RHSA-2025:22861HighCVSS 8.2

Red Hat Security Advisory: Red Hat Developer Hub 1.8.1 release.

Published
December 8, 2025
Last Modified
September 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-60542 — TypeORM: SQL Injection via crafted request to repository.save or repository.update CVE-2025-66031 — node-forge: node-forge ASN.1 Unbounded Recursion

🎯 Affected products4

  • Red Hat Developer Hub 1.8
  • registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:27d08ffa1bc6a2270b5eab59aedaf866cf68ccb902503c2e58e2e2337a1236b9_amd64 as a component of Red Hat Developer Hub 1.8
  • registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:8b5ec4b6085ecb32ea52c33d97adecc313341681b41d891f5346e9b9f8b8a249_amd64 as a component of Red Hat Developer Hub 1.8
  • registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:43839417363ec2910a4746050005f9fbe5efe5776d44a0bd36a8f4b8ecf71ffa_amd64 as a component of Red Hat Developer Hub 1.8

✅ Remediation

For more about Red Hat Developer Hub, see References links Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (10)