RHSA-2026:41929HighCVSS 7.5

Red Hat Security Advisory: Red Hat Developer Hub 1.9.7 release.

Published
July 20, 2026
Last Modified
July 22, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2026-6734 — undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing CVE-2026-9697 — undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-12151 — undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames CVE-2026-13676 — fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-44902 — opentelemetry-js: opentelemetry/exporter-prometheus: opentelemetry-js: Denial of Service via malformed HTTP request CVE-2026-45740 — protobufjs: protobufjs: Denial of Service via crafted JSON descriptors

🔗 References (14)