Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.30.1 Release.
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-8458 — curl: libcurl: Unauthorized connection reuse due to a logical error CVE-2026-8927 — curl: Information disclosure due to uncleared proxy authentication state
🎯 Affected products62
- Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/code-rhel9@sha256:2a80ac1e2c7f68dd5b726d49b5a660959de0036d992356bb742eb08349563dec_amd64 as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/code-rhel9@sha256:2ccbb4d94995be8cf2fee5a48d0c3af5a03abbf0a97413566efa5d4d8cdc0215_s390x as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/code-rhel9@sha256:ac63e3735a58616d9418c62ee65a41f57c9394bb6d48f82dfd11156481191b2a_arm64 as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/code-rhel9@sha256:dd4e4609585bccc42a04c2102845fafc7dd441e4a33259eb3a4ad529ca4bacda_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/code-sshd-rhel9@sha256:1108237eb82d57790761491c65714fbf2c82cbf348d1356293c9fde1a122ccc8_arm64 as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/code-sshd-rhel9@sha256:3505aed52622263559f32a6ff77bbe318b7156a3e98a8efe7369ec2164cebe49_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/code-sshd-rhel9@sha256:8ed534503ea591d237a07150a4ccb48486029b43d29173923943acbbae0f5264_s390x as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/code-sshd-rhel9@sha256:ad05ad6689e93f66c5bbb3e75269a94affd24784b4f45873b14a2db57c45e170_amd64 as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/configbump-rhel9@sha256:1259b70438c94fa7873f908a70cce76d5aab7f0f01faeac8740f450a5c34a21a_amd64 as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/configbump-rhel9@sha256:2672e62cafdddf27936af2995006ccf54f37383cfecd5f0bcf545e27600de98a_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/configbump-rhel9@sha256:ce1d97a305f8a581fe973d7319741d35af48dc51b9630b2c1b25a56dcbdc8818_s390x as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/configbump-rhel9@sha256:d9f06407cfa966d80cd71788b1ca66574bf6f86166a36195f3c1304ea9281b41_arm64 as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/dashboard-rhel9@sha256:38ee8b9c7ea754623d0c857d5c47aa9ffe93e6375ecfbbfcf1176ea994c842c6_arm64 as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/dashboard-rhel9@sha256:6b9d8089f76b0ba4008847692f2713a33949ef4774af43730d08b4b954dc317b_s390x as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/dashboard-rhel9@sha256:765eb2ca9f2133bbd67334196785b12673c91929fb2d43c6ff4b37850a7f2d9e_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/dashboard-rhel9@sha256:bb5346516525fe025ae9cbf1fd3f227fb1cad71ae73ad58264a7e5ffb2931eb3_amd64 as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:b7b68b6c7bc7313accf6767121d4c981241046496307c18b585059e2baedfdb3_amd64 as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:24c7fef8cec6287f9f3b470cd24f8254d2a4e0ffe06aab10590882c8fd610371_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:35c1f9816bddffaf93832ba357942128eb00f78aa524524eb33f74b331714a9c_amd64 as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:656bea74eb40dca9b5289ad514d0ce248de6e033f6b3828b34419992b1e14649_s390x as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:f4786690daf4056f59b79a6416e30a898915ac49865fda266818666abc4453d8_arm64 as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/imagepuller-rhel9@sha256:0660065c3b819781c52457c60ff96ec56ab2412932ae929ffaff01383913c8ee_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/imagepuller-rhel9@sha256:3631abf164330814fd1a336899e5513413c9c20c15edc7afa024a75a3646682f_arm64 as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/imagepuller-rhel9@sha256:811da0b327684c9117ebe5ba1ccae38f3272d55acf680c015148ff024263e446_amd64 as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/imagepuller-rhel9@sha256:89ce2abe27c9abeea7c94580ddf1e41fae6a4df6aff04c9181d8c100b8f2ec07_s390x as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:0f1cea67568be1b8c48d3855061702a0f6cbf25b32aa7cea460b5b42f1d85ffa_arm64 as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:5edc00d72eb88b715d4240c76ced68cab413927727cfe5cb3e45554bf8530161_amd64 as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:b8ccd98628f756480514d0a8bc1dfd40a5c7d2dde8cab4108e9f5e35fde89369_s390x as a component of Red Hat OpenShift Dev Spaces 3.30
- registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:e4e5a9931f64fd28d104ed4b16d681291ad894fd7e25d0e69a9003f6b2ef0118_ppc64le as a component of Red Hat OpenShift Dev Spaces 3.30
- +32 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, applications utilizing libcurl should avoid reusing handles when switching between different proxy configurations. This operational control prevents the unintended leakage of `Proxy-Authorization` headers to incorrect proxies.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:73516
- externalhttps://access.redhat.com/documentation/en-us/red_hat_openshift_dev_spaces/3.30/html/administration_guide/installing-devspaces
- externalhttps://access.redhat.com/security/cve/CVE-2026-8458
- externalhttps://access.redhat.com/security/cve/CVE-2026-8927
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_73516.json