RHSA-2025:19529HighCVSS 7.5

Red Hat Security Advisory: Red Hat Developer Hub 1.7.2 release.

Published
November 3, 2025
Last Modified
August 9, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-58754 — axios: Axios DoS via lack of data size check CVE-2025-59343 — tar-fs: tar-fs symlink validation bypass

🎯 Affected products4

  • Red Hat Developer Hub 1.7
  • registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:385d0b730e3f14f6878221d817b58d31da560c2edc52235b74bbbd8324b29389_amd64 as a component of Red Hat Developer Hub 1.7
  • registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:89f8116ae0bd38b62ae4babdaff52f15a2f6b266633aa0c4099637a70655b93c_amd64 as a component of Red Hat Developer Hub 1.7
  • registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:9de53b6a5b983f026c3bd91f2cb6eee9ddb881e5d15d0b3df2fa080966abb333_amd64 as a component of Red Hat Developer Hub 1.7

✅ Remediation

For more about Red Hat Developer Hub, see References links Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (10)