RHSA-2026:2456HighCVSS 8.7

Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.26.0 Release.

Published
February 10, 2026
Last Modified
June 3, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2024-25621 — github.com/containerd/containerd: containerd local privilege escalation CVE-2025-12816 — node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications CVE-2025-15284 — qs: qs: Denial of Service via improper input validation in array parsing CVE-2025-52881 — runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects CVE-2025-58183 — golang: archive/tar: Unbounded allocation when parsing GNU sparse map CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-64756 — glob: glob: Command Injection Vulnerability via Malicious Filenames CVE-2025-65945 — node-jws: auth0/node-jws: Improper signature verification in HS256 algorithm CVE-2025-66031 — node-forge: node-forge ASN.1 Unbounded Recursion CVE-2025-66418 — urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion CVE-2025-66471 — urllib3: urllib3 Streaming API improperly handles highly compressed data CVE-2025-66490 — github.com/traefik/traefik: Traefik Path Normalization Bypass in Router + Middleware Rules CVE-2026-21441 — urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) CVE-2026-22029 — @remix-run/router: react-router: React Router vulnerable to XSS via Open Redirects

🔗 References (18)