RHSA-2026:67724HighCVSS 7.5

Red Hat Security Advisory: Migration Toolkit for Applications

Published
September 16, 2026
Last Modified
October 1, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-73569 — fast-xml-parser: fast-xml-parser: Denial of Service via repeated DOCTYPE declarations CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing

🎯 Affected products28

  • Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-analyzer-addon-rhel9@sha256:02616be21a5fab7760e69dd3ed58dee4341442d13e5eec157d2dccee490d1bcb_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-analyzer-addon-rhel9@sha256:fc437c8e16062da0690c2515171e1cd7d6f906dd827d7a3d482e3429fdf14e05_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-cli-rhel9@sha256:c283ed95e4fb75820bcfe296b6e746df7dc2f5b3cc74aabe0ab0460c31e88f2d_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-cli-rhel9@sha256:eb56e1d81af9a72f11976db564057a1be47394676e807ad583e61feaaf4207be_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-discovery-addon-rhel9@sha256:52ab72052c3dc50051c7bca50adf7306df84064ac7bbe08d9e75f96cc4b068f9_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-discovery-addon-rhel9@sha256:6143bd7238c6af113e16558f13d57fb5006a081548598438d6c40c55589110a3_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-dotnet-external-provider-rhel9@sha256:4665c73a39ee8c778e15946f7db6d602e2d38fa108f36b82f041ca8113f4239f_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-dotnet-external-provider-rhel9@sha256:dfbbd32389ec60a7fc26f31e2e5aa8b89c6ee430d00856613ca7103c4dff3828_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-go-external-provider-rhel9@sha256:7250ec83be6cace1bd59745591df6ddc02ea35421384de804ba32bd51e7b50c1_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-go-external-provider-rhel9@sha256:d6133e30119f504c5dd33ef1c30b7764143264aca5487267594bc64f3342e583_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-hub-rhel9@sha256:4a8a09eaff889e43baa6a58b35c215c3902490e5278caa25f4dab43cdf8afea6_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-hub-rhel9@sha256:518d2bf5e0c164dd47e84935cf21904ac40a099244aaeaaa0d3f7df697d1d2c9_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-java-external-provider-rhel9@sha256:000a593acaebb6ddd6c9241ba8a77f44bf2ae3f20f07d9f59dc40cddb5312b30_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-java-external-provider-rhel9@sha256:ce31e0aed326c61ba101514eeeb39c5b9fcf0526f0c8bb70c84ec5f5e49fc270_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-nodejs-external-provider-rhel9@sha256:50660cc42a2e7596416c8e60f5050bc06c49025052393c695bd439aa2ceb49cc_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-nodejs-external-provider-rhel9@sha256:e063a943d8401045cf46c5f82526b18831bd020a4d8613587a9809f9ce744b21_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-operator-bundle@sha256:6860e281fa01eedc297a0b5e043fea2b7ad3641278b31520043bb5014e751d76_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-platform-addon-rhel9@sha256:7bcb07d008c6a4bf727509eaecf389d9168b23709c236988d92c8a2fcbbc5776_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-platform-addon-rhel9@sha256:d3a1412fd3be34d76cb420cf28ebd5faea18899837b1e2d405fcff3843d50cfd_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-python-external-provider-rhel9@sha256:54054627942e35913975fe7ae8776d5cd52bb56bc86f138fd599445793fd730a_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-python-external-provider-rhel9@sha256:b5afd3be03bb09a2d649e1e2bb5a07119b3f596843f1be2ed3f6ee6aee7c87a2_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-rhel9-operator@sha256:3da387379212bfac0c0bc18c0bd48a27294cbb8f2113a65c87a3c24b23c42673_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-rhel9-operator@sha256:8340507434da15423d9405236d3574902d29e687aa4011705c7ff8fd95ce8881_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-solution-server-rhel9@sha256:2f07290da5319e71cc2ac01a17398d9619e88a8fd7de4b65310cdcbe4b29f312_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-solution-server-rhel9@sha256:cff08d56550c3d272072ff72f1bac9f1f05065e4eb9810ebf9e0c6696bc544a9_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-ui-rhel9@sha256:6cfe1a3cb3be7857afb7c6c469d5f2ef3e6c39439896ea370fc6a7ecbb1541ff_amd64 as a component of Red Hat Migration Toolkit for Applications 8.2
  • registry.redhat.io/mta/mta-ui-rhel9@sha256:e7bd712ae076820497e4f862165048d2d906de11db9baef1d3e293a3ecb5408b_arm64 as a component of Red Hat Migration Toolkit for Applications 8.2

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stringify. Where qs.parse is used directly, set allowPrototypes: false unless prototype keys are required. For Express applications, review whether the default query parser configuration is necessary. Wrapping qs.stringify calls in try/catch can limit impact to individual requests.

🔗 References (9)