaw was found in the OpenShift Mirror Registry
summary: >-
  A flaw was found in the OpenShift Mirror Registry. This vulnerability allows
  an unauthenticated, remote attacker to enumerate valid usernames and email
  addresses via different error messages during authentication failures and
  account cre…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-209
vendor: redhat
product: mirror_registry_for_red_hat_openshift
affected:
  - mirror_registry_for_red_hat_openshift
  - mirror_registry_for_red_hat_openshift = 2.0
published: '2026-04-08'
updated: '2026-07-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14243'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2025-14243'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2419829'
    label: secalert@redhat.com
tags:
  - nvd
epss: 0.00287
epssPercentile: 0.18893
ingestedAt: '2026-07-26T00:06:14.933Z'
---

## Overview

A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation.

## Affected

- `mirror_registry_for_red_hat_openshift`
- `mirror_registry_for_red_hat_openshift = 2.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
