RHSA-2026:25123HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.28.2 Release.

Published
June 10, 2026
Last Modified
August 23, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2026-6321 — fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies CVE-2026-42578 — netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation CVE-2026-42579 — netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement CVE-2026-42581 — netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers CVE-2026-42584 — netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion CVE-2026-42587 — netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression CVE-2026-43512 — tomcat-coyote: Apache Tomcat: Authentication bypass via digest authentication

🎯 Affected products62

  • Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/code-rhel9@sha256:7e20cd1d638296bcab93a704bfce3ff7cf6c0f7e632e07e69fcacfedf9e8b120_arm64 as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/code-rhel9@sha256:83e1013b0ce89c1f4fc0038c1cb7eab2fd541a6fb1de6a0596fe669a76cde1f4_s390x as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/code-rhel9@sha256:9d47eee451c3d7c7a0c2d83824849ac4053110107997a41df26fe28f9b4749de_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/code-rhel9@sha256:bb9e332650eb73ce20accc25d8bc73bb935e39e0bc6a9b0e7b163707ae25ce6f_amd64 as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/code-sshd-rhel9@sha256:0ce3e6baa0af251b5ae5e8cc64de363aa144c420e1416a2a7bf522aefe0b6dd3_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/code-sshd-rhel9@sha256:324758a4c214f743ba3f38eee3ae2c3f42eac80ac4c10801e103fc531d73cf51_arm64 as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/code-sshd-rhel9@sha256:82994d108c21e3f53c2d87bdec8ddcdb0c0f81c7f1ed93ac996fe83046ea8ed1_s390x as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/code-sshd-rhel9@sha256:b1b3d7416bc5c1609fa890229fc0a0809bc1906813bb4834f57dc610f88974c1_amd64 as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/configbump-rhel9@sha256:5bcd49999db0f7ac5fbc2461c7ac50dec267ee8b4f64c95bdcd746188ab0bfa0_amd64 as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/configbump-rhel9@sha256:62ecbc41b3f1d3cd81e9593fdacac8397d1fc3f616717b247346ac218b7a2ff7_s390x as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/configbump-rhel9@sha256:7ee3d2e13995479495aa2a2f3b7a8f8133f7b69d0e753b00e3fe2ee00416b3a9_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/configbump-rhel9@sha256:b52e83ecc17aefda4a83671c267b3086bb5f92d78259c3e3b2b389042bac7230_arm64 as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/dashboard-rhel9@sha256:1cef563af30567f7aba3baeb6fa94494f93ac07350a23fabaa67d079f780f640_amd64 as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/dashboard-rhel9@sha256:ae7dc192f8ca8c78dc6eb12ef2846b45057e22e183207743aad9261fb5adcb6e_s390x as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/dashboard-rhel9@sha256:ca07c7ae5cdcf93df21348d92c4828e4615b324f2f765907b3459f0d5090c628_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/dashboard-rhel9@sha256:dee20a799ccf5bae94ed50fd2d79ea162cd7384990427db93281fe590d6c7767_arm64 as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:f78d91e983f0f8be019382c2fb620a655bf9f8204bd839e9bfb9c35e1ab8fc90_amd64 as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:4757ac1e8c5a53e2d9a7ce896dbcc1232806a47a29470285c6fee9778a2f0b25_arm64 as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:4e4a72be08cf691ee40dc79d2e625a5b59cf709e15219537ee04a1f03a3df23e_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:a5b3c16ca82c2585debbef262d8de80bb8566384c916915d9fce92d233268d1c_s390x as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:dd4b506d04a2e7be2c62c53a7e1f60fe828ba7f0fc2aab7f6a752f1a4c4e699b_amd64 as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/imagepuller-rhel9@sha256:21d1288562fc757e4714cde2c253c077fba1b7762ab4041e8b3f55d9da1e7b82_arm64 as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/imagepuller-rhel9@sha256:2423f169dcd795c9326d59d953b4507485bf2ef8971f066969dfb2ca921bdf1f_amd64 as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/imagepuller-rhel9@sha256:5e4c074f39614f529e79c8de011446a0b621fb189485eff0061f95f99f0950f8_s390x as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/imagepuller-rhel9@sha256:f1cf981295bdfddb68c8cb83e03da7cbec9aada7dce16586a1508351b11c2e73_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:0de97d2e0e6589cfd3889eca0284154e857c4deef4ab45420e0d75bfc8030252_amd64 as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:12a042cb9e94c6502b61c6d08a49bc8b81f8d3e23932b08c29566906508801d8_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:25137cf516214eac04d5f1fd2ad9a38658e8fc741600b50b4c44f00db437cf01_s390x as a component of Red Hat OpenShift Dev Spaces 3.28
  • registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:5cb0df6d628f764eead0f67206b7251b737932ae04f81dd8c1fd416d2c1be455_arm64 as a component of Red Hat OpenShift Dev Spaces 3.28
  • +32 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Applications utilizing Netty's HttpProxyHandler must ensure that any user-controlled input used to populate outbound headers is rigorously sanitized to prevent CRLF injection. If comprehensive input sanitization cannot be implemented, restricting network access to the application that uses the HttpProxyHandler can reduce the attack surface. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, configure any reverse proxies or load balancers in front of Netty to either reject HTTP/1.0 requests containing both Transfer-Encoding: chunked and Content-Length headers, or to explicitly prioritize the Transfer-Encoding header over Content-Length for HTTP/1.0 traffic. This ensures consistent interpretation of message boundaries and prevents request smuggling attacks. Workaround: To mitigate this issue, disable DIGEST authentication within Apache Tomcat if it is not essential for your environment. This involves modifying the server's authentication configuration to utilize alternative methods or remove the DIGEST realm. A service restart is required for these changes to take effect and may impact functionality relying on DIGEST authentication.

🔗 References (11)