Red Hat Security Advisory: Red Hat Developer Hub 1.8.5 release.
🔗 CVE IDs covered (12)
📋 Description
CVE-2025-61140 — jsonpath: jsonpath: Prototype Pollution vulnerability in the value function CVE-2026-2359 — multer: Multer: Denial of Service via dropped file upload connections CVE-2026-3304 — multer: Multer: Denial of Service via malformed requests CVE-2026-3520 — multer: Multer: Denial of Service via malformed requests CVE-2026-24046 — backstage/backend-defaults: backstage/plugin-scaffolder-backend: backstage/plugin-scaffolder-node: possible symlink path traversal in scaffolder actions CVE-2026-25153 — @backstage/plugin-techdocs-node: @backstage/plugin-techdocs-node vulnerable to arbitrary code execution via MkDocs hooks CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig CVE-2026-25896 — fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling CVE-2026-26278 — fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion CVE-2026-27606 — rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability CVE-2026-27942 — fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
🔗 References (30)
- selfhttps://access.redhat.com/errata/RHSA-2026:6174
- externalhttps://access.redhat.com/security/cve/CVE-2025-61140
- externalhttps://access.redhat.com/security/cve/CVE-2026-2359
- externalhttps://access.redhat.com/security/cve/CVE-2026-24046
- externalhttps://access.redhat.com/security/cve/CVE-2026-25153
- externalhttps://access.redhat.com/security/cve/CVE-2026-25639
- externalhttps://access.redhat.com/security/cve/CVE-2026-25896
- externalhttps://access.redhat.com/security/cve/CVE-2026-26278
- externalhttps://access.redhat.com/security/cve/CVE-2026-27606
- externalhttps://access.redhat.com/security/cve/CVE-2026-27942
- externalhttps://access.redhat.com/security/cve/CVE-2026-3304
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-3520
- externalhttps://issues.redhat.com/browse/RHIDP-11518
- externalhttps://issues.redhat.com/browse/RHIDP-11639
- externalhttps://issues.redhat.com/browse/RHIDP-11731
- externalhttps://issues.redhat.com/browse/RHIDP-12139
- externalhttps://issues.redhat.com/browse/RHIDP-12323
- externalhttps://issues.redhat.com/browse/RHIDP-12335
- externalhttps://issues.redhat.com/browse/RHIDP-12392
- externalhttps://issues.redhat.com/browse/RHIDP-12417
- externalhttps://issues.redhat.com/browse/RHIDP-12444
- externalhttps://issues.redhat.com/browse/RHIDP-12447
- externalhttps://issues.redhat.com/browse/RHIDP-12480
- externalhttps://issues.redhat.com/browse/RHIDP-12904
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/search?gs&searchType=containers&q=rhdh
- externalhttps://developers.redhat.com/rhdh/overview
- externalhttps://docs.redhat.com/en/documentation/red_hat_developer_hub
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_6174.json