Red Hat Security Advisory: Migration Toolkit for Applications
🔗 CVE IDs covered (26)
📋 Description
CVE-2026-4926 — path-to-regexp: path-to-regexp: Denial of Service via crafted regular expressions CVE-2026-12143 — form-data: form-data: Form field override via CRLF injection CVE-2026-13149 — brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-26996 — minimatch: minimatch: Denial of Service via specially crafted glob patterns CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-27904 — minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-40895 — follow-redirects: follow-redirects: Information disclosure via cross-domain redirects CVE-2026-42039 — axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data CVE-2026-42041 — axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling CVE-2026-42044 — axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget CVE-2026-42264 — axios: Axios: Prototype pollution allows information disclosure and request manipulation CVE-2026-42342 — react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing CVE-2026-42504 — mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header CVE-2026-44486 — axios: Axios: Information disclosure of proxy credentials via HTTP redirects CVE-2026-44487 — axios: Axios: Information disclosure of proxy credentials via redirect flows CVE-2026-44488 — axios: Axios: Denial of Service due to unenforced request and response size limits CVE-2026-44492 — axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization CVE-2026-44494 — axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution CVE-2026-44495 — axios: Axios: Information disclosure due to prototype pollution vulnerability CVE-2026-44496 — axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name CVE-2026-55603 — http-proxy-middleware: http-proxy-middleware: Data integrity compromise via CR/LF injection
🎯 Affected products24
- Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-analyzer-addon-rhel9@sha256:e8a9614c7189c8ae2951ef3bd4b3a5dc548917333d5ccadf81bf9cf1bd182e85_amd64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-analyzer-addon-rhel9@sha256:f2c008735c1fd182a1ecbf7afab32a9d1ffd40a09186c31daa41f8053bba66bd_arm64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-cli-rhel9@sha256:5cf496005c3b5ff4c73f5adcb61f907362d82f47962b9c9a9c537b55b5ee0190_amd64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-cli-rhel9@sha256:d54304ee8d1e4ee8fd191a55eb585d2617fb434774ff0e4910e465addcc08e19_arm64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-discovery-addon-rhel9@sha256:8d2acae43f6b37761ba89fa6471c5e7dbcaae48f27d88e32f07c78dd929a7d6d_amd64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-discovery-addon-rhel9@sha256:dd974ca667e38caa223f6d503e67b157f660fce5a65911b27919b24dca1b1290_arm64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-dotnet-external-provider-rhel9@sha256:64fa6c4a8a927f755be0eaa973abd7753c1c28c0086bf94f95a983b23b6c35ce_amd64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-dotnet-external-provider-rhel9@sha256:8f37cc914c03019849362f8ac3ff201ac2e93f9b567450c4b243ed2abc4a71b1_arm64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-generic-external-provider-rhel9@sha256:dbea5a31d965cf3300144f3323ea30c9db33a05ab98cb343d5cdd9edb66f29f6_arm64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-generic-external-provider-rhel9@sha256:f698ef08c8a61dc55a53b9c7d449b4f7862f7cacd7acb62d51d232e722d546f7_amd64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-hub-rhel9@sha256:2115efc013299f9e2b9fec1adf1e44ca715cc260565b42537c4438d81c6a60bb_amd64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-hub-rhel9@sha256:34711e4f558a3df0f65ee127b4fa30e7573a5d306bc9e642a83112b91fea591a_arm64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-java-external-provider-rhel9@sha256:3c65b7377bc1a3430b6349dba1aecdd99787f20ad2c433a4d93585adc1c6674d_arm64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-java-external-provider-rhel9@sha256:7c567b6de60eaa093c853e19066a80c4010dbbbf4e32af0d1fb2997f9549e3ab_amd64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-operator-bundle@sha256:bbd09e16e3f05d51319bc5a9ebc623aa6a9fea1e9c5843b28ff9dce2ca1c2b40_amd64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-platform-addon-rhel9@sha256:55ac64ef75bc633eadccf4da25f33ddef134c557b706746408b4da0cfb768042_amd64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-platform-addon-rhel9@sha256:609847164532128273809aa9292e4f64f02354d77a065a00eddb4835766748c8_arm64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-rhel9-operator@sha256:439729fd40aab21c427a919a6852cc90e8eb2c0206f21657946d7e48d396e09f_amd64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-rhel9-operator@sha256:c5997585d3fe93881d80b9b32fd343ea81ef72e68b6eab676bf1312c1a6ee1d3_arm64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-solution-server-rhel9@sha256:52cfae6d1aedcc12935b696e00cd4c83c415d7dca6ad0c6289e92692a594aab0_amd64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-solution-server-rhel9@sha256:8a3113ec966da0b942695a61f6d381987049145e3670360061dd92427d095bec_arm64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-ui-rhel9@sha256:32b552436a7fe57fafdeb1c2383b3a98a91123e7c1f38511b8c47eb76a8b2b29_amd64 as a component of Red Hat Migration Toolkit for Applications 8.1
- registry.redhat.io/mta/mta-ui-rhel9@sha256:8e12baafaf77888b636adf49cb1f054746e5ab0a2de9ce42229403766389f6fd_arm64 as a component of Red Hat Migration Toolkit for Applications 8.1
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. Workaround: To mitigate this vulnerability, limit the use of multiple sequential optional groups in route patterns within applications that use `path-to-regexp`. Additionally, avoid directly passing user-controlled input as route patterns to prevent the generation of maliciously crafted regular expressions. Workaround: Applications using the `form-data` library should implement strict input validation and sanitization for all field names and filenames derived from untrusted sources. This prevents the injection of control characters (CR, LF, ") that could lead to header injection or form field overrides. Deployments that exclusively use fixed or trusted field names are not impacted. Workaround: There is no practical mitigation for this vulnerability. The brace-expansion package is typically a transitive dependency pulled in via minimatch and glob, making it difficult to isolate. Users should upgrade to a fixed version of brace-expansion when one becomes available. Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Upgrade to a patched version to fully mitigate the issues (ref: https://github.com/remix-run/react-router/security/advisories/GHSA-8x6r-g9mw-2r78). Workaround: To mitigate this issue, restrict network access to services that process MIME headers from untrusted sources. Implement input validation and sanitization for all incoming data, especially MIME headers, to prevent maliciously crafted content from being processed by applications utilizing the vulnerable Golang MIME package. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Restrict network access to affected proxy services. Do not pass untrusted user input into proxy target or header configuration. Upgrade http-proxy-middleware to 3.0.7 or 4.1.1 (or later) once updated packages are available for the affected components.
🔗 References (31)
- selfhttps://access.redhat.com/errata/RHSA-2026:50300
- externalhttps://access.redhat.com/security/cve/CVE-2026-12143
- externalhttps://access.redhat.com/security/cve/CVE-2026-13149
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-26996
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-27904
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-40895
- externalhttps://access.redhat.com/security/cve/CVE-2026-42039
- externalhttps://access.redhat.com/security/cve/CVE-2026-42041
- externalhttps://access.redhat.com/security/cve/CVE-2026-42044
- externalhttps://access.redhat.com/security/cve/CVE-2026-42264
- externalhttps://access.redhat.com/security/cve/CVE-2026-42342
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/cve/CVE-2026-42504
- externalhttps://access.redhat.com/security/cve/CVE-2026-44486
- externalhttps://access.redhat.com/security/cve/CVE-2026-44487
- externalhttps://access.redhat.com/security/cve/CVE-2026-44488
- externalhttps://access.redhat.com/security/cve/CVE-2026-44492
- externalhttps://access.redhat.com/security/cve/CVE-2026-44494
- externalhttps://access.redhat.com/security/cve/CVE-2026-44495
- externalhttps://access.redhat.com/security/cve/CVE-2026-44496
- externalhttps://access.redhat.com/security/cve/CVE-2026-4926
- externalhttps://access.redhat.com/security/cve/CVE-2026-55603
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://developers.redhat.com/products/mta/overview
- externalhttps://docs.redhat.com/en/documentation/migration_toolkit_for_applications/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_50300.json