RHSA-2026:68754HighCVSS 8.6

Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.30.1 Release.

Published
September 17, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (37)

📋 Description

CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-45623 — postcss: PostCSS: Information disclosure and denial of service via crafted CSS input CVE-2026-45819 — baseline-browser-mapping: baseline-browser-mapping: Denial of Service via improper input handling CVE-2026-47219 — find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server CVE-2026-48801 — linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability CVE-2026-54272 — ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification CVE-2026-55831 — io.netty/netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing CVE-2026-55833 — netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification CVE-2026-56745 — netty: io.netty/netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec CVE-2026-56746 — io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header CVE-2026-56819 — io.netty/netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak CVE-2026-59887 — linkify-it: linkify-it: Denial of Service via crafted mailto: links CVE-2026-59899 — io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation CVE-2026-67312 — axios: axios: Denial of Service via uncontrolled recursion in form data processing CVE-2026-67313 — axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON CVE-2026-67314 — axios: axios: Outbound Request Tampering via Prototype Pollution in Basic Auth CVE-2026-67320 — axios: axios: Information disclosure via Prototype Pollution in Node HTTP adapter CVE-2026-67321 — axios: axios: Denial of Service via object serialization bypass CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-69153 — postcss: PostCSS: Information disclosure via crafted sourceMappingURL CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass CVE-2026-71436 — mermaid: Mermaid XY Charts: Denial of Service via invalid X-Axis parameters CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-73088 — browserslist: Browserslist: Prototype pollution leading to denial of service CVE-2026-73089 — browserslist: Browserslist: Denial of Service via unbounded memory growth from distinct query results CVE-2026-73508 — io.netty/netty-codec-dns: Netty: Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names CVE-2026-73566 — tar: node-tar: Denial of Service via crafted long-path tar archive CVE-2026-73646 — postcss: PostCSS: Information disclosure via path traversal in source map auto-loading CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-82562 — qs: qs: Denial of Service via array limit bypass in query string parsing CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies

🎯 Affected products58

  • Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/code-rhel9@sha256:02f759255a2259ae4c7e41a980dcecc9a72efcfb050dcdbeba4469d62eb352db_s390x as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/code-rhel9@sha256:23f78b2564f05173a9d5beb28d85369c6d2c095b479d4d11f3a8f1aae0844f04_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/code-rhel9@sha256:7cb88955f069bb340c95f2b1e8db96578446d3781ade3acf4540288f933b3dc5_amd64 as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/code-rhel9@sha256:a408da5c9d9e5c3e9ea1ed10eda3a539707972da9aafd3aa62f587f3f36f607a_arm64 as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/code-sshd-rhel9@sha256:0b64e3bc6d16813432a246d87828ea80008fb9dfca0f00f67ba745761c6cd284_amd64 as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/code-sshd-rhel9@sha256:292821c33dbe335565d7326628427f116aef46beb19e859f1a430eb55bc908a6_s390x as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/code-sshd-rhel9@sha256:72f9aefc6cffaadc656bf4cebb6111bb719a97c519b6a613908d16f90d355ce2_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/code-sshd-rhel9@sha256:e8c47fe983e7921de3ab242bbfee585906f2e067e1d1be7b053919dee6316fd4_arm64 as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/configbump-rhel9@sha256:1aaac61759582265fc311a741e3153e65da8d5295df154090aecbd6a6990cced_s390x as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/configbump-rhel9@sha256:4eff0c4dc7b65e4192c4cd007b33c2d1266a9c16d407dfb05bccac2c134519f8_arm64 as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/configbump-rhel9@sha256:89945e1e7002f32baf24f667253d21c1afdc5d26831d820f544247ee7ba539d9_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/configbump-rhel9@sha256:ed9b4c7ab59b471037aff0f7ed28a7034c106afdc8499e9f93095a811afa9f26_amd64 as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/dashboard-rhel9@sha256:167f8fd2b88dc37abed12b6496ac32b5b031de3be233f2864afb918c8b692a1a_arm64 as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/dashboard-rhel9@sha256:6494cd526ac465b432f090ed4c8a4b82ef8d115e2b518d3d29d9a67f842d3e8a_amd64 as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/dashboard-rhel9@sha256:66086271381e4fd5f6f156458ef6ddcb15e3ba6d0379530768b11e6ea6b8ae11_s390x as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/dashboard-rhel9@sha256:6722afd90301e2367b5d360337321856a03b9b7427a91ac4d487fc7c235ec992_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:0305cb4f3441510811f3db3fa33097e189aeccfc2256f240c4090862cf834ca5_amd64 as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:4775c3a67b5e7676f9aa46327f07008237ea6e7406e345e3edd402472a02c0a1_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:76ba6ca0573a535cf4699ce293ba9e00b9d960a8f8f9b6aaa81d367ad60e12ab_arm64 as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:b854bd6a5c32c302c1af5290fb437287d3793c747c399b202b0529b1dd51be7f_amd64 as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:cede94c3433ba897c9567d804301f3165779e84d25d61d009076a8679002701b_s390x as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/imagepuller-rhel9@sha256:320393728ff1da09a0adda2d3c85a3314d82eea3c948274b1d111e59ebc0e3a3_arm64 as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/imagepuller-rhel9@sha256:671f83e4669d4a79335a4177c0417ef3efa156b79642cc5850775a7af3fd536c_amd64 as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/imagepuller-rhel9@sha256:d9cab0bbd23f837a9a478f56629556bc6487666b79e241963fa6a616523ebd46_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/imagepuller-rhel9@sha256:ddd590ba06d1a2bdae507a463c0022b07e83ff552b0f86cf3ebc78bbfd32b7fe_s390x as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:1112fdd0f88e9f42de6dd99366c252c842590f1a8a1c32715e6e5d80b311c6f2_amd64 as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:2b95aea3e7e825f9d48b8a8b3bbe0cdb7f51ac9c8e402b549f32a89c0a85ebb8_s390x as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:86c118bddda6b8eadb539646af304988c99d0ea5cdc41201993e9c9bb5296a3e_arm64 as a component of Red Hat OpenShift Dev Spaces 3.30
  • registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:b32817187c9b0319c5377a520c0e3287328b5a6fe74e328f59b00500ea5a70fd_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.30
  • +28 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: There is no available mitigation for this flaw other than updating the bundled find-my-way library to a fixed version (9.7.0 or later). Where feasible, restricting the affected service to HTTP/1.1 (disabling HTTP/2) removes the attack vector, since the flaw is only reachable through the HTTP/2 request path. Workaround: If CORS short-circuit functionality is not required, disable the shortCircuit() configuration in the CorsHandler. Alternatively, implement application-level origin validation to reject requests with null Origin headers. A web application firewall (WAF) can also be configured to block requests with null or missing Origin headers. Workaround: To mitigate this issue, ensure application code validates the size parameter passed to customAlphabet or customRandom, rejecting or sanitizing zero-value inputs before passing them to nanoid. Workaround: Upgrade to axios >= 1.18.0 (1.x) or >= 0.33.0 (0.x), which add recursion depth guards to formDataToJSON. If an immediate upgrade is not possible, validate and limit the nesting depth of FormData field names before passing them to axios.formToJSON() or before sending FormData through axios with Content-Type: application/json, and ensure error handling is in place to catch RangeError exceptions from this code path. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: Pass map: false when invoking PostCSS to disable source map auto-loading. This prevents the path traversal from being triggered, though it removes source map support entirely. Workaround: Avoid rendering or previewing untrusted Mermaid diagram content containing XY chart definitions with attacker-controlled X-Axis parameters in the affected workbench images until the pinned mermaid dependency is upgraded to 10.9.8+/11.16.1+. Workaround: To reduce exposure, ensure that the `browserslist` tool processes only trusted `browserslist-stats.json`, `opts.stats`, and CLI `--stats` data. Avoid using the tool with untrusted input sources in development or build environments. If `browserslist` is integrated into automated pipelines, validate all input data originates from trusted sources. Workaround: Red Hat recommends upgrading to a fixed version as the primary remediation. Where an immediate upgrade is not possible, restrict network access so that only trusted DNS servers and trusted network peers can send DNS traffic to the affected application, using firewall or network policy rules to block or rate-limit DNS traffic from untrusted sources. This reduces exposure to the malformed DNS records that trigger the issue but does not fully eliminate it; upgrading remains the only complete fix. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams. Workaround: Until an updated qs dependency is available in your Red Hat product, limit exposure as follows: 1. If your application calls qs.parse() directly, avoid enabling both comma:true and throwOnLimitExceeded:true when parsing untrusted query strings or urlencoded request bodies. Disable one of these non-default options, or upgrade qs to version 6.16.0 or later. 2. Where qs is included only as a transitive dependency, apply product updates that ship qs 6.16.0 or later when they become available. 3. Enforce HTTP request-line and request-body size limits at your ingress or application server. Because allocated memory scales with attacker-supplied input size, transport-layer limits bound worst-case impact. Host operating systems are not directly affected. These steps apply to application processes that use qs with the vulnerable configuration.

🔗 References (41)