Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.29.0 Release.
🔗 CVE IDs covered (31)
📋 Description
CVE-2026-6734 — undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing
CVE-2026-9697 — undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy
CVE-2026-12151 — undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames
CVE-2026-12856 — vscode-java: vscode: Command Injection vulnerability in the JavaDoc hover provider of the vscode-java extension
CVE-2026-34986 — github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object
CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-39829 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
CVE-2026-42338 — ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input
CVE-2026-42578 — netty: io.netty/netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation
CVE-2026-42579 — netty: Netty: High integrity impact due to improper DNS domain name constraint enforcement
CVE-2026-42581 — netty: io.netty/netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers
CVE-2026-42583 — netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder
CVE-2026-42584 — netty: io.netty/netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion
CVE-2026-42587 — netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
CVE-2026-44249 — netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects
CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows
CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits
CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability
CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
CVE-2026-44774 — traefik: Traefik: Privilege escalation via Kubernetes Gateway API provider configuration bypass
CVE-2026-44893 — netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message
CVE-2026-45292 — opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage
CVE-2026-45736 — ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray
CVE-2026-46595 — golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation
CVE-2026-48043 — netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
CVE-2026-48059 — netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers
CVE-2026-48779 — ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments
CVE-2026-50559 — io.quarkus/quarkus-vertx-http: Quarkus: Authorization bypass in HTTP path-based policies via encoded characters
🎯 Affected products66
- Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/code-rhel9@sha256:1384e5ba2b7d23119a49d8713826f4c65668bca310589ac7abd0c0d41c7e4c90_arm64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/code-rhel9@sha256:7f58528b1da9146aa55917324fdf2b375794742b34e5d10ff57f713af60746cd_amd64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/code-rhel9@sha256:844c3b1499b00aeadfc561642e53792ad80f535efd53b35793ba08b0f26c6d61_s390x as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/code-rhel9@sha256:e1019c30e1d84e66d775d0d6fc7d051803dcbe44823fb2a1914807be39c79dae_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/code-sshd-rhel9@sha256:8c9a7ebf430b9f4ca200c6c70b049e8456cf88fd8bf0871b42d65e8dc786d451_amd64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/code-sshd-rhel9@sha256:926d965e6fd12ec0d758270fb4c90bbdc1a05e60cc4c895cf9b671a296c9d867_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/code-sshd-rhel9@sha256:e8e807451e3c5d8d0a8575e1280d7125a4ece51547a7b4a5cd247837662cedad_s390x as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/code-sshd-rhel9@sha256:f2a24aa01cbe0d926d4aefe3b12eba21eb5ec7f87276e572a6814c727228624c_arm64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/configbump-rhel9@sha256:45cc0d783d1e7874ac73dfbdfe7e03c63b227ab3c4f1e15a0a2f5c97956a76d9_s390x as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/configbump-rhel9@sha256:6f3eb26734e89375c3e1fb7ac366e12dc0d41bac8f07de9210c7e9845a01eec1_arm64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/configbump-rhel9@sha256:768c45fa9f35d98dfe5cfe1ea12f552402bf68ac6e1f828b14310ef59ce57c40_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/configbump-rhel9@sha256:b5f1bf30495f6be97c696cf7f90768629cee96f8d106f745bf95fdefddc99592_amd64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/dashboard-rhel9@sha256:137ffbb95d463d95da6c350600d968f3cd0e9873bf2e7c6edf952ae3229e9e2b_amd64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/dashboard-rhel9@sha256:1cccdfd7e90877c27c6d8caea4f1e8ad89bb97c83d97ddf570d4f4ee116f1986_arm64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/dashboard-rhel9@sha256:71657b82894cfd9e350746f48965e148868a675b9a20dcb7f94a6bc7a5b16ea5_s390x as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/dashboard-rhel9@sha256:881e405e32821ef10cf992c7a633281c1dc45df721fe909048df1689472000ce_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:6c85b42ede0f4745ed558bcb03d033c49f56cef17a70c12e5308066124cac6e3_amd64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:091529a93e258a612fd4a98222e6a370ee10b4e97efa791b50f79a2670163d01_amd64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:0e8958a22f6771ddfe32b34027c69dbbef65d980c7e465a79d4202d2627994ad_arm64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:5a8b0203ff083113e8b30a123ab30c4bad571f57fb59c1e7e01807b92552504e_s390x as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:89bf6a32a0935cacadbc6d23566dce6ca741e404d58c11050638c7b8e868028b_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/imagepuller-rhel9@sha256:077cc953354ea2edd85569a622f97c15d44163d68234e7a9fdee899d25c19cdb_amd64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/imagepuller-rhel9@sha256:66285f866090e1bfbedacd592e9d5ea9f2a30b88aa03bc86bc790d6b98a929a4_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/imagepuller-rhel9@sha256:8c80054171d5063457df4bd074674b1824783a101dacb6137da227080aff957c_s390x as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/imagepuller-rhel9@sha256:b0f15904251c6665961eef9c944d00f17499f7219351fe213fe7935f62fbf7ac_arm64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:62476ac2fb0096caa9b181f523cc3573ccffe70be1433f08d1d0255b6d3a0640_arm64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:6f632bc9829880a44e2e94084284b52683b4a01dc3315043b0aa32eb344b16cb_amd64 as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:aa3d1cf7853bfe8307efb01f714585f378d1d3d4ed5de7c8808a72e4aeecd4f3_s390x as a component of Red Hat OpenShift Dev Spaces 3.29
- registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:bf1d4b2b1ef03e65be59699ce3233a75a34e1777abc182984c7a8efa698a936e_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.29
- +36 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The single most impactful mitigation is applying network egress controls to restrict which external destinations affected applications can reach. Because the vulnerability causes requests to be misrouted to wrong origins, limiting the set of reachable origins directly reduces the attack surface. These controls collectively limit the blast radius of the connection pool misrouting — the attacker must compromise one of the explicitly allowed destinations rather than any arbitrary origin — but they do not fix the underlying logic bug. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, users should avoid opening or interacting with untrusted Java projects or files within Red Hat OpenShift Dev Spaces. Exercise caution and refrain from clicking on unfamiliar links presented in JavaDoc hover popups, particularly when working with code from unverified sources. Disabling the `vscode-java` extension when not actively engaged in Java development can further reduce exposure, though this will impact Java-related functionality. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Applications utilizing Netty's HttpProxyHandler must ensure that any user-controlled input used to populate outbound headers is rigorously sanitized to prevent CRLF injection. If comprehensive input sanitization cannot be implemented, restricting network access to the application that uses the HttpProxyHandler can reduce the attack surface. Workaround: To mitigate this issue, configure any reverse proxies or load balancers in front of Netty to either reject HTTP/1.0 requests containing both Transfer-Encoding: chunked and Content-Length headers, or to explicitly prioritize the Transfer-Encoding header over Content-Length for HTTP/1.0 traffic. This ensures consistent interpretation of message boundaries and prevents request smuggling attacks. Workaround: Upgrade Traefik to version 2.11.46 or later (2.x line), 3.6.17 or later (3.6.x line), or 3.7.1 or later (3.7.x line) by installing updated Red Hat OpenShift Dev Spaces releases that ship a fixed traefik-rhel9 container image. Until updated images are available, limit which principals can create HTTPRoute resources in namespaces where Traefik runs with the Kubernetes Gateway API provider. Disable or tightly restrict the Traefik REST dynamic configuration provider in shared Gateway deployments, and block untrusted use of TraefikService backends that reference @internal handlers.
🔗 References (35)
- selfhttps://access.redhat.com/errata/RHSA-2026:36820
- externalhttps://access.redhat.com/documentation/en-us/red_hat_openshift_dev_spaces/3.29/html/administration_guide/installing-devspaces
- externalhttps://access.redhat.com/security/cve/CVE-2026-12151
- externalhttps://access.redhat.com/security/cve/CVE-2026-12856
- externalhttps://access.redhat.com/security/cve/CVE-2026-34986
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-39829
- externalhttps://access.redhat.com/security/cve/CVE-2026-42338
- externalhttps://access.redhat.com/security/cve/CVE-2026-42578
- externalhttps://access.redhat.com/security/cve/CVE-2026-42579
- externalhttps://access.redhat.com/security/cve/CVE-2026-42581
- externalhttps://access.redhat.com/security/cve/CVE-2026-42583
- externalhttps://access.redhat.com/security/cve/CVE-2026-42584
- externalhttps://access.redhat.com/security/cve/CVE-2026-42587
- externalhttps://access.redhat.com/security/cve/CVE-2026-44249
- externalhttps://access.redhat.com/security/cve/CVE-2026-44486
- externalhttps://access.redhat.com/security/cve/CVE-2026-44487
- externalhttps://access.redhat.com/security/cve/CVE-2026-44488
- externalhttps://access.redhat.com/security/cve/CVE-2026-44492
- externalhttps://access.redhat.com/security/cve/CVE-2026-44494
- externalhttps://access.redhat.com/security/cve/CVE-2026-44495
- externalhttps://access.redhat.com/security/cve/CVE-2026-44496
- externalhttps://access.redhat.com/security/cve/CVE-2026-44774
- externalhttps://access.redhat.com/security/cve/CVE-2026-44893
- externalhttps://access.redhat.com/security/cve/CVE-2026-45292
- externalhttps://access.redhat.com/security/cve/CVE-2026-45736
- externalhttps://access.redhat.com/security/cve/CVE-2026-46595
- externalhttps://access.redhat.com/security/cve/CVE-2026-48043
- externalhttps://access.redhat.com/security/cve/CVE-2026-48059
- externalhttps://access.redhat.com/security/cve/CVE-2026-48779
- externalhttps://access.redhat.com/security/cve/CVE-2026-50559
- externalhttps://access.redhat.com/security/cve/CVE-2026-6734
- externalhttps://access.redhat.com/security/cve/CVE-2026-9697
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_36820.json