Red Hat Security Advisory: Red Hat Developer Hub 1.10.2 release.
🔗 CVE IDs covered (29)
📋 Description
CVE-2026-6322 — fast-uri: fast-uri: URI authority bypass due to improper delimiter handling
CVE-2026-6734 — undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing
CVE-2026-9277 — shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators
CVE-2026-9673 — json-2-csv: json-2-csv: CSV Injection vulnerability allows arbitrary code execution via preventCsvInjection bypass.
CVE-2026-9697 — undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy
CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection
CVE-2026-12151 — undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames
CVE-2026-24781 — vm2: vm2: Arbitrary code execution via sandbox breakout through inspect function
CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass
CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs
CVE-2026-42338 — ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input
CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing
CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects
CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows
CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits
CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability
CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray
CVE-2026-47131 — vm2: vm2: Arbitrary code execution via sandbox escape vulnerability
CVE-2026-47135 — vm2: vm2: Sandbox escape allows arbitrary code execution on the host system
CVE-2026-47137 — vm2: vm2: Sandbox escape leading to arbitrary code execution via security bypass
CVE-2026-47139 — vm2: vm2: Sandbox escape via internal HTTP built-ins leading to network restriction bypass
CVE-2026-47140 — vm2: vm2: Arbitrary code execution due to incomplete sandbox restrictions
CVE-2026-47141 — vm2: vm2: NodeVM observability builtins leak host process and HTTP request data
CVE-2026-47208 — vm2: vm2: Sandbox Breakout Using Promise Species
CVE-2026-47210 — vm2: vm2: Arbitrary code execution via sandbox escape when executing untrusted code with async support.
CVE-2026-48779 — ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments
🎯 Affected products6
- Red Hat Developer Hub 1.10
- registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:61883f5228095e3a3fd5b7daf60e29a5ffd053844f8661a2b5282a77c086dc02_amd64 as a component of Red Hat Developer Hub 1.10
- registry.redhat.io/rhdh/rhdh-must-gather-rhel9@sha256:aacbef97f59305a91db44c3c92c34509027b3d2a4ece07716e6fe8b217dd5ee1_amd64 as a component of Red Hat Developer Hub 1.10
- registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:d4208a03e389fe82e7da2d27c491251e6d43a0b473aa80d3e6a351c77582a92a_amd64 as a component of Red Hat Developer Hub 1.10
- registry.redhat.io/rhdh/rhdh-rag-content-rhel9@sha256:bea9305c453e377dfe6abf20076aec408efe2cbcf05f5a1c04c9b2d2f288bd65_amd64 as a component of Red Hat Developer Hub 1.10
- registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:0856143fa78dbbd74c1c068c75c265451698913608009f40600bb7c46928739b_amd64 as a component of Red Hat Developer Hub 1.10
✅ Remediation
For more about Red Hat Developer Hub, see References links Workaround: The single most impactful mitigation is applying network egress controls to restrict which external destinations affected applications can reach. Because the vulnerability causes requests to be misrouted to wrong origins, limiting the set of reachable origins directly reduces the attack surface. These controls collectively limit the blast radius of the connection pool misrouting — the attacker must compromise one of the explicitly allowed destinations rather than any arbitrary origin — but they do not fix the underlying logic bug. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted.
🔗 References (41)
- selfhttps://access.redhat.com/errata/RHSA-2026:36754
- externalhttps://access.redhat.com/security/cve/CVE-2026-12143
- externalhttps://access.redhat.com/security/cve/CVE-2026-12151
- externalhttps://access.redhat.com/security/cve/CVE-2026-24781
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-42338
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-44486
- externalhttps://access.redhat.com/security/cve/CVE-2026-44487
- externalhttps://access.redhat.com/security/cve/CVE-2026-44488
- externalhttps://access.redhat.com/security/cve/CVE-2026-44492
- externalhttps://access.redhat.com/security/cve/CVE-2026-44494
- externalhttps://access.redhat.com/security/cve/CVE-2026-44495
- externalhttps://access.redhat.com/security/cve/CVE-2026-44496
- externalhttps://access.redhat.com/security/cve/CVE-2026-45736
- externalhttps://access.redhat.com/security/cve/CVE-2026-47131
- externalhttps://access.redhat.com/security/cve/CVE-2026-47135
- externalhttps://access.redhat.com/security/cve/CVE-2026-47137
- externalhttps://access.redhat.com/security/cve/CVE-2026-47139
- externalhttps://access.redhat.com/security/cve/CVE-2026-47140
- externalhttps://access.redhat.com/security/cve/CVE-2026-47141
- externalhttps://access.redhat.com/security/cve/CVE-2026-47208
- externalhttps://access.redhat.com/security/cve/CVE-2026-47210
- externalhttps://access.redhat.com/security/cve/CVE-2026-48779
- externalhttps://access.redhat.com/security/cve/CVE-2026-6322
- externalhttps://access.redhat.com/security/cve/CVE-2026-6734
- externalhttps://access.redhat.com/security/cve/CVE-2026-9277
- externalhttps://access.redhat.com/security/cve/CVE-2026-9673
- externalhttps://access.redhat.com/security/cve/CVE-2026-9697
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/search?gs&searchType=containers&q=rhdh
- externalhttps://developers.redhat.com/rhdh/overview
- externalhttps://docs.redhat.com/en/documentation/red_hat_developer_hub
- externalhttps://issues.redhat.com/browse/RHDHBUGS-3286
- externalhttps://issues.redhat.com/browse/RHDHBUGS-3288
- externalhttps://issues.redhat.com/browse/RHDHBUGS-3290
- externalhttps://issues.redhat.com/browse/RHDHBUGS-3291
- externalhttps://issues.redhat.com/browse/RHDHBUGS-3293
- externalhttps://issues.redhat.com/browse/RHDHBUGS-3398
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_36754.json