Red Hat Security Advisory: Red Hat Developer Hub 1.9.9 release.
🔗 CVE IDs covered (30)
📋 Description
CVE-2026-19534 — undici: undici: Denial of Service via unrequested WebSocket subprotocol CVE-2026-33818 — encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal CVE-2026-54272 — ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification CVE-2026-55553 — urllib: urllib: Credential leakage via cross-origin redirects CVE-2026-56853 — net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service CVE-2026-56858 — html/template: golang: Go html/template: Cross-Site Scripting via pathological input CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-56860 — net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution CVE-2026-56862 — crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVE-2026-67214 — nanoid: nanoid: Denial of Service via negative size input in non-secure module functions CVE-2026-67312 — axios: axios: Denial of Service via uncontrolled recursion in form data processing CVE-2026-67422 — pymdown-extensions: Pymdown-extensions: Denial of Service via Regular Expression Vulnerability CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass CVE-2026-73086 — nanoid: nanoid: Predictable ID generation due to integer overflow CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-83605 — xmldom: @xmldom/xmldom: xmldom: Attribute injection allows client-side script execution CVE-2026-83607 — xmldom: xmldom: Cross-site scripting via unvalidated element name injection CVE-2026-83608 — xmldom: @xmldom/xmldom: xmldom: XML Markup Injection via DocType Name Bypass CVE-2026-83613 — xmldom: @xmldom/xmldom: xmldom: Denial of Service due to quadratic-time attribute processing CVE-2026-83614 — xmldom: @xmldom/xmldom: xmldom: Denial of Service via quadratic-time XML parsing CVE-2026-83615 — xmldom: @xmldom/xmldom: xmldom: Denial of Service via quadratic memory consumption CVE-2026-83616 — xmldom: xmldom: XML Structure Injection via Unvalidated Processing Instruction Targets CVE-2026-83619 — @xmldom/xmldom: xmldom: Denial of Service via crafted XML input CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies CVE-2026-84961 — undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options
🎯 Affected products4
- Red Hat Developer Hub 1.9
- registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:ea53db6012b6fe1c80760624caddb0d3b674614b62cb3c359ed3fde270314eb2_amd64 as a component of Red Hat Developer Hub 1.9
- registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:1b8153a28b5a3797104fd32a54e3ac38b3b573ff2d65d99bd257d650eddea1fc_amd64 as a component of Red Hat Developer Hub 1.9
- registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:036c292951ddf755006c6fefc9e1b8faf9a784757b91785e990bbfb856baa3ff_amd64 as a component of Red Hat Developer Hub 1.9
✅ Remediation
For more about Red Hat Developer Hub, see References links Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Sanitize all user-supplied integer inputs before passing them to `nanoid` or `customAlphabet` functions in the `nanoid/non-secure` module, ensuring the size parameter is strictly a non-negative integer. Workaround: Upgrade to axios >= 1.18.0 (1.x) or >= 0.33.0 (0.x), which add recursion depth guards to formDataToJSON. If an immediate upgrade is not possible, validate and limit the nesting depth of FormData field names before passing them to axios.formToJSON() or before sending FormData through axios with Content-Type: application/json, and ensure error handling is in place to catch RangeError exceptions from this code path. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams. Workaround: Sanitize or validate all untrusted element names before passing them to Document.createElement(), ensuring input strictly adheres to valid XML QName specifications prior to serialization. Workaround: Sanitize or validate all target strings passed to Document.createProcessingInstruction() to ensure compliance with XML Name production rules prior to serialization. Workaround: Applications that do not use BalancedPool, or that use it without a custom function-valued connect/tls option, are not affected and require no action. As a workaround until packages are updated, avoid using BalancedPool for any connection that relies on custom TLS certificate validation (e.g. certificate pinning); use Client, Pool, or Agent instead, which are unaffected. The permanent fix is upgrading undici to 7.29.1 or later (7.x line) or 8.10.2 or later (8.x line).
🔗 References (37)
- selfhttps://access.redhat.com/errata/RHSA-2026:69248
- externalhttps://access.redhat.com/security/cve/CVE-2026-19534
- externalhttps://access.redhat.com/security/cve/CVE-2026-33818
- externalhttps://access.redhat.com/security/cve/CVE-2026-54272
- externalhttps://access.redhat.com/security/cve/CVE-2026-55553
- externalhttps://access.redhat.com/security/cve/CVE-2026-56853
- externalhttps://access.redhat.com/security/cve/CVE-2026-56858
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-56860
- externalhttps://access.redhat.com/security/cve/CVE-2026-56862
- externalhttps://access.redhat.com/security/cve/CVE-2026-67214
- externalhttps://access.redhat.com/security/cve/CVE-2026-67312
- externalhttps://access.redhat.com/security/cve/CVE-2026-67422
- externalhttps://access.redhat.com/security/cve/CVE-2026-69152
- externalhttps://access.redhat.com/security/cve/CVE-2026-69192
- externalhttps://access.redhat.com/security/cve/CVE-2026-73086
- externalhttps://access.redhat.com/security/cve/CVE-2026-75899
- externalhttps://access.redhat.com/security/cve/CVE-2026-75931
- externalhttps://access.redhat.com/security/cve/CVE-2026-75975
- externalhttps://access.redhat.com/security/cve/CVE-2026-76172
- externalhttps://access.redhat.com/security/cve/CVE-2026-83605
- externalhttps://access.redhat.com/security/cve/CVE-2026-83607
- externalhttps://access.redhat.com/security/cve/CVE-2026-83608
- externalhttps://access.redhat.com/security/cve/CVE-2026-83613
- externalhttps://access.redhat.com/security/cve/CVE-2026-83614
- externalhttps://access.redhat.com/security/cve/CVE-2026-83615
- externalhttps://access.redhat.com/security/cve/CVE-2026-83616
- externalhttps://access.redhat.com/security/cve/CVE-2026-83619
- externalhttps://access.redhat.com/security/cve/CVE-2026-84292
- externalhttps://access.redhat.com/security/cve/CVE-2026-84394
- externalhttps://access.redhat.com/security/cve/CVE-2026-84961
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://catalog.redhat.com/search?gs&searchType=containers&q=rhdh
- externalhttps://developers.redhat.com/rhdh/overview
- externalhttps://docs.redhat.com/en/documentation/red_hat_developer_hub
- externalhttps://issues.redhat.com/browse/RHDHBUGS-3741
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_69248.json