RHSA-2026:26234HighCVSS 8.8

Red Hat Security Advisory: Red Hat Developer Hub 1.9.5 release.

Published
June 16, 2026
Last Modified
August 25, 2026

🔗 CVE IDs covered (10)

📋 Description

CVE-2026-6321 — fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling CVE-2026-24781 — vm2: vm2: Arbitrary code execution via sandbox breakout through inspect function CVE-2026-32281 — crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation CVE-2026-41242 — protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields CVE-2026-41672 — xmldom: @xmldom/xmldom: xmldom: Arbitrary XML Node Injection CVE-2026-41673 — @xmldom/xmldom: xmldom: xmldom: Denial of Service via deeply nested XML documents CVE-2026-41674 — xmldom: xmldom: Arbitrary XML markup injection CVE-2026-41675 — xmldom: xmldom: Arbitrary XML node injection via crafted processing instructions CVE-2026-44293 — protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors

🎯 Affected products4

  • Red Hat Developer Hub 1.9
  • registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:dca74b10e54c6598ef2f8d962f677895ee6ca745778f0f5db25e0ebfe443990e_amd64 as a component of Red Hat Developer Hub 1.9
  • registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:dac8b7c19b9bf59aa6df97828ae6955252ba45246d1597cd2cf46c028dfce4fb_amd64 as a component of Red Hat Developer Hub 1.9
  • registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:9e95e1183f47b0f9aa439bdb408a0ccdf87b72cefe704abad0c7e9a90bd607f5_amd64 as a component of Red Hat Developer Hub 1.9

✅ Remediation

For more about Red Hat Developer Hub, see References links Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (17)