Red Hat Security Advisory: Red Hat Developer Hub 1.10.0 release.
🔗 CVE IDs covered (7)
📋 Description
CVE-2026-2950 — lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass CVE-2026-4923 — path-to-regexp: path-to-regexp: Denial of Service via specially crafted paths with multiple wildcards CVE-2026-22036 — undici: Undici: Denial of Service via excessive decompression steps CVE-2026-27601 — Underscore.js: Underscore.js: Denial of Service via recursive data structures in flatten and isEqual functions CVE-2026-31988 — yauzl: yauzl: Denial of Service vulnerability in zip file processing CVE-2026-32235 — @backstage/plugin-auth-backend: @backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass CVE-2026-33349 — fast-xml-parser: fast-xml-parser: Denial of Service via unbounded entity expansion due to incorrect configuration limit handling
🎯 Affected products4
- Red Hat Developer Hub 1.10
- registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:b99622b2ec913bdf7ad25a7a9919fbf07a6a177548b3f486acf648c533ca4f22_amd64 as a component of Red Hat Developer Hub 1.10
- registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:b04577fd53315437ef4580af92055fb5238649a5a11e68e264ea1ed70eae79db_amd64 as a component of Red Hat Developer Hub 1.10
- registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:c290c8d9d433286ac038022c229b359500b7451a3d3f97c3c50371b6198df029_amd64 as a component of Red Hat Developer Hub 1.10
✅ Remediation
For more about Red Hat Developer Hub, see References links Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, applications utilizing Underscore.js should ensure that any processing of untrusted, recursively structured data with `_.flatten` or `_.isEqual` explicitly enforces a finite depth limit. Review application code to identify and modify calls to these functions, adding appropriate depth parameters to prevent stack overflow conditions. Additionally, input validation should be implemented to sanitize untrusted data before it is processed by Underscore.js functions.
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2026:24841
- externalhttps://access.redhat.com/security/cve/CVE-2026-22036
- externalhttps://access.redhat.com/security/cve/CVE-2026-27601
- externalhttps://access.redhat.com/security/cve/CVE-2026-2950
- externalhttps://access.redhat.com/security/cve/CVE-2026-31988
- externalhttps://access.redhat.com/security/cve/CVE-2026-32235
- externalhttps://access.redhat.com/security/cve/CVE-2026-33349
- externalhttps://access.redhat.com/security/cve/CVE-2026-4923
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/search?gs&searchType=containers&q=rhdh
- externalhttps://developers.redhat.com/rhdh/overview
- externalhttps://docs.redhat.com/en/documentation/red_hat_developer_hub
- externalhttps://issues.redhat.com/browse/RHDHBUGS-2870
- externalhttps://issues.redhat.com/browse/RHDHBUGS-2962
- externalhttps://issues.redhat.com/browse/RHDHBUGS-2964
- externalhttps://issues.redhat.com/browse/RHDHBUGS-2965
- externalhttps://issues.redhat.com/browse/RHDHBUGS-2966
- externalhttps://issues.redhat.com/browse/RHDHBUGS-2971
- externalhttps://issues.redhat.com/browse/RHDHBUGS-2974
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_24841.json