Red Hat Security Advisory: Red Hat Developer Hub 1.9.3 release.
🔗 CVE IDs covered (15)
📋 Description
CVE-2025-61140 — jsonpath: jsonpath: Prototype Pollution vulnerability in the value function CVE-2025-69873 — ajv: ReDoS via $data reference CVE-2026-1615 — jsonpath: jsonpath: Arbitrary Code Execution via unsafe JSON Path expression evaluation CVE-2026-2359 — multer: Multer: Denial of Service via dropped file upload connections CVE-2026-3304 — multer: Multer: Denial of Service via malformed requests CVE-2026-3520 — multer: Multer: Denial of Service via malformed requests CVE-2026-24046 — backstage/backend-defaults: backstage/plugin-scaffolder-backend: backstage/plugin-scaffolder-node: possible symlink path traversal in scaffolder actions CVE-2026-25153 — @backstage/plugin-techdocs-node: @backstage/plugin-techdocs-node vulnerable to arbitrary code execution via MkDocs hooks CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig CVE-2026-25679 — net/url: Incorrect parsing of IPv6 host literals in net/url CVE-2026-25896 — fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling CVE-2026-26278 — fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion CVE-2026-27606 — rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability CVE-2026-27942 — fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
🔗 References (22)
- selfhttps://access.redhat.com/errata/RHSA-2026:6802
- externalhttps://access.redhat.com/security/cve/CVE-2025-61140
- externalhttps://access.redhat.com/security/cve/CVE-2025-69873
- externalhttps://access.redhat.com/security/cve/CVE-2026-1615
- externalhttps://access.redhat.com/security/cve/CVE-2026-2359
- externalhttps://access.redhat.com/security/cve/CVE-2026-24046
- externalhttps://access.redhat.com/security/cve/CVE-2026-25153
- externalhttps://access.redhat.com/security/cve/CVE-2026-25639
- externalhttps://access.redhat.com/security/cve/CVE-2026-25679
- externalhttps://access.redhat.com/security/cve/CVE-2026-25896
- externalhttps://access.redhat.com/security/cve/CVE-2026-26278
- externalhttps://access.redhat.com/security/cve/CVE-2026-27606
- externalhttps://access.redhat.com/security/cve/CVE-2026-27942
- externalhttps://access.redhat.com/security/cve/CVE-2026-3304
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-3520
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/search?gs&searchType=containers&q=rhdh
- externalhttps://developers.redhat.com/rhdh/overview
- externalhttps://docs.redhat.com/en/documentation/red_hat_developer_hub
- externalhttps://issues.redhat.com/browse/RHDHBUGS-2736
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_6802.json