Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage
🔗 CVE IDs covered (8)
📋 Description
CVE-2026-9375 — urllib3: urllib3: Denial of Service via decompression bomb bypass with Brotli support CVE-2026-59879 — immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations CVE-2026-71491 — sqlparse: sqlparse: Denial of Service via quadratic CPU consumption in comment grouping CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies CVE-2026-87776 — compression: compression: Denial of Service via memory leak on premature response close
🎯 Affected products5
- Red Hat Discovery 2
- registry.redhat.io/discovery/discovery-server-rhel9@sha256:7504b5b4e7a6efc09b4867c4e3ae29338fd758acf4e7e0fb7aec2d2979d8df93_arm64 as a component of Red Hat Discovery 2
- registry.redhat.io/discovery/discovery-server-rhel9@sha256:d8ddf4f17643611e504a71519be81ceb79e61f41632be3f327f4fbe2a1e5e198_amd64 as a component of Red Hat Discovery 2
- registry.redhat.io/discovery/discovery-ui-rhel9@sha256:7f9f86aa64673b84d7982c03fe7e70627ed8c4f1dbefe59110eb13f4af0573c0_arm64 as a component of Red Hat Discovery 2
- registry.redhat.io/discovery/discovery-ui-rhel9@sha256:b2491e82a198efc1ceccd9eb383dbebbb1e4251a9bf4628471b099a5a037cfaf_amd64 as a component of Red Hat Discovery 2
✅ Remediation
The containers required to run Discovery can be installed through discovery-installer RPM. See the official documentation for more details. Workaround: To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort. Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stringify. Where qs.parse is used directly, set allowPrototypes: false unless prototype keys are required. For Express applications, review whether the default query parser configuration is necessary. Wrapping qs.stringify calls in try/catch can limit impact to individual requests. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Update the compression middleware to version 1.8.2 or later. No supported workaround is currently available if the affected version cannot be updated.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:69289
- externalhttps://access.redhat.com/security/cve/CVE-2026-59879
- externalhttps://access.redhat.com/security/cve/CVE-2026-71491
- externalhttps://access.redhat.com/security/cve/CVE-2026-82417
- externalhttps://access.redhat.com/security/cve/CVE-2026-84292
- externalhttps://access.redhat.com/security/cve/CVE-2026-84375
- externalhttps://access.redhat.com/security/cve/CVE-2026-84394
- externalhttps://access.redhat.com/security/cve/CVE-2026-87776
- externalhttps://access.redhat.com/security/cve/CVE-2026-9375
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/subscription_central/1-latest/#Discovery
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_69289.json