RHSA-2026:2844HighCVSS 9.8
Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.26.1 Release.
🔗 CVE IDs covered (6)
📋 Description
CVE-2025-6176 — Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS CVE-2025-15467 — openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61732 — cmd/cgo: Go cgo: Code smuggling due to comment parsing discrepancy CVE-2026-0719 — libsoup: Signed to Unsigned Conversion Error Leading to Stack-Based Buffer Overflow in libsoup NTLM Authentication CVE-2026-1761 — libsoup: Stack-Based Buffer Overflow in libsoup Multipart Response Parsingmultipart HTTP response
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:2844
- externalhttps://access.redhat.com/documentation/en-us/red_hat_openshift_dev_spaces/3.26/html/administration_guide/installing-devspaces
- externalhttps://access.redhat.com/security/cve/CVE-2025-15467
- externalhttps://access.redhat.com/security/cve/CVE-2025-61726
- externalhttps://access.redhat.com/security/cve/CVE-2025-61732
- externalhttps://access.redhat.com/security/cve/CVE-2025-6176
- externalhttps://access.redhat.com/security/cve/CVE-2026-0719
- externalhttps://access.redhat.com/security/cve/CVE-2026-1761
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2844.json