RHSA-2026:76788CriticalCVSS 10.0

Red Hat Security Advisory: Red Hat Developer Hub 1.10.5 Plugin Catalog GA plugins release.

Published
October 6, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (50)

📋 Description

CVE-2026-19534 — undici: undici: Denial of Service via unrequested WebSocket subprotocol CVE-2026-47683 — vm2: vm2: Denial of Service due to memory allocation limit bypass CVE-2026-47686 — vm2: vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE CVE-2026-47698 — vm2: vm2: Sandbox Breakout Using Dangerous Host Proto Mutators CVE-2026-55553 — urllib: urllib: Credential leakage via cross-origin redirects CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-77037 — multer: Multer: Denial of Service via file descriptor leak on aborted uploads CVE-2026-77078 — multer: Multer: Denial of Service via crafted multipart field names CVE-2026-77413 — jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions CVE-2026-77414 — jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions CVE-2026-77415 — jsonata: JSONata: Arbitrary Code Execution via crafted JSONata expressions CVE-2026-82333 — multer: Multer: Denial of Service via oversized array index in field names CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies CVE-2026-84961 — undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options CVE-2026-87776 — compression: compression: Denial of Service via memory leak on premature response close CVE-2026-88932 — multer: multer: Denial of Service via orphaned disk writes on aborted uploads CVE-2026-89011 — isomorphic-git: isomorphic-git: Information disclosure via prototype pollution in getRemoteInfo function. CVE-2026-92934 — vm2: vm2 before 3.11.8 Sandbox Escape RCE via AggregateError CVE-2026-92935 — vm2: vm2 NodeVM Remote Code Execution via Array-Shaped Require CVE-2026-92937 — vm2: vm2 3.11.6 Remote Code Execution via Promise call/apply CVE-2026-92938 — vm2: vm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqlite CVE-2026-92939 — vm2: vm2 3.11.3 through 3.11.6 Native Code Execution via crypto.setEngine CVE-2026-92940 — vm2: vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent CVE-2026-92941 — vm2: vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation CVE-2026-92942 — vm2: vm2: Denial of Service via timeout bypass in sandboxed code CVE-2026-92944 — vm2: vm2 3.10.2 through 3.11.6 Sandbox Escape via Promise Protector CVE-2026-92946 — vm2: vm2 before 3.11.7 Remote Code Execution via require.external CVE-2026-92947 — vm2: vm2 before 3.11.7 Memory Disclosure via Buffer Pool CVE-2026-92948 — vm2: vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test CVE-2026-92950 — vm2: vm2 before 3.11.7 Sandbox Escape via CLI require CVE-2026-92951 — vm2: vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver CVE-2026-92953 — vm2: vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray CVE-2026-92954 — vm2: vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise CVE-2026-92955 — vm2: vm2 before 3.11.8 Sandbox Escape via NodeVM CVE-2026-92956 — vm2: vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming CVE-2026-92957 — vm2: vm2 before 3.11.7 Authentication Bypass via node: Prefix CVE-2026-92958 — vm2: vm2: Sandbox escape via denylist bypass in NodeVM CVE-2026-92959 — vm2: vm2: Asynchronous code execution bypass via Promise thenable assimilation CVE-2026-92960 — vm2: vm2 before 3.11.6 Process-wide State Exposure via os and dns CVE-2026-92961 — vm2: vm2: Denial of Service via memory exhaustion CVE-2026-93603 — vm2: vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function CVE-2026-93604 — vm2: vm2: Sandbox escape via crypto.setFips() function CVE-2026-93605 — vm2: vm2 NodeVM before 3.12.1 Remote Code Execution via child_process CVE-2026-93606 — vm2: vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species

🎯 Affected products8

  • Red Hat Developer Hub 1.10
  • registry.redhat.io/rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend@sha256:55b8b4e43f9dd474dee53d824591695012994daec86efee4dc08612b12425a46_amd64 as a component of Red Hat Developer Hub 1.10
  • registry.redhat.io/rhdh/red-hat-developer-hub-backstage-plugin-lightspeed@sha256:0ca07bd2b15a85bfda16cbc0904fb4ee6c8620e18b891ba89ae792cf0a165095_amd64 as a component of Red Hat Developer Hub 1.10
  • registry.redhat.io/rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend-module-loki@sha256:5549940696691cc087777c20f5d46b485d31e9fe3db896caa2eca7bfef3edb72_amd64 as a component of Red Hat Developer Hub 1.10
  • registry.redhat.io/rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend@sha256:c6a5e6d9c8f3ab900c2b29848273540f4a3e97d351faa338a66da46c0b59d04f_amd64 as a component of Red Hat Developer Hub 1.10
  • registry.redhat.io/rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-form-widgets@sha256:df55fd567640bcd54d8e0d19baa97a5e72429865ad342c94bb80c3a49a5c184e_amd64 as a component of Red Hat Developer Hub 1.10
  • registry.redhat.io/rhdh/red-hat-developer-hub-backstage-plugin-orchestrator@sha256:3aa39a8c3b7bf33aeaae5b3f924d0a2f7625e64657ce9b5517a3a73620f142bb_amd64 as a component of Red Hat Developer Hub 1.10
  • registry.redhat.io/rhdh/red-hat-developer-hub-backstage-plugin-scaffolder-backend-module-orchestrator@sha256:924c4e5e8642438f3099272ff7edd746a66fcec4779aeafb9fd6b3ae0c594f72_amd64 as a component of Red Hat Developer Hub 1.10

✅ Remediation

For more about Red Hat Developer Hub, see References links Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams. Workaround: Upgrade to multer 2.3.0 or later, which properly closes the destination write stream on abnormal source termination and defers cleanup until the stream has closed. Workaround: Update affected products to versions containing multer 2.3.0 or later. There are no known workarounds - upgrading is the only remediation. Workaround: To mitigate this issue, applications utilizing the JSONata library should be configured to strictly validate and sanitize all incoming JSONata expressions, ensuring that only trusted and well-formed expressions are processed. If processing untrusted expressions is unavoidable, deploy the application in a sandboxed environment with minimal privileges to limit the potential impact of arbitrary code execution. Workaround: To mitigate this Critical vulnerability, ensure that all JSONata expressions processed by Red Hat products are sourced exclusively from trusted origins. Avoid processing untrusted or unvalidated JSONata expressions. If processing untrusted input is unavoidable, it must be performed within a strictly isolated and sandboxed environment to contain potential arbitrary code execution and limit its impact on the host system. Workaround: Upgrade to multer 2.3.0 or later. For CVE-2026-82333, multer 2.3.0 adds an opt-in fieldArrayIndexLimit option that rejects oversized array indexes - set limits.fieldArrayIndexLimit to the largest array index your application needs. Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stringify. Where qs.parse is used directly, set allowPrototypes: false unless prototype keys are required. For Express applications, review whether the default query parser configuration is necessary. Wrapping qs.stringify calls in try/catch can limit impact to individual requests. Workaround: Applications that do not use BalancedPool, or that use it without a custom function-valued connect/tls option, are not affected and require no action. As a workaround until packages are updated, avoid using BalancedPool for any connection that relies on custom TLS certificate validation (e.g. certificate pinning); use Client, Pool, or Agent instead, which are unaffected. The permanent fix is upgrading undici to 7.29.1 or later (7.x line) or 8.10.2 or later (8.x line). Workaround: Update the compression middleware to version 1.8.2 or later. No supported workaround is currently available if the affected version cannot be updated. Workaround: Until updates are available, administrators can implement the following mitigations to reduce the risk of disk exhaustion: 1. Monitor disk usage on systems running Red Hat Developer Hub or Ansible Portal and set up alerts for unusual disk consumption patterns. 2. Implement rate limiting on file upload endpoints to restrict the number of upload requests from a single IP address or user account within a given time period. 3. If authentication is not strictly required for file upload endpoints, enable authentication to reduce the attack surface to authenticated users only. 4. Periodically clean up orphaned temporary files in multer's storage directory. The default upload directory is typically in the system temp folder or a configured uploads directory. 5. Set disk quota limits for the user account or partition used by the application to prevent complete disk exhaustion from affecting the entire system. For production environments, apply updates as they become available from Red Hat product teams. Workaround: Until the fix is applied, do not expose non-strict host functions to the sandbox. Only inject strict-mode or ES-module functions so a missing this cannot resolve to the host global. Workaround: This issue is fixed in vm2 version 3.12.1. Red Hat will provide updated versions of Developer Hub and Ansible Portal that include the fixed library version. Until updates are available, administrators can reduce the risk of sandbox escape attacks by implementing the following mitigations: 1. Review vm2 sandbox configurations to determine if the 'crypto' builtin is explicitly allowlisted for untrusted guest code (require.builtin: ['crypto']). If crypto access is not required for guest code functionality, remove it from the allowlist. 2. Restrict the sources from which untrusted code is accepted. Only allow code execution from authenticated, trusted users or verified sources. Implement code review processes for any scripts or plugins before they are executed in vm2 sandboxes. 3. Monitor for unexpected changes to the Node.js process FIPS mode. Log calls to crypto.getFips() before and after guest code execution to detect unauthorized FIPS mode modifications. 4. In FIPS-required environments, consider running vm2 sandboxes in separate isolated processes rather than in the same process as critical application components. Process-level isolation provides an additional security boundary beyond vm2's VM isolation. 5. Implement additional access controls and audit logging for any systems that accept and execute user-provided code, scripts, or plugins. 6. Upgrade to vm2 3.12.1 or later as soon as updated packages are available from Red Hat. Workaround: Until the fix is applied, do not configure NodeVM with require.builtin set to ['*'], a star-minus subtract list, or an explicit child_process allow. Use a tight builtin allowlist that excludes child_process. Workaround: Until the fix is applied, do not expose host functions that return host-realm Promise objects to VM/NodeVM. Return only serialized primitives, or keep host work fully outside the sandbox.

🔗 References (194)