RHSA-2026:79088CriticalCVSS 10.0

Red Hat Security Advisory: Red Hat Developer Hub 1.10.5 release.

Published
October 8, 2026
Last Modified
October 8, 2026

🔗 CVE IDs covered (56)

📋 Description

CVE-2026-13697 — undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives CVE-2026-14456 — openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server CVE-2026-18798 — openssl: QUIC server may trigger double free when processing INITIAL packet CVE-2026-19534 — undici: undici: Denial of Service via unrequested WebSocket subprotocol CVE-2026-47683 — vm2: vm2: Denial of Service due to memory allocation limit bypass CVE-2026-47686 — vm2: vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE CVE-2026-47698 — vm2: vm2: Sandbox Breakout Using Dangerous Host Proto Mutators CVE-2026-55553 — urllib: urllib: Credential leakage via cross-origin redirects CVE-2026-63072 — openssl: heap buffer overflow in CMS key unwrapping CVE-2026-63076 — openssl: invalid pointer dereference in CMP server via crafted protectionAlg CVE-2026-67213 — nanoid: nanoid: Denial of Service via infinite loop in random ID generation CVE-2026-67214 — nanoid: nanoid: Denial of Service via negative size input in non-secure module functions CVE-2026-67422 — pymdown-extensions: Pymdown-extensions: Denial of Service via Regular Expression Vulnerability CVE-2026-75899 — fast-uri: fast-uri: Server-Side Request Forgery via repeated hostname percent-decoding CVE-2026-75931 — fast-uri: fast-uri: Host confusion via skipped IDN canonicalization CVE-2026-75975 — fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization CVE-2026-76172 — fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects CVE-2026-77037 — multer: Multer: Denial of Service via file descriptor leak on aborted uploads CVE-2026-77078 — multer: Multer: Denial of Service via crafted multipart field names CVE-2026-82333 — multer: Multer: Denial of Service via oversized array index in field names CVE-2026-82417 — qs: qs: Denial of Service via improper validation in stringify function CVE-2026-84292 — fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization CVE-2026-84375 — js-yaml: js-yaml: Denial of Service vulnerability in YAML parsing CVE-2026-84394 — fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies CVE-2026-84445 — google.golang.org/grpc: gRPC-Go: Denial of Service via malformed RPC requests CVE-2026-84961 — undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options CVE-2026-87776 — compression: compression: Denial of Service via memory leak on premature response close CVE-2026-88932 — multer: multer: Denial of Service via orphaned disk writes on aborted uploads CVE-2026-89011 — isomorphic-git: isomorphic-git: Information disclosure via prototype pollution in getRemoteInfo function. CVE-2026-92934 — vm2: vm2 before 3.11.8 Sandbox Escape RCE via AggregateError CVE-2026-92935 — vm2: vm2 NodeVM Remote Code Execution via Array-Shaped Require CVE-2026-92937 — vm2: vm2 3.11.6 Remote Code Execution via Promise call/apply CVE-2026-92938 — vm2: vm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqlite CVE-2026-92939 — vm2: vm2 3.11.3 through 3.11.6 Native Code Execution via crypto.setEngine CVE-2026-92940 — vm2: vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent CVE-2026-92941 — vm2: vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation CVE-2026-92942 — vm2: vm2: Denial of Service via timeout bypass in sandboxed code CVE-2026-92944 — vm2: vm2 3.10.2 through 3.11.6 Sandbox Escape via Promise Protector CVE-2026-92946 — vm2: vm2 before 3.11.7 Remote Code Execution via require.external CVE-2026-92947 — vm2: vm2 before 3.11.7 Memory Disclosure via Buffer Pool CVE-2026-92948 — vm2: vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test CVE-2026-92950 — vm2: vm2 before 3.11.7 Sandbox Escape via CLI require CVE-2026-92951 — vm2: vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver CVE-2026-92953 — vm2: vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray CVE-2026-92954 — vm2: vm2 3.10.0 through 3.11.5 Denial of Service via Host Promise CVE-2026-92955 — vm2: vm2 before 3.11.8 Sandbox Escape via NodeVM CVE-2026-92956 — vm2: vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming CVE-2026-92957 — vm2: vm2 before 3.11.7 Authentication Bypass via node: Prefix CVE-2026-92958 — vm2: vm2: Sandbox escape via denylist bypass in NodeVM CVE-2026-92959 — vm2: vm2: Asynchronous code execution bypass via Promise thenable assimilation CVE-2026-92960 — vm2: vm2 before 3.11.6 Process-wide State Exposure via os and dns CVE-2026-92961 — vm2: vm2: Denial of Service via memory exhaustion CVE-2026-93603 — vm2: vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function CVE-2026-93604 — vm2: vm2: Sandbox escape via crypto.setFips() function CVE-2026-93605 — vm2: vm2 NodeVM before 3.12.1 Remote Code Execution via child_process CVE-2026-93606 — vm2: vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species

🎯 Affected products6

  • Red Hat Developer Hub 1.10
  • registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:0f02ae0b8405912741a180af1c290feac2003e69d062bec9c7cd5d13f8732dc9_amd64 as a component of Red Hat Developer Hub 1.10
  • registry.redhat.io/rhdh/rhdh-must-gather-rhel9@sha256:38374b57f1896ba7be54a5778ba55aa0e6766443c5421c6481a82f909cfacc51_amd64 as a component of Red Hat Developer Hub 1.10
  • registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:f71a2783106a98ccbfb60f7219f8220cc778da946f0a800c2ce1d66384ed947a_amd64 as a component of Red Hat Developer Hub 1.10
  • registry.redhat.io/rhdh/rhdh-rag-content-rhel9@sha256:2f71e0edb79f26d812edeb1754075159c9c9a0c8250c4d542e83a0725ad60725_amd64 as a component of Red Hat Developer Hub 1.10
  • registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:a20e789a899fcf4918db20426fce1d3d865391e7dee7c5c50e31533fbdd51fa0_amd64 as a component of Red Hat Developer Hub 1.10

✅ Remediation

For more about Red Hat Developer Hub, see References links Workaround: Option 1: Rate-limit or Firewall Inbound QUIC (UDP 443) [Goal: Slow or block QUIC Initial packets before they reach the vulnerable listener.] A. Confirm QUIC Exposure - Check if any service is listening on UDP 443: ~~~ $ ss -ulnp | grep ':443' # or $ sudo lsof -iUDP:443 -n -P ~~~ Note: If no service is listening on UDP 443, this CVE does not apply (TCP 443 is unaffected). B. Restrict Access to UDP 443 ( Default-deny UDP 443 and allow only trusted networks:) ~~~ $ sudo firewall-cmd --permanent --remove-service=quic 2>/dev/null $ sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="10.0.0.0/8" port port="443" protocol="udp" accept' $ sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" port port="443" protocol="udp" drop' $ sudo firewall-cmd --reload ~~~ C. Verify - Confirm the restriction by testing from an external host (the connection should fail or be throttled): ~~~ $ nc -u -v YOUR_HOST 443 ~~~ Option 2: Disable QUIC Server If QUIC/HTTP3 is not required, remove the vulnerable code path entirely and use TLS/TCP instead. Recommended Mitigation Priority Priority : Action 1.Confirm UDP 443 QUIC listener exists and OpenSSL version is in affected range 2.Block or rate-limit UDP 443 at firewall/edge (immediate) 3.Disable QUIC/HTTP3 on the service if not needed 4.Upgrade OpenSSL to fixed release when available 5.Application owners: set SSL_VALUE_QUIC_MAX_PENDING_CONNS if default 256 is too high Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, ensure application code validates the size parameter passed to customAlphabet or customRandom, rejecting or sanitizing zero-value inputs before passing them to nanoid. Workaround: Sanitize all user-supplied integer inputs before passing them to `nanoid` or `customAlphabet` functions in the `nanoid/non-secure` module, ensuring the size parameter is strictly a non-negative integer. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Until updates are available, restrict the processing of user-supplied URIs to trusted sources only, implement strict allowlists for destination hosts (preferably IP-based rather than hostname-based), and apply egress filtering to prevent server-initiated connections to internal networks or cloud metadata services. Workaround: There is no mitigation available for this issue. Apply updates as they become available from Red Hat product teams. Workaround: Upgrade to multer 2.3.0 or later, which properly closes the destination write stream on abnormal source termination and defers cleanup until the stream has closed. Workaround: Update affected products to versions containing multer 2.3.0 or later. There are no known workarounds - upgrading is the only remediation. Workaround: Upgrade to multer 2.3.0 or later. For CVE-2026-82333, multer 2.3.0 adds an opt-in fieldArrayIndexLimit option that rejects oversized array indexes - set limits.fieldArrayIndexLimit to the largest array index your application needs. Workaround: If an immediate upgrade to qs 6.16.0 is not feasible, avoid re-serializing attacker-influenced parsed query or body objects with qs.stringify. Where qs.parse is used directly, set allowPrototypes: false unless prototype keys are required. For Express applications, review whether the default query parser configuration is necessary. Wrapping qs.stringify calls in try/catch can limit impact to individual requests. Workaround: Applications that do not use BalancedPool, or that use it without a custom function-valued connect/tls option, are not affected and require no action. As a workaround until packages are updated, avoid using BalancedPool for any connection that relies on custom TLS certificate validation (e.g. certificate pinning); use Client, Pool, or Agent instead, which are unaffected. The permanent fix is upgrading undici to 7.29.1 or later (7.x line) or 8.10.2 or later (8.x line). Workaround: Update the compression middleware to version 1.8.2 or later. No supported workaround is currently available if the affected version cannot be updated. Workaround: Until updates are available, administrators can implement the following mitigations to reduce the risk of disk exhaustion: 1. Monitor disk usage on systems running Red Hat Developer Hub or Ansible Portal and set up alerts for unusual disk consumption patterns. 2. Implement rate limiting on file upload endpoints to restrict the number of upload requests from a single IP address or user account within a given time period. 3. If authentication is not strictly required for file upload endpoints, enable authentication to reduce the attack surface to authenticated users only. 4. Periodically clean up orphaned temporary files in multer's storage directory. The default upload directory is typically in the system temp folder or a configured uploads directory. 5. Set disk quota limits for the user account or partition used by the application to prevent complete disk exhaustion from affecting the entire system. For production environments, apply updates as they become available from Red Hat product teams. Workaround: Until the fix is applied, do not expose non-strict host functions to the sandbox. Only inject strict-mode or ES-module functions so a missing this cannot resolve to the host global. Workaround: This issue is fixed in vm2 version 3.12.1. Red Hat will provide updated versions of Developer Hub and Ansible Portal that include the fixed library version. Until updates are available, administrators can reduce the risk of sandbox escape attacks by implementing the following mitigations: 1. Review vm2 sandbox configurations to determine if the 'crypto' builtin is explicitly allowlisted for untrusted guest code (require.builtin: ['crypto']). If crypto access is not required for guest code functionality, remove it from the allowlist. 2. Restrict the sources from which untrusted code is accepted. Only allow code execution from authenticated, trusted users or verified sources. Implement code review processes for any scripts or plugins before they are executed in vm2 sandboxes. 3. Monitor for unexpected changes to the Node.js process FIPS mode. Log calls to crypto.getFips() before and after guest code execution to detect unauthorized FIPS mode modifications. 4. In FIPS-required environments, consider running vm2 sandboxes in separate isolated processes rather than in the same process as critical application components. Process-level isolation provides an additional security boundary beyond vm2's VM isolation. 5. Implement additional access controls and audit logging for any systems that accept and execute user-provided code, scripts, or plugins. 6. Upgrade to vm2 3.12.1 or later as soon as updated packages are available from Red Hat. Workaround: Until the fix is applied, do not configure NodeVM with require.builtin set to ['*'], a star-minus subtract list, or an explicit child_process allow. Use a tight builtin allowlist that excludes child_process. Workaround: Until the fix is applied, do not expose host functions that return host-realm Promise objects to VM/NodeVM. Return only serialized primitives, or keep host work fully outside the sandbox.

🔗 References (259)