RHSA-2025:14090HighCVSS 8.1

Red Hat Security Advisory: Red Hat Developer Hub 1.7.0 release.

Published
August 19, 2025
Last Modified
September 6, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2025-5417 — rhdh: Red Hat Developer Hub user permissions CVE-2025-6545 — pbkdf2: pbkdf2 silently returns predictable key material CVE-2025-7338 — multer: Multer Denial of Service CVE-2025-22870 — golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net CVE-2025-32996 — http-proxy-middleware: Always-Incorrect Control Flow Implementation in http-proxy-middleware CVE-2025-32997 — http-proxy-middleware: Improper Check for Unusual or Exceptional Conditions in http-proxy-middleware CVE-2025-48387 — tar-fs: tar-fs has issue where extract can write outside the specified dir with a specific tarball CVE-2025-48997 — multer: Multer vulnerable to Denial of Service via unhandled exception CVE-2025-54419 — @node-saml/node-saml: Node-SAML Signature Verification Vulnerability

🎯 Affected products4

  • Red Hat Developer Hub 1.7
  • registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:aa3c5b50c65aee51b932fafcbf479ce54f15496cffc2744860bd9e135cce815c_amd64 as a component of Red Hat Developer Hub 1.7
  • registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:7dad33bce18ec8417e9345ce8cdd39f3c9bfd637cecc8ce6750fa3e5279dc06b_amd64 as a component of Red Hat Developer Hub 1.7
  • registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:72beabd2760976369736af8c22388b030603f9d503020aa581f4b8ec1c50c740_amd64 as a component of Red Hat Developer Hub 1.7

✅ Remediation

For more about Red Hat Developer Hub, see References links Workaround: Red Hat Developer Hub 1.5 contains mitigation guidelines present at https://docs.redhat.com/en/documentation/red_hat_developer_hub/1.5/html/configuring_red_hat_developer_hub/readonlyrootfilesystem Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.

🔗 References (18)