Red Hat Security Advisory: Ansible plug-ins for Red Hat Developer Hub Product Release Update
🔗 CVE IDs covered (16)
📋 Description
CVE-2026-5079 — multer: Multer: Denial of Service via deeply nested field names in multipart form data
CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation
CVE-2026-67214 — nanoid: nanoid: Denial of Service via negative size input in non-secure module functions
CVE-2026-67313 — axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON
CVE-2026-67314 — axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth
CVE-2026-67320 — axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter
CVE-2026-67321 — axios: axios: Denial of Service via object serialization bypass
CVE-2026-73563 — @backstage/plugin-auth-backend: Backstage: Unauthenticated OAuth account takeover via redirect_uri allowlist bypass
CVE-2026-73566 — tar: node-tar: Denial of Service via crafted long-path tar archive
CVE-2026-75838 — dompurify: DOMPurify: Cross-Site Scripting via IN_PLACE sanitization
CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding
CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization
CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization
CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects
CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization
CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies
🎯 Affected products2
- Red Hat Ansible Automation Platform 2.1
- registry.redhat.io/ansible-automation-platform/automation-portal@sha256:7145c54b94927bc64e9def7a47cb43b7706ee21d41f8dd97a08ea8ff1fcad65e_amd64 as a component of Red Hat Ansible Automation Platform 2.1
✅ Remediation
For more about Ansible plugins for Red Hat Developer Hub, see References links Workaround: To reduce the impact of this denial of service vulnerability, configure the `limits.fields` option within your `multer` instance to a reasonable maximum value. This action restricts the number of fields processed from multipart form data, thereby limiting the resources an attacker can consume. This partial mitigation requires an application restart to take effect and does not fully prevent the vulnerability. Workaround: To mitigate this issue, ensure application code validates the size parameter passed to customAlphabet or customRandom, rejecting or sanitizing zero-value inputs before passing them to nanoid. Workaround: Sanitize all user-supplied integer inputs before passing them to `nanoid` or `customAlphabet` functions in the `nanoid/non-secure` module, ensuring the size parameter is strictly a non-negative integer. Workaround: Do not enable the experimental dynamic client registration or client ID metadata document features. If these features are currently enabled, review and restrict the allowedRedirectUriPatterns and allowedClientIdPatterns configurations to use fully qualified hostnames with explicit protocols rather than wildcard or protocol-less patterns. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2026:65118
- externalhttps://access.redhat.com/security/cve/CVE-2026-5079
- externalhttps://access.redhat.com/security/cve/CVE-2026-67213
- externalhttps://access.redhat.com/security/cve/CVE-2026-67214
- externalhttps://access.redhat.com/security/cve/CVE-2026-67313
- externalhttps://access.redhat.com/security/cve/CVE-2026-67314
- externalhttps://access.redhat.com/security/cve/CVE-2026-67320
- externalhttps://access.redhat.com/security/cve/CVE-2026-67321
- externalhttps://access.redhat.com/security/cve/CVE-2026-73563
- externalhttps://access.redhat.com/security/cve/CVE-2026-73566
- externalhttps://access.redhat.com/security/cve/CVE-2026-75838
- externalhttps://access.redhat.com/security/cve/CVE-2026-75899
- externalhttps://access.redhat.com/security/cve/CVE-2026-75931
- externalhttps://access.redhat.com/security/cve/CVE-2026-75975
- externalhttps://access.redhat.com/security/cve/CVE-2026-76172
- externalhttps://access.redhat.com/security/cve/CVE-2026-84292
- externalhttps://access.redhat.com/security/cve/CVE-2026-84394
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_65118.json