Red Hat Security Advisory: Ansible plug-ins for Red Hat Developer Hub Product Release Update
🔗 CVE IDs covered (15)
📋 Description
CVE-2026-19534 — undici: undici: Denial of Service via unrequested WebSocket subprotocol CVE-2026-47683 — vm2: vm2: Denial of Service due to memory allocation limit bypass CVE-2026-55553 — urllib: urllib: Credential leakage via cross-origin redirects CVE-2026-56859 — encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue CVE-2026-59869 — js-yaml: js-yaml: Denial of Service via crafted YAML documents CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing CVE-2026-87776 — compression: compression: Denial of Service via memory leak on premature response close CVE-2026-88932 — multer: multer: Denial of Service via orphaned disk writes on aborted uploads CVE-2026-89011 — isomorphic-git: isomorphic-git: Information disclosure via prototype pollution in getRemoteInfo function. CVE-2026-92000 — adm-zip: adm-zip: Denial of Service via crafted ZIP archives with zero declared uncompressed size CVE-2026-92942 — vm2: vm2: Denial of Service via timeout bypass in sandboxed code CVE-2026-92958 — vm2: vm2: Sandbox escape via denylist bypass in NodeVM CVE-2026-92959 — vm2: vm2: Asynchronous code execution bypass via Promise thenable assimilation CVE-2026-92961 — vm2: vm2: Denial of Service via memory exhaustion
🎯 Affected products2
- Red Hat Ansible Automation Platform 2.2
- registry.redhat.io/ansible-automation-platform/automation-portal@sha256:ca5c8160a6cb0fa122c3cc91852325af72b9713db1c2683b68e91433b762e604_amd64 as a component of Red Hat Ansible Automation Platform 2.2
✅ Remediation
For more about Ansible plugins for Red Hat Developer Hub, see References links Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, restrict the processing of untrusted YAML documents by applications that rely on `js-yaml`. Implement robust input validation and sanitization for all YAML data originating from external or untrusted sources. Consider limiting network access to services that parse YAML content to trusted networks or clients through appropriate firewall configurations. Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stringify. Where qs.parse is used directly, set allowPrototypes: false unless prototype keys are required. For Express applications, review whether the default query parser configuration is necessary. Wrapping qs.stringify calls in try/catch can limit impact to individual requests. Workaround: Update the compression middleware to version 1.8.2 or later. No supported workaround is currently available if the affected version cannot be updated. Workaround: Until updates are available, administrators can implement the following mitigations to reduce the risk of disk exhaustion: 1. Monitor disk usage on systems running Red Hat Developer Hub or Ansible Portal and set up alerts for unusual disk consumption patterns. 2. Implement rate limiting on file upload endpoints to restrict the number of upload requests from a single IP address or user account within a given time period. 3. If authentication is not strictly required for file upload endpoints, enable authentication to reduce the attack surface to authenticated users only. 4. Periodically clean up orphaned temporary files in multer's storage directory. The default upload directory is typically in the system temp folder or a configured uploads directory. 5. Set disk quota limits for the user account or partition used by the application to prevent complete disk exhaustion from affecting the entire system. For production environments, apply updates as they become available from Red Hat product teams.
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2026:72722
- externalhttps://access.redhat.com/security/cve/CVE-2026-19534
- externalhttps://access.redhat.com/security/cve/CVE-2026-47683
- externalhttps://access.redhat.com/security/cve/CVE-2026-55553
- externalhttps://access.redhat.com/security/cve/CVE-2026-56859
- externalhttps://access.redhat.com/security/cve/CVE-2026-59869
- externalhttps://access.redhat.com/security/cve/CVE-2026-82417
- externalhttps://access.redhat.com/security/cve/CVE-2026-84375
- externalhttps://access.redhat.com/security/cve/CVE-2026-87776
- externalhttps://access.redhat.com/security/cve/CVE-2026-88932
- externalhttps://access.redhat.com/security/cve/CVE-2026-89011
- externalhttps://access.redhat.com/security/cve/CVE-2026-92000
- externalhttps://access.redhat.com/security/cve/CVE-2026-92942
- externalhttps://access.redhat.com/security/cve/CVE-2026-92958
- externalhttps://access.redhat.com/security/cve/CVE-2026-92959
- externalhttps://access.redhat.com/security/cve/CVE-2026-92961
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_72722.json