Red Hat Security Advisory: Red Hat Developer Hub 1.8.5 release.
🔗 CVE IDs covered (12)
📋 Description
CVE-2025-61140 — jsonpath: jsonpath: Prototype Pollution vulnerability in the value function CVE-2026-2359 — multer: Multer: Denial of Service via dropped file upload connections CVE-2026-3304 — multer: Multer: Denial of Service via malformed requests CVE-2026-3520 — multer: Multer: Denial of Service via malformed requests CVE-2026-24046 — backstage/backend-defaults: backstage/plugin-scaffolder-backend: backstage/plugin-scaffolder-node: possible symlink path traversal in scaffolder actions CVE-2026-25153 — @backstage/plugin-techdocs-node: @backstage/plugin-techdocs-node vulnerable to arbitrary code execution via MkDocs hooks CVE-2026-25639 — axios: Axios affected by Denial of Service via proto Key in mergeConfig CVE-2026-25896 — fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling CVE-2026-26278 — fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion CVE-2026-27606 — rollup: Rollup: Remote Code Execution via Path Traversal Vulnerability CVE-2026-27942 — fast-xml-parser: fast-xml-parser: Stack overflow leads to Denial of Service CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
🎯 Affected products4
- Red Hat Developer Hub 1.8
- registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:2e8ed97c6e6d232f66bb81dc074b8bb2712dc54004cc565fcb1d2b43a9bb2046_amd64 as a component of Red Hat Developer Hub 1.8
- registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:400d642f10348a0728a624b135228714b3302f1cabc096150a340407133c54e7_amd64 as a component of Red Hat Developer Hub 1.8
- registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:72d72d0e8b67012bfaaeae0e1fbbcf8e35c74d4d6252051eabef3e9dd979d48e_amd64 as a component of Red Hat Developer Hub 1.8
✅ Remediation
For more about Red Hat Developer Hub, see References links Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, consider implementing strict access controls for Backstage Scaffolder templates. Restrict the ability to create and execute Scaffolder templates to trusted users only, utilizing the Backstage permissions framework. Additionally, audit existing templates for any symlink usage and consider running Backstage within a containerized environment with a highly restricted filesystem to limit potential impact. Workaround: To mitigate this vulnerability, configure applications using the `fast-xml-parser` XML builder to set the `preserveOrder` option to `false`. Alternatively, ensure that all XML input data is thoroughly validated before being passed to the builder to prevent the processing of malicious or malformed content. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.
🔗 References (30)
- selfhttps://access.redhat.com/errata/RHSA-2026:6174
- externalhttps://access.redhat.com/security/cve/CVE-2025-61140
- externalhttps://access.redhat.com/security/cve/CVE-2026-2359
- externalhttps://access.redhat.com/security/cve/CVE-2026-24046
- externalhttps://access.redhat.com/security/cve/CVE-2026-25153
- externalhttps://access.redhat.com/security/cve/CVE-2026-25639
- externalhttps://access.redhat.com/security/cve/CVE-2026-25896
- externalhttps://access.redhat.com/security/cve/CVE-2026-26278
- externalhttps://access.redhat.com/security/cve/CVE-2026-27606
- externalhttps://access.redhat.com/security/cve/CVE-2026-27942
- externalhttps://access.redhat.com/security/cve/CVE-2026-3304
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/cve/CVE-2026-3520
- externalhttps://issues.redhat.com/browse/RHIDP-11518
- externalhttps://issues.redhat.com/browse/RHIDP-11639
- externalhttps://issues.redhat.com/browse/RHIDP-11731
- externalhttps://issues.redhat.com/browse/RHIDP-12139
- externalhttps://issues.redhat.com/browse/RHIDP-12323
- externalhttps://issues.redhat.com/browse/RHIDP-12335
- externalhttps://issues.redhat.com/browse/RHIDP-12392
- externalhttps://issues.redhat.com/browse/RHIDP-12417
- externalhttps://issues.redhat.com/browse/RHIDP-12444
- externalhttps://issues.redhat.com/browse/RHIDP-12447
- externalhttps://issues.redhat.com/browse/RHIDP-12480
- externalhttps://issues.redhat.com/browse/RHIDP-12904
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/search?gs&searchType=containers&q=rhdh
- externalhttps://developers.redhat.com/rhdh/overview
- externalhttps://docs.redhat.com/en/documentation/red_hat_developer_hub
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_6174.json