RHSA-2026:72712HighCVSS 8.5

Red Hat Security Advisory: Ansible plug-ins for Red Hat Developer Hub Product Release Update

Published
September 28, 2026
Last Modified
October 4, 2026

🔗 CVE IDs covered (16)

📋 Description

CVE-2026-5038 — multer: Multer: Denial of Service via aborted or malformed multipart uploads CVE-2026-19534 — undici: undici: Denial of Service via unrequested WebSocket subprotocol CVE-2026-47683 — vm2: vm2: Denial of Service due to memory allocation limit bypass CVE-2026-55553 — urllib: urllib: Credential leakage via cross-origin redirects CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-59879 — immutable-js: Immutable.js: Denial of Service due to mishandling of large index values in List operations CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing CVE-2026-87776 — compression: compression: Denial of Service via memory leak on premature response close CVE-2026-88932 — multer: multer: Denial of Service via orphaned disk writes on aborted uploads CVE-2026-89011 — isomorphic-git: isomorphic-git: Information disclosure via prototype pollution in getRemoteInfo function. CVE-2026-92000 — adm-zip: adm-zip: Denial of Service via crafted ZIP archives with zero declared uncompressed size CVE-2026-92942 — vm2: vm2: Denial of Service via timeout bypass in sandboxed code CVE-2026-92958 — vm2: vm2: Sandbox escape via denylist bypass in NodeVM CVE-2026-92959 — vm2: vm2: Asynchronous code execution bypass via Promise thenable assimilation CVE-2026-92961 — vm2: vm2: Denial of Service via memory exhaustion

🎯 Affected products2

  • Red Hat Ansible Automation Platform 2.1
  • registry.redhat.io/ansible-automation-platform/automation-portal@sha256:2659ae04974d930322789112efc9181bc7cf3990999a204eba45aec0639f0c3d_amd64 as a component of Red Hat Ansible Automation Platform 2.1

✅ Remediation

For more about Ansible plugins for Red Hat Developer Hub, see References links Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: To mitigate this issue, applications should implement input validation to reject or clamp any externally supplied List index or key-path segment that exceeds a sane maximum, specifically values greater than or equal to 2^30. Additionally, running request handling in isolated worker processes with capped heap sizes (e.g., using `--max-old-space-size`) can contain the impact of a potential process abort. Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stringify. Where qs.parse is used directly, set allowPrototypes: false unless prototype keys are required. For Express applications, review whether the default query parser configuration is necessary. Wrapping qs.stringify calls in try/catch can limit impact to individual requests. Workaround: Update the compression middleware to version 1.8.2 or later. No supported workaround is currently available if the affected version cannot be updated. Workaround: Until updates are available, administrators can implement the following mitigations to reduce the risk of disk exhaustion: 1. Monitor disk usage on systems running Red Hat Developer Hub or Ansible Portal and set up alerts for unusual disk consumption patterns. 2. Implement rate limiting on file upload endpoints to restrict the number of upload requests from a single IP address or user account within a given time period. 3. If authentication is not strictly required for file upload endpoints, enable authentication to reduce the attack surface to authenticated users only. 4. Periodically clean up orphaned temporary files in multer's storage directory. The default upload directory is typically in the system temp folder or a configured uploads directory. 5. Set disk quota limits for the user account or partition used by the application to prevent complete disk exhaustion from affecting the entire system. For production environments, apply updates as they become available from Red Hat product teams.

🔗 References (20)