RHSA-2026:6174HighCVSS 9.1

Red Hat Security Advisory: Red Hat Developer Hub 1.8.5 release.

Published
March 30, 2026
Last Modified
June 3, 2026

🔗 CVE IDs covered (12)

CVE-2026-25153CVE-2026-25639CVE-2026-33186CVE-2026-3520 · pendingCVE-2026-24046CVE-2026-25896 · pendingCVE-2026-26278 · pendingCVE-2026-27606 · pendingCVE-2026-27942 · pendingCVE-2025-61140CVE-2026-2359 · pendingCVE-2026-3304 · pending

📋 Description

CVE-2025-61140 — jsonpath: jsonpath: Prototype Pollution vulnerability in the value function CVE-2026-2359 — multer: Multer: Denial of Service via dropped file upload connections CVE-2026-3304 — multer: Multer: Denial of Service via malformed requests CVE-2026-3520 — multer: Multer: Denial of Service via malformed requests CVE-2026-24046 — backstage/backend-defaults: backstage/plugin-scaffolder-backend: backstage/plugin-scaffolder-node: possible symlink path traversal in scaffolder actions CVE-2026-25153 — @backstage/plugin-techdocs-node: @backstage/plugin-techdocs-node vulnerable to arbitrary code execution via MkDocs hooks CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig CVE-2026-25896 — fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling CVE-2026-26278 — fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion CVE-2026-27606 — rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability CVE-2026-27942 — fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

🔗 References (30)