RHSA-2026:6802HighCVSS 9.8

Red Hat Security Advisory: Red Hat Developer Hub 1.9.3 release.

Published
April 7, 2026
Last Modified
June 3, 2026

🔗 CVE IDs covered (15)

CVE-2026-25153CVE-2026-27606 · pendingCVE-2025-61140CVE-2025-69873CVE-2026-3304 · pendingCVE-2026-3520 · pendingCVE-2026-26278 · pendingCVE-2026-33186CVE-2026-1615CVE-2026-24046CVE-2026-25639CVE-2026-27942 · pendingCVE-2026-2359 · pendingCVE-2026-25679CVE-2026-25896 · pending

📋 Description

CVE-2025-61140 — jsonpath: jsonpath: Prototype Pollution vulnerability in the value function CVE-2025-69873 — ajv: ReDoS via $data reference CVE-2026-1615 — jsonpath: jsonpath: Arbitrary Code Execution via unsafe JSON Path expression evaluation CVE-2026-2359 — multer: Multer: Denial of Service via dropped file upload connections CVE-2026-3304 — multer: Multer: Denial of Service via malformed requests CVE-2026-3520 — multer: Multer: Denial of Service via malformed requests CVE-2026-24046 — backstage/backend-defaults: backstage/plugin-scaffolder-backend: backstage/plugin-scaffolder-node: possible symlink path traversal in scaffolder actions CVE-2026-25153 — @backstage/plugin-techdocs-node: @backstage/plugin-techdocs-node vulnerable to arbitrary code execution via MkDocs hooks CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-25896 — fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling CVE-2026-26278 — fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion CVE-2026-27606 — rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability CVE-2026-27942 — fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation

🔗 References (22)