RHSA-2026:62260

Vulnerability from csaf_redhat - Published: 2026-09-01 18:22 - Updated: 2026-10-02 10:33
Summary
Red Hat Security Advisory: Red Hat OpenShift Dev Spaces 3.30.0 Release.
Severity
Important
Notes
Topic: Red Hat OpenShift Dev Spaces 3.30.0 has been released.
Details: Red Hat OpenShift Dev Spaces provides a cloud developer workspace server and a browser-based IDE built for teams and organizations. Dev Spaces runs in OpenShift and is well-suited for container-based development. The 3.30 release is based on Eclipse Che 7.121 and uses the DevWorkspace engine to provide support for workspaces based on devfile v2.1 and v2.2. Users still using the v1 standard should migrate as soon as possible. https://devfile.io/docs/2.2.0/migrating-to-devfile-v2 Dev Spaces supports OpenShift EUS releases v4.16 and higher. Users are expected to update to supported OpenShift releases in order to continue to get Dev Spaces updates. https://access.redhat.com/support/policy/updates/openshift#crw
Terms of Use: This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

A flaw was found in Netty where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:10bcd975f5d03858c30d65f8969391b72a05ff69cdf881de3c27a89272bb39e8_ppc64le —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:99392ab8ee91b46131519490ea92adef817140751f84c5ef421a59369deb04da_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f69a7c87ff903073da4602b2daa377d714117960aacd7e5912b94ae752dfec08_arm64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f7587af345f0bf512627705f8543b8533b0d92fd5e845fc3c6c84094c277cc1e_amd64 —
Vendor Fix fix
Workaround
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:37194dd2cd72d6cdb57ca93fd1cfe6e4aa70ec826a3e86032cde0d0738262bd2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:5fcb1e5c626c5d3aa85e0ec98062a44803d2815871236a3b7541b95078997c78_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:8f84e4d5f4cf71219fbed65092645ded0df00369b42b5487ddef7d0c6cac331b_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:e576efc0fbec5378a870880a7bce40327a86203f2ff426fb62d8c767f125761a_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:5093c89215a4dd74643a2911ce3e3f9e351fda5adf71ee897b7b702840025d47_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:803f8b179959a2b20c71876814b09bae7e5ee15cc2dc0a7e7e1fded75a52fc8c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:af4e4fde13a96dd7fd6126bc67927e1873f12fc3263f749527603e60e75e8f5e_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:bce9235e326ab64aabbe7080ca74cbd24d6f9090819d82d9f2f7abb814e3b26f_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:0a1d01a849daf85556bea32c69dde2621021d28ed33c6f1268375345df1c9409_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:14a9baa0a9f39517264880f36689046f91f4ddadd383de1a28a56468de08c7bd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b2cd6a2da440d20b39571dbee7bd31c49ad7a7411530735c8896ac38e30ce4b3_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b3bba37ab9e9d214ff805510072ea56ea9a2e0bc07c42244bc330dd595befedb_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:08bb9bfbb83303d07932903db066c32bfdd3f2acbffd99b40de60e61ab05175b_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:467c2c6858ff7ea5a2c6dca1bb95638c9bc4f99ebcda932bb3bfc65f82f82155_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:6ec7b2a574f90ee5629cae48ce32544fb429aadbbee22eb88992932e7e80a28a_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:ca56033e3eec4a8fc2432418141f5c76a4c7c52391d14ff023c67f5c315cae39_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:3f4b18a7d40ff1b17e6610ab2e6a79b77e3e9f9026b2d1a77f2892ae3ec7c4a0_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:562e100628a6d9b06f519e8d2a555bdaa43b79e7f30870dc94da9c87dac3fcb6_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:5b96816dc89ecd3b6db02011805a3ed9069f5db86b4158eac8b2f931f0e9532b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:cd0d86c44dc30c77d2876540a75249fbcb0cb1b3ecf4d14394f6eebe2061f9a6_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:d98a5605205445fe1fd9a8f439b09918eb187eef468a0546a911c5ee1d00f851_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:130cf3c00d9042bdc07da56eee755b2682a13f77b9bd445ca9369e7aee9f02cf_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:5f5b25b4cbfa35f731247c948d83f31b100fa99c0126a964fbd46bab9c204b55_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:7f0a8c6cdbc3031e5e0193819310640f115a658ff4883914b1876c9a21dc010a_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:c722c2cdf62c8dc9953dde8a5cb283c3afece2e7925b4213c6cb6afa76004f29_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:188e877e1d78b19fa479d4b2815fc0d48fb8a048274d7f3aa37f5bf7e16523dd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:36779d828279ae8078a29ce39ed42d8311fe40fb13347533e2d0652a23a2324f_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:8e216bcc9a9f70469bbd1b91e94d30e74d6fb8cc650bf2ca562a0aa6e82591f7_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:9889305d3ba264f5e015a58e355840b90807995d2e1fb672e64c42fd4d4f070b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:122bbd2d696d9ac1a98a6d587c4ebb503ae13eac888bd63c48695aeef5a3ec93_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:8e7d83f45214e9841238d396ecf3e89ce4b43910f951136bf9e792b224ab09e7_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:98164a2ff734c7d74b8bf9d55db9aafc2e1922baf8e4146efed21642e022a513_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:af08600dbbfde6a494e4a54ddfaae4f067778412b8bbaa0e0d6ff22018121438_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:560dd6062c5240e73ec60ecc13d402009b01e81ed452b6314c3817a2d116d575_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:61a523a9663ff94b984f06fb72a570a18faf326b5efe6ef7d3ba55f96d4e422f_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:a4f8b673fd049befb193ee8f93ac8167b784cfe35b5de3584b19a95c726d9cff_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:b73b5fef7a238e3a16a0b724a8022588a4f69195743bf489f2bb01e4d3a59113_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:121aee11bc25d5e983808691d3b82905048b5a67ffb01f61c86815867e4e8d08_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:7ba97ebd86b3442cd95ffa2605b7890e2f85731ae84ee696d18bae0633439afe_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:9eccdaac68f3ce6a42a435ceb511483d0f233fb21b3dee8343b8d70cbd67f2ac_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:f74ce43b7d8ade25e5b0f78a41f87db5c6005a85f48cde956b9a87a5892c3a87_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:1ad319aa2d1f00c745609246ea315955298a7028afe3fc5502a68c2d1b5c8467_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:29840664ab5a92cebe5aef4ca45e14c558fe92b832a9d2b8ddec426eaed93144_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:4e76c5cb1ed229c3c1d51beedad3e7970a29c55d32cfc0500153fded3dc8a1c9_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:908382349b4ba81195c2fdc9e650d304cd868ff94d809414d7e44947f2725e0c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:38a0acf8e97a7d0c6a4c8d6815321e35df6ad35736a7338267ce9b5adb118662_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:8b8f3387a3764beb3d8ad6a027b05f42619ccf33165e733e8dc7b3f135895dc5_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:b338c1060dd859a8747e0812e176ab266d338aea799becd41e48afc50061fb82_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:ba0aebd6b6b6ceb676b6990d5bd9f3b7efe40cedd9407149da92c55435ef7db6_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:1e1215926b9d71cc0131148ad92f4ea8ea8b1e2ba72d6f73396601fceac5ee75_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4cd3b940aa076240f9c7e1fffd05c6bd739a76f31f94d2e4e80ce109fec27206_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4fb0b9f0ab3c37feeace62a178b6abd0e25797cb9ea326c4e1c079ad7791c7a2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:b0b215ef0b00aff4be01e9c7718f92ef0c249782e37ad5fde717d9b76e112a92_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:1a1dc37c6638cf1bbbcdef28032f1e5e847d99566a8b76338376245798fdcf92_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:67a090d14c2859d30419de71d46f85b71d8bfb8ea0f831f103be9a236af1153c_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:6a14d27e13cfc97103437c822cb7becf22d9a6c2fcb94729c977d6d5ffecaa0d_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:eaab16b83d494e162ab01c2476c548907eababda4b20317666f41119467c6890_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:2ee7edad219c94eb91465132570a8180b038c0e1e94e4c20f15ac20388d443a2_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:3e9d56b1c640ac770ef67309529a662c36a24858b4c0d74273e72c6398181cf4_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:bde7602ad25518d0344589c2efe1ff51af32e3070292751cb4a3e1de9788d291_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:ee6cce6ce7461624def1638ac43fbf4cf81a9fc2f88a0729fca1399d19e78820_amd64 —
Workaround
Threats
Impact Important

A flaw was found in curl. When a new data transfer attempts to upgrade its connection using STARTTLS, it may incorrectly reuse an existing live connection. This reuse can occur even if the Transport Layer Security (TLS) configuration of the new transfer does not match the existing connection, potentially leading to an insecure connection being established.

CWE-295 - Improper Certificate Validation
Affected products
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:37194dd2cd72d6cdb57ca93fd1cfe6e4aa70ec826a3e86032cde0d0738262bd2_ppc64le —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:5fcb1e5c626c5d3aa85e0ec98062a44803d2815871236a3b7541b95078997c78_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:8f84e4d5f4cf71219fbed65092645ded0df00369b42b5487ddef7d0c6cac331b_amd64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:e576efc0fbec5378a870880a7bce40327a86203f2ff426fb62d8c767f125761a_arm64 —
Vendor Fix fix
Workaround
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:5093c89215a4dd74643a2911ce3e3f9e351fda5adf71ee897b7b702840025d47_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:803f8b179959a2b20c71876814b09bae7e5ee15cc2dc0a7e7e1fded75a52fc8c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:af4e4fde13a96dd7fd6126bc67927e1873f12fc3263f749527603e60e75e8f5e_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:bce9235e326ab64aabbe7080ca74cbd24d6f9090819d82d9f2f7abb814e3b26f_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:0a1d01a849daf85556bea32c69dde2621021d28ed33c6f1268375345df1c9409_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:14a9baa0a9f39517264880f36689046f91f4ddadd383de1a28a56468de08c7bd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b2cd6a2da440d20b39571dbee7bd31c49ad7a7411530735c8896ac38e30ce4b3_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b3bba37ab9e9d214ff805510072ea56ea9a2e0bc07c42244bc330dd595befedb_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:08bb9bfbb83303d07932903db066c32bfdd3f2acbffd99b40de60e61ab05175b_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:467c2c6858ff7ea5a2c6dca1bb95638c9bc4f99ebcda932bb3bfc65f82f82155_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:6ec7b2a574f90ee5629cae48ce32544fb429aadbbee22eb88992932e7e80a28a_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:ca56033e3eec4a8fc2432418141f5c76a4c7c52391d14ff023c67f5c315cae39_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:3f4b18a7d40ff1b17e6610ab2e6a79b77e3e9f9026b2d1a77f2892ae3ec7c4a0_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:562e100628a6d9b06f519e8d2a555bdaa43b79e7f30870dc94da9c87dac3fcb6_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:5b96816dc89ecd3b6db02011805a3ed9069f5db86b4158eac8b2f931f0e9532b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:cd0d86c44dc30c77d2876540a75249fbcb0cb1b3ecf4d14394f6eebe2061f9a6_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:d98a5605205445fe1fd9a8f439b09918eb187eef468a0546a911c5ee1d00f851_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:130cf3c00d9042bdc07da56eee755b2682a13f77b9bd445ca9369e7aee9f02cf_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:5f5b25b4cbfa35f731247c948d83f31b100fa99c0126a964fbd46bab9c204b55_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:7f0a8c6cdbc3031e5e0193819310640f115a658ff4883914b1876c9a21dc010a_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:c722c2cdf62c8dc9953dde8a5cb283c3afece2e7925b4213c6cb6afa76004f29_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:188e877e1d78b19fa479d4b2815fc0d48fb8a048274d7f3aa37f5bf7e16523dd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:36779d828279ae8078a29ce39ed42d8311fe40fb13347533e2d0652a23a2324f_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:8e216bcc9a9f70469bbd1b91e94d30e74d6fb8cc650bf2ca562a0aa6e82591f7_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:9889305d3ba264f5e015a58e355840b90807995d2e1fb672e64c42fd4d4f070b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:10bcd975f5d03858c30d65f8969391b72a05ff69cdf881de3c27a89272bb39e8_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:99392ab8ee91b46131519490ea92adef817140751f84c5ef421a59369deb04da_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f69a7c87ff903073da4602b2daa377d714117960aacd7e5912b94ae752dfec08_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f7587af345f0bf512627705f8543b8533b0d92fd5e845fc3c6c84094c277cc1e_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:122bbd2d696d9ac1a98a6d587c4ebb503ae13eac888bd63c48695aeef5a3ec93_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:8e7d83f45214e9841238d396ecf3e89ce4b43910f951136bf9e792b224ab09e7_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:98164a2ff734c7d74b8bf9d55db9aafc2e1922baf8e4146efed21642e022a513_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:af08600dbbfde6a494e4a54ddfaae4f067778412b8bbaa0e0d6ff22018121438_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:560dd6062c5240e73ec60ecc13d402009b01e81ed452b6314c3817a2d116d575_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:61a523a9663ff94b984f06fb72a570a18faf326b5efe6ef7d3ba55f96d4e422f_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:a4f8b673fd049befb193ee8f93ac8167b784cfe35b5de3584b19a95c726d9cff_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:b73b5fef7a238e3a16a0b724a8022588a4f69195743bf489f2bb01e4d3a59113_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:121aee11bc25d5e983808691d3b82905048b5a67ffb01f61c86815867e4e8d08_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:7ba97ebd86b3442cd95ffa2605b7890e2f85731ae84ee696d18bae0633439afe_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:9eccdaac68f3ce6a42a435ceb511483d0f233fb21b3dee8343b8d70cbd67f2ac_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:f74ce43b7d8ade25e5b0f78a41f87db5c6005a85f48cde956b9a87a5892c3a87_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:1ad319aa2d1f00c745609246ea315955298a7028afe3fc5502a68c2d1b5c8467_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:29840664ab5a92cebe5aef4ca45e14c558fe92b832a9d2b8ddec426eaed93144_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:4e76c5cb1ed229c3c1d51beedad3e7970a29c55d32cfc0500153fded3dc8a1c9_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:908382349b4ba81195c2fdc9e650d304cd868ff94d809414d7e44947f2725e0c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:38a0acf8e97a7d0c6a4c8d6815321e35df6ad35736a7338267ce9b5adb118662_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:8b8f3387a3764beb3d8ad6a027b05f42619ccf33165e733e8dc7b3f135895dc5_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:b338c1060dd859a8747e0812e176ab266d338aea799becd41e48afc50061fb82_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:ba0aebd6b6b6ceb676b6990d5bd9f3b7efe40cedd9407149da92c55435ef7db6_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:1e1215926b9d71cc0131148ad92f4ea8ea8b1e2ba72d6f73396601fceac5ee75_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4cd3b940aa076240f9c7e1fffd05c6bd739a76f31f94d2e4e80ce109fec27206_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4fb0b9f0ab3c37feeace62a178b6abd0e25797cb9ea326c4e1c079ad7791c7a2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:b0b215ef0b00aff4be01e9c7718f92ef0c249782e37ad5fde717d9b76e112a92_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:1a1dc37c6638cf1bbbcdef28032f1e5e847d99566a8b76338376245798fdcf92_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:67a090d14c2859d30419de71d46f85b71d8bfb8ea0f831f103be9a236af1153c_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:6a14d27e13cfc97103437c822cb7becf22d9a6c2fcb94729c977d6d5ffecaa0d_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:eaab16b83d494e162ab01c2476c548907eababda4b20317666f41119467c6890_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:2ee7edad219c94eb91465132570a8180b038c0e1e94e4c20f15ac20388d443a2_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:3e9d56b1c640ac770ef67309529a662c36a24858b4c0d74273e72c6398181cf4_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:bde7602ad25518d0344589c2efe1ff51af32e3070292751cb4a3e1de9788d291_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:ee6cce6ce7461624def1638ac43fbf4cf81a9fc2f88a0729fca1399d19e78820_amd64 —
Workaround
Threats
Impact Important

A flaw was found in the shell-quote component. The quote() function did not properly validate object-token inputs, allowing line terminators to pass unescaped into the output. A remote attacker could exploit this vulnerability by providing specially crafted input, which a POSIX shell would interpret as a command separator. This could lead to command injection, enabling the attacker to execute arbitrary code on the system.

CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Affected products
Fixed 4 products, the same list as for CVE-2026-8286
Known not affected 61 products, the same list as for CVE-2026-8286
Threats
Impact Important

A flaw was found in curl. When a libcurl-based application uses SCP:// or SFTP:// for transfers and employs the CURLOPT_SSH_KEYFUNCTION callback, it may silently accept an untrusted server. This occurs if the server's host key type differs from the one stored in the known_hosts file. The callback mechanism fails to enforce the host key restriction, enabling a connection to an untrusted server and risking a man-in-the-middle attack.

CWE-347 - Improper Verification of Cryptographic Signature
Affected products
Fixed 4 products, the same list as for CVE-2026-8286
Known not affected 61 products, the same list as for CVE-2026-8286
Threats
Impact Important

A flaw was found in Eclipse Parsson. The JSON parser did not enforce a default maximum on the number of characters consumed while processing a single JSON document. A remote attacker could exploit this by providing a very large, specially crafted JSON document. This could force applications to consume excessive CPU and memory, leading to a denial of service (DoS).

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:560dd6062c5240e73ec60ecc13d402009b01e81ed452b6314c3817a2d116d575_amd64 —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:61a523a9663ff94b984f06fb72a570a18faf326b5efe6ef7d3ba55f96d4e422f_ppc64le —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:a4f8b673fd049befb193ee8f93ac8167b784cfe35b5de3584b19a95c726d9cff_s390x —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:b73b5fef7a238e3a16a0b724a8022588a4f69195743bf489f2bb01e4d3a59113_arm64 —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:121aee11bc25d5e983808691d3b82905048b5a67ffb01f61c86815867e4e8d08_amd64 —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:7ba97ebd86b3442cd95ffa2605b7890e2f85731ae84ee696d18bae0633439afe_s390x —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:9eccdaac68f3ce6a42a435ceb511483d0f233fb21b3dee8343b8d70cbd67f2ac_arm64 —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:f74ce43b7d8ade25e5b0f78a41f87db5c6005a85f48cde956b9a87a5892c3a87_ppc64le —
Vendor Fix fix
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:37194dd2cd72d6cdb57ca93fd1cfe6e4aa70ec826a3e86032cde0d0738262bd2_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:5fcb1e5c626c5d3aa85e0ec98062a44803d2815871236a3b7541b95078997c78_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:8f84e4d5f4cf71219fbed65092645ded0df00369b42b5487ddef7d0c6cac331b_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:e576efc0fbec5378a870880a7bce40327a86203f2ff426fb62d8c767f125761a_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:5093c89215a4dd74643a2911ce3e3f9e351fda5adf71ee897b7b702840025d47_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:803f8b179959a2b20c71876814b09bae7e5ee15cc2dc0a7e7e1fded75a52fc8c_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:af4e4fde13a96dd7fd6126bc67927e1873f12fc3263f749527603e60e75e8f5e_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:bce9235e326ab64aabbe7080ca74cbd24d6f9090819d82d9f2f7abb814e3b26f_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:0a1d01a849daf85556bea32c69dde2621021d28ed33c6f1268375345df1c9409_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:14a9baa0a9f39517264880f36689046f91f4ddadd383de1a28a56468de08c7bd_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b2cd6a2da440d20b39571dbee7bd31c49ad7a7411530735c8896ac38e30ce4b3_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b3bba37ab9e9d214ff805510072ea56ea9a2e0bc07c42244bc330dd595befedb_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:08bb9bfbb83303d07932903db066c32bfdd3f2acbffd99b40de60e61ab05175b_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:467c2c6858ff7ea5a2c6dca1bb95638c9bc4f99ebcda932bb3bfc65f82f82155_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:6ec7b2a574f90ee5629cae48ce32544fb429aadbbee22eb88992932e7e80a28a_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:ca56033e3eec4a8fc2432418141f5c76a4c7c52391d14ff023c67f5c315cae39_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:3f4b18a7d40ff1b17e6610ab2e6a79b77e3e9f9026b2d1a77f2892ae3ec7c4a0_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:562e100628a6d9b06f519e8d2a555bdaa43b79e7f30870dc94da9c87dac3fcb6_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:5b96816dc89ecd3b6db02011805a3ed9069f5db86b4158eac8b2f931f0e9532b_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:cd0d86c44dc30c77d2876540a75249fbcb0cb1b3ecf4d14394f6eebe2061f9a6_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:d98a5605205445fe1fd9a8f439b09918eb187eef468a0546a911c5ee1d00f851_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:130cf3c00d9042bdc07da56eee755b2682a13f77b9bd445ca9369e7aee9f02cf_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:5f5b25b4cbfa35f731247c948d83f31b100fa99c0126a964fbd46bab9c204b55_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:7f0a8c6cdbc3031e5e0193819310640f115a658ff4883914b1876c9a21dc010a_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:c722c2cdf62c8dc9953dde8a5cb283c3afece2e7925b4213c6cb6afa76004f29_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:188e877e1d78b19fa479d4b2815fc0d48fb8a048274d7f3aa37f5bf7e16523dd_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:36779d828279ae8078a29ce39ed42d8311fe40fb13347533e2d0652a23a2324f_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:8e216bcc9a9f70469bbd1b91e94d30e74d6fb8cc650bf2ca562a0aa6e82591f7_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:9889305d3ba264f5e015a58e355840b90807995d2e1fb672e64c42fd4d4f070b_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:10bcd975f5d03858c30d65f8969391b72a05ff69cdf881de3c27a89272bb39e8_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:99392ab8ee91b46131519490ea92adef817140751f84c5ef421a59369deb04da_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f69a7c87ff903073da4602b2daa377d714117960aacd7e5912b94ae752dfec08_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f7587af345f0bf512627705f8543b8533b0d92fd5e845fc3c6c84094c277cc1e_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:122bbd2d696d9ac1a98a6d587c4ebb503ae13eac888bd63c48695aeef5a3ec93_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:8e7d83f45214e9841238d396ecf3e89ce4b43910f951136bf9e792b224ab09e7_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:98164a2ff734c7d74b8bf9d55db9aafc2e1922baf8e4146efed21642e022a513_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:af08600dbbfde6a494e4a54ddfaae4f067778412b8bbaa0e0d6ff22018121438_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:1ad319aa2d1f00c745609246ea315955298a7028afe3fc5502a68c2d1b5c8467_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:29840664ab5a92cebe5aef4ca45e14c558fe92b832a9d2b8ddec426eaed93144_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:4e76c5cb1ed229c3c1d51beedad3e7970a29c55d32cfc0500153fded3dc8a1c9_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:908382349b4ba81195c2fdc9e650d304cd868ff94d809414d7e44947f2725e0c_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:38a0acf8e97a7d0c6a4c8d6815321e35df6ad35736a7338267ce9b5adb118662_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:8b8f3387a3764beb3d8ad6a027b05f42619ccf33165e733e8dc7b3f135895dc5_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:b338c1060dd859a8747e0812e176ab266d338aea799becd41e48afc50061fb82_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:ba0aebd6b6b6ceb676b6990d5bd9f3b7efe40cedd9407149da92c55435ef7db6_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:1e1215926b9d71cc0131148ad92f4ea8ea8b1e2ba72d6f73396601fceac5ee75_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4cd3b940aa076240f9c7e1fffd05c6bd739a76f31f94d2e4e80ce109fec27206_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4fb0b9f0ab3c37feeace62a178b6abd0e25797cb9ea326c4e1c079ad7791c7a2_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:b0b215ef0b00aff4be01e9c7718f92ef0c249782e37ad5fde717d9b76e112a92_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:1a1dc37c6638cf1bbbcdef28032f1e5e847d99566a8b76338376245798fdcf92_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:67a090d14c2859d30419de71d46f85b71d8bfb8ea0f831f103be9a236af1153c_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:6a14d27e13cfc97103437c822cb7becf22d9a6c2fcb94729c977d6d5ffecaa0d_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:eaab16b83d494e162ab01c2476c548907eababda4b20317666f41119467c6890_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:2ee7edad219c94eb91465132570a8180b038c0e1e94e4c20f15ac20388d443a2_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:3e9d56b1c640ac770ef67309529a662c36a24858b4c0d74273e72c6398181cf4_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:bde7602ad25518d0344589c2efe1ff51af32e3070292751cb4a3e1de9788d291_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:ee6cce6ce7461624def1638ac43fbf4cf81a9fc2f88a0729fca1399d19e78820_amd64 —
Threats
Impact Important

A flaw was found in Eclipse Jetty, a widely used web server and servlet container. This vulnerability affects its HTTP Digest authentication mechanism, which is used to verify user identities. The issue arises because Jetty's hash computation for passwords does not correctly handle certain characters, leading to a weakness in how passwords are processed. A remote attacker could exploit this by crafting a specific password that generates the same internal hash as a legitimate user's password, thereby bypassing authentication and gaining unauthorized access to the victim's account.

CWE-303 - Incorrect Implementation of Authentication Algorithm
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Important

A flaw was found in Eclipse Jetty. This vulnerability allows a remote attacker to cause the server to retain HTTP/1.1 request trailers from a prior connection. Consequently, subsequent requests made over the same connection may unintentionally disclose information by reporting the previously retained trailers, or a combination of previous and current request trailers.

CWE-201 - Insertion of Sensitive Information Into Sent Data
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Moderate

A flaw was found in form-data, a library for creating readable multipart/form-data streams. A remote attacker can exploit this vulnerability by injecting carriage return (CR), line feed (LF), or double-quote (") characters into the `field` argument of `FormData#append` or the `filename` option. This allows the attacker to inject additional headers or smuggle entire additional multipart parts into requests, potentially enabling them to add or override form fields and compromise data integrity.

CWE-93 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
Affected products
Fixed 4 products, the same list as for CVE-2026-8286
Known not affected 61 products, the same list as for CVE-2026-8286
Threats
Impact Important

A flaw was found in undici. A malicious WebSocket server can exploit this by streaming numerous small or empty continuation frames. This can bypass per-frame and cumulative-size validation, leading to unbounded memory growth in the client process. The primary consequence is memory exhaustion, resulting in a denial of service (DoS) for affected applications using the undici WebSocket client or WebSocketStream API.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:08bb9bfbb83303d07932903db066c32bfdd3f2acbffd99b40de60e61ab05175b_amd64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:467c2c6858ff7ea5a2c6dca1bb95638c9bc4f99ebcda932bb3bfc65f82f82155_ppc64le —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:6ec7b2a574f90ee5629cae48ce32544fb429aadbbee22eb88992932e7e80a28a_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:ca56033e3eec4a8fc2432418141f5c76a4c7c52391d14ff023c67f5c315cae39_arm64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:560dd6062c5240e73ec60ecc13d402009b01e81ed452b6314c3817a2d116d575_amd64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:61a523a9663ff94b984f06fb72a570a18faf326b5efe6ef7d3ba55f96d4e422f_ppc64le —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:a4f8b673fd049befb193ee8f93ac8167b784cfe35b5de3584b19a95c726d9cff_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:b73b5fef7a238e3a16a0b724a8022588a4f69195743bf489f2bb01e4d3a59113_arm64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:121aee11bc25d5e983808691d3b82905048b5a67ffb01f61c86815867e4e8d08_amd64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:7ba97ebd86b3442cd95ffa2605b7890e2f85731ae84ee696d18bae0633439afe_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:9eccdaac68f3ce6a42a435ceb511483d0f233fb21b3dee8343b8d70cbd67f2ac_arm64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:f74ce43b7d8ade25e5b0f78a41f87db5c6005a85f48cde956b9a87a5892c3a87_ppc64le —
Vendor Fix fix
Workaround
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:37194dd2cd72d6cdb57ca93fd1cfe6e4aa70ec826a3e86032cde0d0738262bd2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:5fcb1e5c626c5d3aa85e0ec98062a44803d2815871236a3b7541b95078997c78_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:8f84e4d5f4cf71219fbed65092645ded0df00369b42b5487ddef7d0c6cac331b_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:e576efc0fbec5378a870880a7bce40327a86203f2ff426fb62d8c767f125761a_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:5093c89215a4dd74643a2911ce3e3f9e351fda5adf71ee897b7b702840025d47_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:803f8b179959a2b20c71876814b09bae7e5ee15cc2dc0a7e7e1fded75a52fc8c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:af4e4fde13a96dd7fd6126bc67927e1873f12fc3263f749527603e60e75e8f5e_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:bce9235e326ab64aabbe7080ca74cbd24d6f9090819d82d9f2f7abb814e3b26f_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:0a1d01a849daf85556bea32c69dde2621021d28ed33c6f1268375345df1c9409_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:14a9baa0a9f39517264880f36689046f91f4ddadd383de1a28a56468de08c7bd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b2cd6a2da440d20b39571dbee7bd31c49ad7a7411530735c8896ac38e30ce4b3_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b3bba37ab9e9d214ff805510072ea56ea9a2e0bc07c42244bc330dd595befedb_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:3f4b18a7d40ff1b17e6610ab2e6a79b77e3e9f9026b2d1a77f2892ae3ec7c4a0_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:562e100628a6d9b06f519e8d2a555bdaa43b79e7f30870dc94da9c87dac3fcb6_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:5b96816dc89ecd3b6db02011805a3ed9069f5db86b4158eac8b2f931f0e9532b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:cd0d86c44dc30c77d2876540a75249fbcb0cb1b3ecf4d14394f6eebe2061f9a6_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:d98a5605205445fe1fd9a8f439b09918eb187eef468a0546a911c5ee1d00f851_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:130cf3c00d9042bdc07da56eee755b2682a13f77b9bd445ca9369e7aee9f02cf_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:5f5b25b4cbfa35f731247c948d83f31b100fa99c0126a964fbd46bab9c204b55_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:7f0a8c6cdbc3031e5e0193819310640f115a658ff4883914b1876c9a21dc010a_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:c722c2cdf62c8dc9953dde8a5cb283c3afece2e7925b4213c6cb6afa76004f29_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:188e877e1d78b19fa479d4b2815fc0d48fb8a048274d7f3aa37f5bf7e16523dd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:36779d828279ae8078a29ce39ed42d8311fe40fb13347533e2d0652a23a2324f_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:8e216bcc9a9f70469bbd1b91e94d30e74d6fb8cc650bf2ca562a0aa6e82591f7_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:9889305d3ba264f5e015a58e355840b90807995d2e1fb672e64c42fd4d4f070b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:10bcd975f5d03858c30d65f8969391b72a05ff69cdf881de3c27a89272bb39e8_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:99392ab8ee91b46131519490ea92adef817140751f84c5ef421a59369deb04da_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f69a7c87ff903073da4602b2daa377d714117960aacd7e5912b94ae752dfec08_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f7587af345f0bf512627705f8543b8533b0d92fd5e845fc3c6c84094c277cc1e_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:122bbd2d696d9ac1a98a6d587c4ebb503ae13eac888bd63c48695aeef5a3ec93_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:8e7d83f45214e9841238d396ecf3e89ce4b43910f951136bf9e792b224ab09e7_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:98164a2ff734c7d74b8bf9d55db9aafc2e1922baf8e4146efed21642e022a513_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:af08600dbbfde6a494e4a54ddfaae4f067778412b8bbaa0e0d6ff22018121438_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:1ad319aa2d1f00c745609246ea315955298a7028afe3fc5502a68c2d1b5c8467_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:29840664ab5a92cebe5aef4ca45e14c558fe92b832a9d2b8ddec426eaed93144_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:4e76c5cb1ed229c3c1d51beedad3e7970a29c55d32cfc0500153fded3dc8a1c9_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:908382349b4ba81195c2fdc9e650d304cd868ff94d809414d7e44947f2725e0c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:38a0acf8e97a7d0c6a4c8d6815321e35df6ad35736a7338267ce9b5adb118662_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:8b8f3387a3764beb3d8ad6a027b05f42619ccf33165e733e8dc7b3f135895dc5_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:b338c1060dd859a8747e0812e176ab266d338aea799becd41e48afc50061fb82_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:ba0aebd6b6b6ceb676b6990d5bd9f3b7efe40cedd9407149da92c55435ef7db6_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:1e1215926b9d71cc0131148ad92f4ea8ea8b1e2ba72d6f73396601fceac5ee75_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4cd3b940aa076240f9c7e1fffd05c6bd739a76f31f94d2e4e80ce109fec27206_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4fb0b9f0ab3c37feeace62a178b6abd0e25797cb9ea326c4e1c079ad7791c7a2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:b0b215ef0b00aff4be01e9c7718f92ef0c249782e37ad5fde717d9b76e112a92_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:1a1dc37c6638cf1bbbcdef28032f1e5e847d99566a8b76338376245798fdcf92_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:67a090d14c2859d30419de71d46f85b71d8bfb8ea0f831f103be9a236af1153c_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:6a14d27e13cfc97103437c822cb7becf22d9a6c2fcb94729c977d6d5ffecaa0d_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:eaab16b83d494e162ab01c2476c548907eababda4b20317666f41119467c6890_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:2ee7edad219c94eb91465132570a8180b038c0e1e94e4c20f15ac20388d443a2_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:3e9d56b1c640ac770ef67309529a662c36a24858b4c0d74273e72c6398181cf4_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:bde7602ad25518d0344589c2efe1ff51af32e3070292751cb4a3e1de9788d291_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:ee6cce6ce7461624def1638ac43fbf4cf81a9fc2f88a0729fca1399d19e78820_amd64 —
Workaround
Threats
Impact Important

A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time complexity, leading to significant CPU consumption and event-loop blocking. This can result in a Denial of Service (DoS) for the affected system.

CWE-1333 - Inefficient Regular Expression Complexity
Affected products
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:37194dd2cd72d6cdb57ca93fd1cfe6e4aa70ec826a3e86032cde0d0738262bd2_ppc64le —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:5fcb1e5c626c5d3aa85e0ec98062a44803d2815871236a3b7541b95078997c78_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:8f84e4d5f4cf71219fbed65092645ded0df00369b42b5487ddef7d0c6cac331b_amd64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:e576efc0fbec5378a870880a7bce40327a86203f2ff426fb62d8c767f125761a_arm64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:560dd6062c5240e73ec60ecc13d402009b01e81ed452b6314c3817a2d116d575_amd64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:61a523a9663ff94b984f06fb72a570a18faf326b5efe6ef7d3ba55f96d4e422f_ppc64le —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:a4f8b673fd049befb193ee8f93ac8167b784cfe35b5de3584b19a95c726d9cff_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:b73b5fef7a238e3a16a0b724a8022588a4f69195743bf489f2bb01e4d3a59113_arm64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:121aee11bc25d5e983808691d3b82905048b5a67ffb01f61c86815867e4e8d08_amd64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:7ba97ebd86b3442cd95ffa2605b7890e2f85731ae84ee696d18bae0633439afe_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:9eccdaac68f3ce6a42a435ceb511483d0f233fb21b3dee8343b8d70cbd67f2ac_arm64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:f74ce43b7d8ade25e5b0f78a41f87db5c6005a85f48cde956b9a87a5892c3a87_ppc64le —
Vendor Fix fix
Workaround
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:5093c89215a4dd74643a2911ce3e3f9e351fda5adf71ee897b7b702840025d47_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:803f8b179959a2b20c71876814b09bae7e5ee15cc2dc0a7e7e1fded75a52fc8c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:af4e4fde13a96dd7fd6126bc67927e1873f12fc3263f749527603e60e75e8f5e_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:bce9235e326ab64aabbe7080ca74cbd24d6f9090819d82d9f2f7abb814e3b26f_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:0a1d01a849daf85556bea32c69dde2621021d28ed33c6f1268375345df1c9409_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:14a9baa0a9f39517264880f36689046f91f4ddadd383de1a28a56468de08c7bd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b2cd6a2da440d20b39571dbee7bd31c49ad7a7411530735c8896ac38e30ce4b3_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b3bba37ab9e9d214ff805510072ea56ea9a2e0bc07c42244bc330dd595befedb_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:08bb9bfbb83303d07932903db066c32bfdd3f2acbffd99b40de60e61ab05175b_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:467c2c6858ff7ea5a2c6dca1bb95638c9bc4f99ebcda932bb3bfc65f82f82155_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:6ec7b2a574f90ee5629cae48ce32544fb429aadbbee22eb88992932e7e80a28a_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:ca56033e3eec4a8fc2432418141f5c76a4c7c52391d14ff023c67f5c315cae39_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:3f4b18a7d40ff1b17e6610ab2e6a79b77e3e9f9026b2d1a77f2892ae3ec7c4a0_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:562e100628a6d9b06f519e8d2a555bdaa43b79e7f30870dc94da9c87dac3fcb6_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:5b96816dc89ecd3b6db02011805a3ed9069f5db86b4158eac8b2f931f0e9532b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:cd0d86c44dc30c77d2876540a75249fbcb0cb1b3ecf4d14394f6eebe2061f9a6_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:d98a5605205445fe1fd9a8f439b09918eb187eef468a0546a911c5ee1d00f851_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:130cf3c00d9042bdc07da56eee755b2682a13f77b9bd445ca9369e7aee9f02cf_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:5f5b25b4cbfa35f731247c948d83f31b100fa99c0126a964fbd46bab9c204b55_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:7f0a8c6cdbc3031e5e0193819310640f115a658ff4883914b1876c9a21dc010a_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:c722c2cdf62c8dc9953dde8a5cb283c3afece2e7925b4213c6cb6afa76004f29_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:188e877e1d78b19fa479d4b2815fc0d48fb8a048274d7f3aa37f5bf7e16523dd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:36779d828279ae8078a29ce39ed42d8311fe40fb13347533e2d0652a23a2324f_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:8e216bcc9a9f70469bbd1b91e94d30e74d6fb8cc650bf2ca562a0aa6e82591f7_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:9889305d3ba264f5e015a58e355840b90807995d2e1fb672e64c42fd4d4f070b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:10bcd975f5d03858c30d65f8969391b72a05ff69cdf881de3c27a89272bb39e8_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:99392ab8ee91b46131519490ea92adef817140751f84c5ef421a59369deb04da_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f69a7c87ff903073da4602b2daa377d714117960aacd7e5912b94ae752dfec08_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f7587af345f0bf512627705f8543b8533b0d92fd5e845fc3c6c84094c277cc1e_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:122bbd2d696d9ac1a98a6d587c4ebb503ae13eac888bd63c48695aeef5a3ec93_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:8e7d83f45214e9841238d396ecf3e89ce4b43910f951136bf9e792b224ab09e7_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:98164a2ff734c7d74b8bf9d55db9aafc2e1922baf8e4146efed21642e022a513_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:af08600dbbfde6a494e4a54ddfaae4f067778412b8bbaa0e0d6ff22018121438_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:1ad319aa2d1f00c745609246ea315955298a7028afe3fc5502a68c2d1b5c8467_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:29840664ab5a92cebe5aef4ca45e14c558fe92b832a9d2b8ddec426eaed93144_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:4e76c5cb1ed229c3c1d51beedad3e7970a29c55d32cfc0500153fded3dc8a1c9_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:908382349b4ba81195c2fdc9e650d304cd868ff94d809414d7e44947f2725e0c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:38a0acf8e97a7d0c6a4c8d6815321e35df6ad35736a7338267ce9b5adb118662_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:8b8f3387a3764beb3d8ad6a027b05f42619ccf33165e733e8dc7b3f135895dc5_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:b338c1060dd859a8747e0812e176ab266d338aea799becd41e48afc50061fb82_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:ba0aebd6b6b6ceb676b6990d5bd9f3b7efe40cedd9407149da92c55435ef7db6_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:1e1215926b9d71cc0131148ad92f4ea8ea8b1e2ba72d6f73396601fceac5ee75_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4cd3b940aa076240f9c7e1fffd05c6bd739a76f31f94d2e4e80ce109fec27206_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4fb0b9f0ab3c37feeace62a178b6abd0e25797cb9ea326c4e1c079ad7791c7a2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:b0b215ef0b00aff4be01e9c7718f92ef0c249782e37ad5fde717d9b76e112a92_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:1a1dc37c6638cf1bbbcdef28032f1e5e847d99566a8b76338376245798fdcf92_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:67a090d14c2859d30419de71d46f85b71d8bfb8ea0f831f103be9a236af1153c_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:6a14d27e13cfc97103437c822cb7becf22d9a6c2fcb94729c977d6d5ffecaa0d_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:eaab16b83d494e162ab01c2476c548907eababda4b20317666f41119467c6890_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:2ee7edad219c94eb91465132570a8180b038c0e1e94e4c20f15ac20388d443a2_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:3e9d56b1c640ac770ef67309529a662c36a24858b4c0d74273e72c6398181cf4_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:bde7602ad25518d0344589c2efe1ff51af32e3070292751cb4a3e1de9788d291_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:ee6cce6ce7461624def1638ac43fbf4cf81a9fc2f88a0729fca1399d19e78820_amd64 —
Workaround
Threats
Impact Important

A flaw was found in Eclipse Vert.x. The `DefaultRedirectHandler` in `vertx-core` improperly handles HTTP 30x redirects by propagating all request headers, including sensitive authentication and session credentials, to cross-origin redirect destinations. An attacker can exploit this by redirecting a Vert.x HttpClient request to a malicious host. This allows the attacker to capture sensitive information such as bearer tokens, basic authentication credentials, session cookies, and API keys, leading to unauthorized access or further attacks.

CWE-346 - Origin Validation Error
Affected products
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:10bcd975f5d03858c30d65f8969391b72a05ff69cdf881de3c27a89272bb39e8_ppc64le —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:99392ab8ee91b46131519490ea92adef817140751f84c5ef421a59369deb04da_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f69a7c87ff903073da4602b2daa377d714117960aacd7e5912b94ae752dfec08_arm64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f7587af345f0bf512627705f8543b8533b0d92fd5e845fc3c6c84094c277cc1e_amd64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:1ad319aa2d1f00c745609246ea315955298a7028afe3fc5502a68c2d1b5c8467_arm64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:29840664ab5a92cebe5aef4ca45e14c558fe92b832a9d2b8ddec426eaed93144_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:4e76c5cb1ed229c3c1d51beedad3e7970a29c55d32cfc0500153fded3dc8a1c9_ppc64le —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:908382349b4ba81195c2fdc9e650d304cd868ff94d809414d7e44947f2725e0c_amd64 —
Vendor Fix fix
Workaround
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:37194dd2cd72d6cdb57ca93fd1cfe6e4aa70ec826a3e86032cde0d0738262bd2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:5fcb1e5c626c5d3aa85e0ec98062a44803d2815871236a3b7541b95078997c78_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:8f84e4d5f4cf71219fbed65092645ded0df00369b42b5487ddef7d0c6cac331b_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:e576efc0fbec5378a870880a7bce40327a86203f2ff426fb62d8c767f125761a_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:5093c89215a4dd74643a2911ce3e3f9e351fda5adf71ee897b7b702840025d47_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:803f8b179959a2b20c71876814b09bae7e5ee15cc2dc0a7e7e1fded75a52fc8c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:af4e4fde13a96dd7fd6126bc67927e1873f12fc3263f749527603e60e75e8f5e_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:bce9235e326ab64aabbe7080ca74cbd24d6f9090819d82d9f2f7abb814e3b26f_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:0a1d01a849daf85556bea32c69dde2621021d28ed33c6f1268375345df1c9409_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:14a9baa0a9f39517264880f36689046f91f4ddadd383de1a28a56468de08c7bd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b2cd6a2da440d20b39571dbee7bd31c49ad7a7411530735c8896ac38e30ce4b3_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b3bba37ab9e9d214ff805510072ea56ea9a2e0bc07c42244bc330dd595befedb_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:08bb9bfbb83303d07932903db066c32bfdd3f2acbffd99b40de60e61ab05175b_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:467c2c6858ff7ea5a2c6dca1bb95638c9bc4f99ebcda932bb3bfc65f82f82155_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:6ec7b2a574f90ee5629cae48ce32544fb429aadbbee22eb88992932e7e80a28a_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:ca56033e3eec4a8fc2432418141f5c76a4c7c52391d14ff023c67f5c315cae39_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:3f4b18a7d40ff1b17e6610ab2e6a79b77e3e9f9026b2d1a77f2892ae3ec7c4a0_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:562e100628a6d9b06f519e8d2a555bdaa43b79e7f30870dc94da9c87dac3fcb6_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:5b96816dc89ecd3b6db02011805a3ed9069f5db86b4158eac8b2f931f0e9532b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:cd0d86c44dc30c77d2876540a75249fbcb0cb1b3ecf4d14394f6eebe2061f9a6_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:d98a5605205445fe1fd9a8f439b09918eb187eef468a0546a911c5ee1d00f851_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:130cf3c00d9042bdc07da56eee755b2682a13f77b9bd445ca9369e7aee9f02cf_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:5f5b25b4cbfa35f731247c948d83f31b100fa99c0126a964fbd46bab9c204b55_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:7f0a8c6cdbc3031e5e0193819310640f115a658ff4883914b1876c9a21dc010a_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:c722c2cdf62c8dc9953dde8a5cb283c3afece2e7925b4213c6cb6afa76004f29_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:188e877e1d78b19fa479d4b2815fc0d48fb8a048274d7f3aa37f5bf7e16523dd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:36779d828279ae8078a29ce39ed42d8311fe40fb13347533e2d0652a23a2324f_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:8e216bcc9a9f70469bbd1b91e94d30e74d6fb8cc650bf2ca562a0aa6e82591f7_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:9889305d3ba264f5e015a58e355840b90807995d2e1fb672e64c42fd4d4f070b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:122bbd2d696d9ac1a98a6d587c4ebb503ae13eac888bd63c48695aeef5a3ec93_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:8e7d83f45214e9841238d396ecf3e89ce4b43910f951136bf9e792b224ab09e7_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:98164a2ff734c7d74b8bf9d55db9aafc2e1922baf8e4146efed21642e022a513_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:af08600dbbfde6a494e4a54ddfaae4f067778412b8bbaa0e0d6ff22018121438_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:560dd6062c5240e73ec60ecc13d402009b01e81ed452b6314c3817a2d116d575_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:61a523a9663ff94b984f06fb72a570a18faf326b5efe6ef7d3ba55f96d4e422f_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:a4f8b673fd049befb193ee8f93ac8167b784cfe35b5de3584b19a95c726d9cff_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:b73b5fef7a238e3a16a0b724a8022588a4f69195743bf489f2bb01e4d3a59113_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:121aee11bc25d5e983808691d3b82905048b5a67ffb01f61c86815867e4e8d08_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:7ba97ebd86b3442cd95ffa2605b7890e2f85731ae84ee696d18bae0633439afe_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:9eccdaac68f3ce6a42a435ceb511483d0f233fb21b3dee8343b8d70cbd67f2ac_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:f74ce43b7d8ade25e5b0f78a41f87db5c6005a85f48cde956b9a87a5892c3a87_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:38a0acf8e97a7d0c6a4c8d6815321e35df6ad35736a7338267ce9b5adb118662_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:8b8f3387a3764beb3d8ad6a027b05f42619ccf33165e733e8dc7b3f135895dc5_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:b338c1060dd859a8747e0812e176ab266d338aea799becd41e48afc50061fb82_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:ba0aebd6b6b6ceb676b6990d5bd9f3b7efe40cedd9407149da92c55435ef7db6_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:1e1215926b9d71cc0131148ad92f4ea8ea8b1e2ba72d6f73396601fceac5ee75_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4cd3b940aa076240f9c7e1fffd05c6bd739a76f31f94d2e4e80ce109fec27206_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4fb0b9f0ab3c37feeace62a178b6abd0e25797cb9ea326c4e1c079ad7791c7a2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:b0b215ef0b00aff4be01e9c7718f92ef0c249782e37ad5fde717d9b76e112a92_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:1a1dc37c6638cf1bbbcdef28032f1e5e847d99566a8b76338376245798fdcf92_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:67a090d14c2859d30419de71d46f85b71d8bfb8ea0f831f103be9a236af1153c_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:6a14d27e13cfc97103437c822cb7becf22d9a6c2fcb94729c977d6d5ffecaa0d_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:eaab16b83d494e162ab01c2476c548907eababda4b20317666f41119467c6890_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:2ee7edad219c94eb91465132570a8180b038c0e1e94e4c20f15ac20388d443a2_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:3e9d56b1c640ac770ef67309529a662c36a24858b4c0d74273e72c6398181cf4_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:bde7602ad25518d0344589c2efe1ff51af32e3070292751cb4a3e1de9788d291_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:ee6cce6ce7461624def1638ac43fbf4cf81a9fc2f88a0729fca1399d19e78820_amd64 —
Workaround
Threats
Impact Important

A flaw was found in Eclipse Vert.x Web Client. The WebClientSession component does not properly validate the Domain attribute of a Set-Cookie response header against the originating server's domain. This vulnerability allows a remote attacker to inject a cookie scoped to an arbitrary third-party domain. When the victim application subsequently sends a request to the targeted domain, the injected cookie is presented, potentially leading to information disclosure and unauthorized access to sensitive data through the attacker's account on that service.

CWE-346 - Origin Validation Error
Affected products
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:1ad319aa2d1f00c745609246ea315955298a7028afe3fc5502a68c2d1b5c8467_arm64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:29840664ab5a92cebe5aef4ca45e14c558fe92b832a9d2b8ddec426eaed93144_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:4e76c5cb1ed229c3c1d51beedad3e7970a29c55d32cfc0500153fded3dc8a1c9_ppc64le —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:908382349b4ba81195c2fdc9e650d304cd868ff94d809414d7e44947f2725e0c_amd64 —
Vendor Fix fix
Workaround
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:37194dd2cd72d6cdb57ca93fd1cfe6e4aa70ec826a3e86032cde0d0738262bd2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:5fcb1e5c626c5d3aa85e0ec98062a44803d2815871236a3b7541b95078997c78_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:8f84e4d5f4cf71219fbed65092645ded0df00369b42b5487ddef7d0c6cac331b_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:e576efc0fbec5378a870880a7bce40327a86203f2ff426fb62d8c767f125761a_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:5093c89215a4dd74643a2911ce3e3f9e351fda5adf71ee897b7b702840025d47_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:803f8b179959a2b20c71876814b09bae7e5ee15cc2dc0a7e7e1fded75a52fc8c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:af4e4fde13a96dd7fd6126bc67927e1873f12fc3263f749527603e60e75e8f5e_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:bce9235e326ab64aabbe7080ca74cbd24d6f9090819d82d9f2f7abb814e3b26f_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:0a1d01a849daf85556bea32c69dde2621021d28ed33c6f1268375345df1c9409_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:14a9baa0a9f39517264880f36689046f91f4ddadd383de1a28a56468de08c7bd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b2cd6a2da440d20b39571dbee7bd31c49ad7a7411530735c8896ac38e30ce4b3_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b3bba37ab9e9d214ff805510072ea56ea9a2e0bc07c42244bc330dd595befedb_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:08bb9bfbb83303d07932903db066c32bfdd3f2acbffd99b40de60e61ab05175b_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:467c2c6858ff7ea5a2c6dca1bb95638c9bc4f99ebcda932bb3bfc65f82f82155_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:6ec7b2a574f90ee5629cae48ce32544fb429aadbbee22eb88992932e7e80a28a_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:ca56033e3eec4a8fc2432418141f5c76a4c7c52391d14ff023c67f5c315cae39_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:3f4b18a7d40ff1b17e6610ab2e6a79b77e3e9f9026b2d1a77f2892ae3ec7c4a0_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:562e100628a6d9b06f519e8d2a555bdaa43b79e7f30870dc94da9c87dac3fcb6_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:5b96816dc89ecd3b6db02011805a3ed9069f5db86b4158eac8b2f931f0e9532b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:cd0d86c44dc30c77d2876540a75249fbcb0cb1b3ecf4d14394f6eebe2061f9a6_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:d98a5605205445fe1fd9a8f439b09918eb187eef468a0546a911c5ee1d00f851_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:130cf3c00d9042bdc07da56eee755b2682a13f77b9bd445ca9369e7aee9f02cf_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:5f5b25b4cbfa35f731247c948d83f31b100fa99c0126a964fbd46bab9c204b55_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:7f0a8c6cdbc3031e5e0193819310640f115a658ff4883914b1876c9a21dc010a_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:c722c2cdf62c8dc9953dde8a5cb283c3afece2e7925b4213c6cb6afa76004f29_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:188e877e1d78b19fa479d4b2815fc0d48fb8a048274d7f3aa37f5bf7e16523dd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:36779d828279ae8078a29ce39ed42d8311fe40fb13347533e2d0652a23a2324f_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:8e216bcc9a9f70469bbd1b91e94d30e74d6fb8cc650bf2ca562a0aa6e82591f7_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:9889305d3ba264f5e015a58e355840b90807995d2e1fb672e64c42fd4d4f070b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:10bcd975f5d03858c30d65f8969391b72a05ff69cdf881de3c27a89272bb39e8_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:99392ab8ee91b46131519490ea92adef817140751f84c5ef421a59369deb04da_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f69a7c87ff903073da4602b2daa377d714117960aacd7e5912b94ae752dfec08_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f7587af345f0bf512627705f8543b8533b0d92fd5e845fc3c6c84094c277cc1e_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:122bbd2d696d9ac1a98a6d587c4ebb503ae13eac888bd63c48695aeef5a3ec93_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:8e7d83f45214e9841238d396ecf3e89ce4b43910f951136bf9e792b224ab09e7_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:98164a2ff734c7d74b8bf9d55db9aafc2e1922baf8e4146efed21642e022a513_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:af08600dbbfde6a494e4a54ddfaae4f067778412b8bbaa0e0d6ff22018121438_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:560dd6062c5240e73ec60ecc13d402009b01e81ed452b6314c3817a2d116d575_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:61a523a9663ff94b984f06fb72a570a18faf326b5efe6ef7d3ba55f96d4e422f_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:a4f8b673fd049befb193ee8f93ac8167b784cfe35b5de3584b19a95c726d9cff_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:b73b5fef7a238e3a16a0b724a8022588a4f69195743bf489f2bb01e4d3a59113_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:121aee11bc25d5e983808691d3b82905048b5a67ffb01f61c86815867e4e8d08_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:7ba97ebd86b3442cd95ffa2605b7890e2f85731ae84ee696d18bae0633439afe_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:9eccdaac68f3ce6a42a435ceb511483d0f233fb21b3dee8343b8d70cbd67f2ac_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:f74ce43b7d8ade25e5b0f78a41f87db5c6005a85f48cde956b9a87a5892c3a87_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:38a0acf8e97a7d0c6a4c8d6815321e35df6ad35736a7338267ce9b5adb118662_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:8b8f3387a3764beb3d8ad6a027b05f42619ccf33165e733e8dc7b3f135895dc5_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:b338c1060dd859a8747e0812e176ab266d338aea799becd41e48afc50061fb82_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:ba0aebd6b6b6ceb676b6990d5bd9f3b7efe40cedd9407149da92c55435ef7db6_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:1e1215926b9d71cc0131148ad92f4ea8ea8b1e2ba72d6f73396601fceac5ee75_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4cd3b940aa076240f9c7e1fffd05c6bd739a76f31f94d2e4e80ce109fec27206_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4fb0b9f0ab3c37feeace62a178b6abd0e25797cb9ea326c4e1c079ad7791c7a2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:b0b215ef0b00aff4be01e9c7718f92ef0c249782e37ad5fde717d9b76e112a92_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:1a1dc37c6638cf1bbbcdef28032f1e5e847d99566a8b76338376245798fdcf92_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:67a090d14c2859d30419de71d46f85b71d8bfb8ea0f831f103be9a236af1153c_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:6a14d27e13cfc97103437c822cb7becf22d9a6c2fcb94729c977d6d5ffecaa0d_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:eaab16b83d494e162ab01c2476c548907eababda4b20317666f41119467c6890_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:2ee7edad219c94eb91465132570a8180b038c0e1e94e4c20f15ac20388d443a2_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:3e9d56b1c640ac770ef67309529a662c36a24858b4c0d74273e72c6398181cf4_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:bde7602ad25518d0344589c2efe1ff51af32e3070292751cb4a3e1de9788d291_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:ee6cce6ce7461624def1638ac43fbf4cf81a9fc2f88a0729fca1399d19e78820_amd64 —
Workaround
Threats
Impact Important

A flaw was found in golang.org/x/net/html. When arbitrary HTML is parsed and then rendered, it can result in an unexpected HTML tree. This allows an attacker to bypass HTML sanitization mechanisms, leading to Cross-Site Scripting (XSS) attacks in applications. Such attacks can result in information disclosure or arbitrary code execution.

CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected products
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:38a0acf8e97a7d0c6a4c8d6815321e35df6ad35736a7338267ce9b5adb118662_amd64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:8b8f3387a3764beb3d8ad6a027b05f42619ccf33165e733e8dc7b3f135895dc5_ppc64le —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:b338c1060dd859a8747e0812e176ab266d338aea799becd41e48afc50061fb82_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:ba0aebd6b6b6ceb676b6990d5bd9f3b7efe40cedd9407149da92c55435ef7db6_arm64 —
Vendor Fix fix
Workaround
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:37194dd2cd72d6cdb57ca93fd1cfe6e4aa70ec826a3e86032cde0d0738262bd2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:5fcb1e5c626c5d3aa85e0ec98062a44803d2815871236a3b7541b95078997c78_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:8f84e4d5f4cf71219fbed65092645ded0df00369b42b5487ddef7d0c6cac331b_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:e576efc0fbec5378a870880a7bce40327a86203f2ff426fb62d8c767f125761a_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:5093c89215a4dd74643a2911ce3e3f9e351fda5adf71ee897b7b702840025d47_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:803f8b179959a2b20c71876814b09bae7e5ee15cc2dc0a7e7e1fded75a52fc8c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:af4e4fde13a96dd7fd6126bc67927e1873f12fc3263f749527603e60e75e8f5e_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:bce9235e326ab64aabbe7080ca74cbd24d6f9090819d82d9f2f7abb814e3b26f_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:0a1d01a849daf85556bea32c69dde2621021d28ed33c6f1268375345df1c9409_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:14a9baa0a9f39517264880f36689046f91f4ddadd383de1a28a56468de08c7bd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b2cd6a2da440d20b39571dbee7bd31c49ad7a7411530735c8896ac38e30ce4b3_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b3bba37ab9e9d214ff805510072ea56ea9a2e0bc07c42244bc330dd595befedb_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:08bb9bfbb83303d07932903db066c32bfdd3f2acbffd99b40de60e61ab05175b_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:467c2c6858ff7ea5a2c6dca1bb95638c9bc4f99ebcda932bb3bfc65f82f82155_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:6ec7b2a574f90ee5629cae48ce32544fb429aadbbee22eb88992932e7e80a28a_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:ca56033e3eec4a8fc2432418141f5c76a4c7c52391d14ff023c67f5c315cae39_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:3f4b18a7d40ff1b17e6610ab2e6a79b77e3e9f9026b2d1a77f2892ae3ec7c4a0_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:562e100628a6d9b06f519e8d2a555bdaa43b79e7f30870dc94da9c87dac3fcb6_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:5b96816dc89ecd3b6db02011805a3ed9069f5db86b4158eac8b2f931f0e9532b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:cd0d86c44dc30c77d2876540a75249fbcb0cb1b3ecf4d14394f6eebe2061f9a6_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:d98a5605205445fe1fd9a8f439b09918eb187eef468a0546a911c5ee1d00f851_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:130cf3c00d9042bdc07da56eee755b2682a13f77b9bd445ca9369e7aee9f02cf_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:5f5b25b4cbfa35f731247c948d83f31b100fa99c0126a964fbd46bab9c204b55_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:7f0a8c6cdbc3031e5e0193819310640f115a658ff4883914b1876c9a21dc010a_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:c722c2cdf62c8dc9953dde8a5cb283c3afece2e7925b4213c6cb6afa76004f29_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:188e877e1d78b19fa479d4b2815fc0d48fb8a048274d7f3aa37f5bf7e16523dd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:36779d828279ae8078a29ce39ed42d8311fe40fb13347533e2d0652a23a2324f_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:8e216bcc9a9f70469bbd1b91e94d30e74d6fb8cc650bf2ca562a0aa6e82591f7_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:9889305d3ba264f5e015a58e355840b90807995d2e1fb672e64c42fd4d4f070b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:10bcd975f5d03858c30d65f8969391b72a05ff69cdf881de3c27a89272bb39e8_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:99392ab8ee91b46131519490ea92adef817140751f84c5ef421a59369deb04da_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f69a7c87ff903073da4602b2daa377d714117960aacd7e5912b94ae752dfec08_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f7587af345f0bf512627705f8543b8533b0d92fd5e845fc3c6c84094c277cc1e_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:122bbd2d696d9ac1a98a6d587c4ebb503ae13eac888bd63c48695aeef5a3ec93_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:8e7d83f45214e9841238d396ecf3e89ce4b43910f951136bf9e792b224ab09e7_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:98164a2ff734c7d74b8bf9d55db9aafc2e1922baf8e4146efed21642e022a513_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:af08600dbbfde6a494e4a54ddfaae4f067778412b8bbaa0e0d6ff22018121438_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:560dd6062c5240e73ec60ecc13d402009b01e81ed452b6314c3817a2d116d575_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:61a523a9663ff94b984f06fb72a570a18faf326b5efe6ef7d3ba55f96d4e422f_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:a4f8b673fd049befb193ee8f93ac8167b784cfe35b5de3584b19a95c726d9cff_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:b73b5fef7a238e3a16a0b724a8022588a4f69195743bf489f2bb01e4d3a59113_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:121aee11bc25d5e983808691d3b82905048b5a67ffb01f61c86815867e4e8d08_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:7ba97ebd86b3442cd95ffa2605b7890e2f85731ae84ee696d18bae0633439afe_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:9eccdaac68f3ce6a42a435ceb511483d0f233fb21b3dee8343b8d70cbd67f2ac_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:f74ce43b7d8ade25e5b0f78a41f87db5c6005a85f48cde956b9a87a5892c3a87_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:1ad319aa2d1f00c745609246ea315955298a7028afe3fc5502a68c2d1b5c8467_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:29840664ab5a92cebe5aef4ca45e14c558fe92b832a9d2b8ddec426eaed93144_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:4e76c5cb1ed229c3c1d51beedad3e7970a29c55d32cfc0500153fded3dc8a1c9_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:908382349b4ba81195c2fdc9e650d304cd868ff94d809414d7e44947f2725e0c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:1e1215926b9d71cc0131148ad92f4ea8ea8b1e2ba72d6f73396601fceac5ee75_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4cd3b940aa076240f9c7e1fffd05c6bd739a76f31f94d2e4e80ce109fec27206_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4fb0b9f0ab3c37feeace62a178b6abd0e25797cb9ea326c4e1c079ad7791c7a2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:b0b215ef0b00aff4be01e9c7718f92ef0c249782e37ad5fde717d9b76e112a92_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:1a1dc37c6638cf1bbbcdef28032f1e5e847d99566a8b76338376245798fdcf92_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:67a090d14c2859d30419de71d46f85b71d8bfb8ea0f831f103be9a236af1153c_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:6a14d27e13cfc97103437c822cb7becf22d9a6c2fcb94729c977d6d5ffecaa0d_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:eaab16b83d494e162ab01c2476c548907eababda4b20317666f41119467c6890_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:2ee7edad219c94eb91465132570a8180b038c0e1e94e4c20f15ac20388d443a2_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:3e9d56b1c640ac770ef67309529a662c36a24858b4c0d74273e72c6398181cf4_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:bde7602ad25518d0344589c2efe1ff51af32e3070292751cb4a3e1de9788d291_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:ee6cce6ce7461624def1638ac43fbf4cf81a9fc2f88a0729fca1399d19e78820_amd64 —
Workaround
Threats
Impact Important

A flaw was found in Go JOSE, a library for handling JSON Web Encryption (JWE) objects. A remote attacker could exploit this vulnerability by providing a specially crafted JWE object. When decrypting such an object, if a key wrapping algorithm is specified but the encrypted key field is empty, the application can crash. This leads to a denial of service (DoS), making the affected service unavailable to legitimate users.

CWE-131 - Incorrect Calculation of Buffer Size
Affected products
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:122bbd2d696d9ac1a98a6d587c4ebb503ae13eac888bd63c48695aeef5a3ec93_ppc64le —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:8e7d83f45214e9841238d396ecf3e89ce4b43910f951136bf9e792b224ab09e7_arm64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:98164a2ff734c7d74b8bf9d55db9aafc2e1922baf8e4146efed21642e022a513_amd64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:af08600dbbfde6a494e4a54ddfaae4f067778412b8bbaa0e0d6ff22018121438_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:38a0acf8e97a7d0c6a4c8d6815321e35df6ad35736a7338267ce9b5adb118662_amd64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:8b8f3387a3764beb3d8ad6a027b05f42619ccf33165e733e8dc7b3f135895dc5_ppc64le —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:b338c1060dd859a8747e0812e176ab266d338aea799becd41e48afc50061fb82_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:ba0aebd6b6b6ceb676b6990d5bd9f3b7efe40cedd9407149da92c55435ef7db6_arm64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:2ee7edad219c94eb91465132570a8180b038c0e1e94e4c20f15ac20388d443a2_arm64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:3e9d56b1c640ac770ef67309529a662c36a24858b4c0d74273e72c6398181cf4_ppc64le —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:bde7602ad25518d0344589c2efe1ff51af32e3070292751cb4a3e1de9788d291_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:ee6cce6ce7461624def1638ac43fbf4cf81a9fc2f88a0729fca1399d19e78820_amd64 —
Vendor Fix fix
Workaround
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:37194dd2cd72d6cdb57ca93fd1cfe6e4aa70ec826a3e86032cde0d0738262bd2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:5fcb1e5c626c5d3aa85e0ec98062a44803d2815871236a3b7541b95078997c78_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:8f84e4d5f4cf71219fbed65092645ded0df00369b42b5487ddef7d0c6cac331b_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:e576efc0fbec5378a870880a7bce40327a86203f2ff426fb62d8c767f125761a_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:5093c89215a4dd74643a2911ce3e3f9e351fda5adf71ee897b7b702840025d47_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:803f8b179959a2b20c71876814b09bae7e5ee15cc2dc0a7e7e1fded75a52fc8c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:af4e4fde13a96dd7fd6126bc67927e1873f12fc3263f749527603e60e75e8f5e_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:bce9235e326ab64aabbe7080ca74cbd24d6f9090819d82d9f2f7abb814e3b26f_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:0a1d01a849daf85556bea32c69dde2621021d28ed33c6f1268375345df1c9409_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:14a9baa0a9f39517264880f36689046f91f4ddadd383de1a28a56468de08c7bd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b2cd6a2da440d20b39571dbee7bd31c49ad7a7411530735c8896ac38e30ce4b3_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b3bba37ab9e9d214ff805510072ea56ea9a2e0bc07c42244bc330dd595befedb_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:08bb9bfbb83303d07932903db066c32bfdd3f2acbffd99b40de60e61ab05175b_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:467c2c6858ff7ea5a2c6dca1bb95638c9bc4f99ebcda932bb3bfc65f82f82155_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:6ec7b2a574f90ee5629cae48ce32544fb429aadbbee22eb88992932e7e80a28a_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:ca56033e3eec4a8fc2432418141f5c76a4c7c52391d14ff023c67f5c315cae39_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:3f4b18a7d40ff1b17e6610ab2e6a79b77e3e9f9026b2d1a77f2892ae3ec7c4a0_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:562e100628a6d9b06f519e8d2a555bdaa43b79e7f30870dc94da9c87dac3fcb6_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:5b96816dc89ecd3b6db02011805a3ed9069f5db86b4158eac8b2f931f0e9532b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:cd0d86c44dc30c77d2876540a75249fbcb0cb1b3ecf4d14394f6eebe2061f9a6_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:d98a5605205445fe1fd9a8f439b09918eb187eef468a0546a911c5ee1d00f851_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:130cf3c00d9042bdc07da56eee755b2682a13f77b9bd445ca9369e7aee9f02cf_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:5f5b25b4cbfa35f731247c948d83f31b100fa99c0126a964fbd46bab9c204b55_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:7f0a8c6cdbc3031e5e0193819310640f115a658ff4883914b1876c9a21dc010a_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:c722c2cdf62c8dc9953dde8a5cb283c3afece2e7925b4213c6cb6afa76004f29_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:188e877e1d78b19fa479d4b2815fc0d48fb8a048274d7f3aa37f5bf7e16523dd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:36779d828279ae8078a29ce39ed42d8311fe40fb13347533e2d0652a23a2324f_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:8e216bcc9a9f70469bbd1b91e94d30e74d6fb8cc650bf2ca562a0aa6e82591f7_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:9889305d3ba264f5e015a58e355840b90807995d2e1fb672e64c42fd4d4f070b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:10bcd975f5d03858c30d65f8969391b72a05ff69cdf881de3c27a89272bb39e8_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:99392ab8ee91b46131519490ea92adef817140751f84c5ef421a59369deb04da_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f69a7c87ff903073da4602b2daa377d714117960aacd7e5912b94ae752dfec08_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f7587af345f0bf512627705f8543b8533b0d92fd5e845fc3c6c84094c277cc1e_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:560dd6062c5240e73ec60ecc13d402009b01e81ed452b6314c3817a2d116d575_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:61a523a9663ff94b984f06fb72a570a18faf326b5efe6ef7d3ba55f96d4e422f_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:a4f8b673fd049befb193ee8f93ac8167b784cfe35b5de3584b19a95c726d9cff_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:b73b5fef7a238e3a16a0b724a8022588a4f69195743bf489f2bb01e4d3a59113_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:121aee11bc25d5e983808691d3b82905048b5a67ffb01f61c86815867e4e8d08_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:7ba97ebd86b3442cd95ffa2605b7890e2f85731ae84ee696d18bae0633439afe_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:9eccdaac68f3ce6a42a435ceb511483d0f233fb21b3dee8343b8d70cbd67f2ac_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:f74ce43b7d8ade25e5b0f78a41f87db5c6005a85f48cde956b9a87a5892c3a87_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:1ad319aa2d1f00c745609246ea315955298a7028afe3fc5502a68c2d1b5c8467_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:29840664ab5a92cebe5aef4ca45e14c558fe92b832a9d2b8ddec426eaed93144_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:4e76c5cb1ed229c3c1d51beedad3e7970a29c55d32cfc0500153fded3dc8a1c9_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:908382349b4ba81195c2fdc9e650d304cd868ff94d809414d7e44947f2725e0c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:1e1215926b9d71cc0131148ad92f4ea8ea8b1e2ba72d6f73396601fceac5ee75_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4cd3b940aa076240f9c7e1fffd05c6bd739a76f31f94d2e4e80ce109fec27206_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4fb0b9f0ab3c37feeace62a178b6abd0e25797cb9ea326c4e1c079ad7791c7a2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:b0b215ef0b00aff4be01e9c7718f92ef0c249782e37ad5fde717d9b76e112a92_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:1a1dc37c6638cf1bbbcdef28032f1e5e847d99566a8b76338376245798fdcf92_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:67a090d14c2859d30419de71d46f85b71d8bfb8ea0f831f103be9a236af1153c_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:6a14d27e13cfc97103437c822cb7becf22d9a6c2fcb94729c977d6d5ffecaa0d_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:eaab16b83d494e162ab01c2476c548907eababda4b20317666f41119467c6890_ppc64le —
Workaround
Threats
Impact Important

A flaw was found in the `net/mail` package of the Go programming language. An attacker could provide specially crafted inputs to the `ParseAddress`, `ParseAddressList`, or `ParseDate` functions. This could lead to excessive consumption of CPU and memory resources, resulting in a Denial of Service (DoS) for applications processing these inputs.

CWE-606 - Unchecked Input for Loop Condition
Affected products
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:0a1d01a849daf85556bea32c69dde2621021d28ed33c6f1268375345df1c9409_ppc64le —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:14a9baa0a9f39517264880f36689046f91f4ddadd383de1a28a56468de08c7bd_amd64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b2cd6a2da440d20b39571dbee7bd31c49ad7a7411530735c8896ac38e30ce4b3_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b3bba37ab9e9d214ff805510072ea56ea9a2e0bc07c42244bc330dd595befedb_arm64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:38a0acf8e97a7d0c6a4c8d6815321e35df6ad35736a7338267ce9b5adb118662_amd64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:8b8f3387a3764beb3d8ad6a027b05f42619ccf33165e733e8dc7b3f135895dc5_ppc64le —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:b338c1060dd859a8747e0812e176ab266d338aea799becd41e48afc50061fb82_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:ba0aebd6b6b6ceb676b6990d5bd9f3b7efe40cedd9407149da92c55435ef7db6_arm64 —
Vendor Fix fix
Workaround
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:37194dd2cd72d6cdb57ca93fd1cfe6e4aa70ec826a3e86032cde0d0738262bd2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:5fcb1e5c626c5d3aa85e0ec98062a44803d2815871236a3b7541b95078997c78_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:8f84e4d5f4cf71219fbed65092645ded0df00369b42b5487ddef7d0c6cac331b_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:e576efc0fbec5378a870880a7bce40327a86203f2ff426fb62d8c767f125761a_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:5093c89215a4dd74643a2911ce3e3f9e351fda5adf71ee897b7b702840025d47_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:803f8b179959a2b20c71876814b09bae7e5ee15cc2dc0a7e7e1fded75a52fc8c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:af4e4fde13a96dd7fd6126bc67927e1873f12fc3263f749527603e60e75e8f5e_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:bce9235e326ab64aabbe7080ca74cbd24d6f9090819d82d9f2f7abb814e3b26f_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:08bb9bfbb83303d07932903db066c32bfdd3f2acbffd99b40de60e61ab05175b_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:467c2c6858ff7ea5a2c6dca1bb95638c9bc4f99ebcda932bb3bfc65f82f82155_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:6ec7b2a574f90ee5629cae48ce32544fb429aadbbee22eb88992932e7e80a28a_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:ca56033e3eec4a8fc2432418141f5c76a4c7c52391d14ff023c67f5c315cae39_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:3f4b18a7d40ff1b17e6610ab2e6a79b77e3e9f9026b2d1a77f2892ae3ec7c4a0_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:562e100628a6d9b06f519e8d2a555bdaa43b79e7f30870dc94da9c87dac3fcb6_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:5b96816dc89ecd3b6db02011805a3ed9069f5db86b4158eac8b2f931f0e9532b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:cd0d86c44dc30c77d2876540a75249fbcb0cb1b3ecf4d14394f6eebe2061f9a6_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:d98a5605205445fe1fd9a8f439b09918eb187eef468a0546a911c5ee1d00f851_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:130cf3c00d9042bdc07da56eee755b2682a13f77b9bd445ca9369e7aee9f02cf_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:5f5b25b4cbfa35f731247c948d83f31b100fa99c0126a964fbd46bab9c204b55_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:7f0a8c6cdbc3031e5e0193819310640f115a658ff4883914b1876c9a21dc010a_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:c722c2cdf62c8dc9953dde8a5cb283c3afece2e7925b4213c6cb6afa76004f29_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:188e877e1d78b19fa479d4b2815fc0d48fb8a048274d7f3aa37f5bf7e16523dd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:36779d828279ae8078a29ce39ed42d8311fe40fb13347533e2d0652a23a2324f_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:8e216bcc9a9f70469bbd1b91e94d30e74d6fb8cc650bf2ca562a0aa6e82591f7_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:9889305d3ba264f5e015a58e355840b90807995d2e1fb672e64c42fd4d4f070b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:10bcd975f5d03858c30d65f8969391b72a05ff69cdf881de3c27a89272bb39e8_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:99392ab8ee91b46131519490ea92adef817140751f84c5ef421a59369deb04da_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f69a7c87ff903073da4602b2daa377d714117960aacd7e5912b94ae752dfec08_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f7587af345f0bf512627705f8543b8533b0d92fd5e845fc3c6c84094c277cc1e_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:122bbd2d696d9ac1a98a6d587c4ebb503ae13eac888bd63c48695aeef5a3ec93_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:8e7d83f45214e9841238d396ecf3e89ce4b43910f951136bf9e792b224ab09e7_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:98164a2ff734c7d74b8bf9d55db9aafc2e1922baf8e4146efed21642e022a513_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:af08600dbbfde6a494e4a54ddfaae4f067778412b8bbaa0e0d6ff22018121438_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:560dd6062c5240e73ec60ecc13d402009b01e81ed452b6314c3817a2d116d575_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:61a523a9663ff94b984f06fb72a570a18faf326b5efe6ef7d3ba55f96d4e422f_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:a4f8b673fd049befb193ee8f93ac8167b784cfe35b5de3584b19a95c726d9cff_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:b73b5fef7a238e3a16a0b724a8022588a4f69195743bf489f2bb01e4d3a59113_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:121aee11bc25d5e983808691d3b82905048b5a67ffb01f61c86815867e4e8d08_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:7ba97ebd86b3442cd95ffa2605b7890e2f85731ae84ee696d18bae0633439afe_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:9eccdaac68f3ce6a42a435ceb511483d0f233fb21b3dee8343b8d70cbd67f2ac_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:f74ce43b7d8ade25e5b0f78a41f87db5c6005a85f48cde956b9a87a5892c3a87_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:1ad319aa2d1f00c745609246ea315955298a7028afe3fc5502a68c2d1b5c8467_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:29840664ab5a92cebe5aef4ca45e14c558fe92b832a9d2b8ddec426eaed93144_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:4e76c5cb1ed229c3c1d51beedad3e7970a29c55d32cfc0500153fded3dc8a1c9_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:908382349b4ba81195c2fdc9e650d304cd868ff94d809414d7e44947f2725e0c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:1e1215926b9d71cc0131148ad92f4ea8ea8b1e2ba72d6f73396601fceac5ee75_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4cd3b940aa076240f9c7e1fffd05c6bd739a76f31f94d2e4e80ce109fec27206_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4fb0b9f0ab3c37feeace62a178b6abd0e25797cb9ea326c4e1c079ad7791c7a2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:b0b215ef0b00aff4be01e9c7718f92ef0c249782e37ad5fde717d9b76e112a92_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:1a1dc37c6638cf1bbbcdef28032f1e5e847d99566a8b76338376245798fdcf92_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:67a090d14c2859d30419de71d46f85b71d8bfb8ea0f831f103be9a236af1153c_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:6a14d27e13cfc97103437c822cb7becf22d9a6c2fcb94729c977d6d5ffecaa0d_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:eaab16b83d494e162ab01c2476c548907eababda4b20317666f41119467c6890_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:2ee7edad219c94eb91465132570a8180b038c0e1e94e4c20f15ac20388d443a2_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:3e9d56b1c640ac770ef67309529a662c36a24858b4c0d74273e72c6398181cf4_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:bde7602ad25518d0344589c2efe1ff51af32e3070292751cb4a3e1de9788d291_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:ee6cce6ce7461624def1638ac43fbf4cf81a9fc2f88a0729fca1399d19e78820_amd64 —
Workaround
Threats
Impact Important

A flaw was found in golang.org/x/crypto/ssh. The Verify() method, responsible for FIDO/U2F security key types, did not properly check for user presence. This allowed signatures to be accepted without requiring a physical touch on the hardware security key. As a result, an attacker could potentially use a hardware security key in an unattended manner, bypassing a critical security control designed to ensure user intent.

CWE-347 - Improper Verification of Cryptographic Signature
Affected products
Fixed 4 products, the same list as for CVE-2026-27136
Known not affected 61 products, the same list as for CVE-2026-27136
Threats
Impact Important

A flaw was found in golang.org/x/crypto/ssh. SSH servers configured to use CertChecker as a public key callback, without explicitly setting IsUserAuthority or IsHostAuthority, are vulnerable. A remote attacker can exploit this by presenting a specially crafted certificate, causing the server to panic and resulting in a Denial of Service (DoS).

CWE-476 - NULL Pointer Dereference
Affected products
Fixed 4 products, the same list as for CVE-2026-27136
Known not affected 61 products, the same list as for CVE-2026-27136
Threats
Impact Important

A flaw was found in quic-go, an implementation of the QUIC protocol in Go. A remote attacker can exploit this by sending specially crafted HTTP/3 trailer fields. This can cause the system to allocate excessive memory, leading to a denial-of-service (DoS) condition where the affected server or client may crash or run out of resources.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 4 products, the same list as for CVE-2026-27136
Known not affected 61 products, the same list as for CVE-2026-27136
Threats
Impact Important

A flaw was found in Micrometer. A remote attacker can provide specially crafted gRPC (gRPC Remote Procedure Call) requests, which may lead to a denial-of-service (DoS) condition. This vulnerability allows an attacker to disrupt the availability of the affected system.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Important

A flaw was found in Micrometer. A remote attacker can provide specially crafted HTTP requests, which may lead to a denial-of-service (DoS) condition. This vulnerability allows an attacker to disrupt the availability of the affected system.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Important

A flaw was found in protobufjs, a JavaScript (JS) library used for compiling protobuf definitions. A remote attacker with low privileges can exploit this vulnerability by injecting arbitrary code into the "type" fields of protobuf definitions. This malicious code will then execute during the object decoding process, leading to arbitrary code execution and potentially full system compromise.

CWE-94 - Improper Control of Generation of Code ('Code Injection')
Affected products
Fixed 4 products, the same list as for CVE-2026-8286
Known not affected 61 products, the same list as for CVE-2026-8286
Threats
Impact Important

A flaw was found in Spring Data Commons. A remote attacker can exploit this vulnerability by providing specially crafted property path strings to the MappingContext property path resolution. This can lead to resource exhaustion, resulting in a denial of service (DoS) for affected applications.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Important

A flaw was found in Spring Data Commons. An attacker can exploit this vulnerability by sending repeated requests with specially crafted strings, which are then permanently retained in the internal property-lookup cache. This can lead to heap exhaustion, resulting in a Denial of Service (DoS) for the affected system.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Important

A flaw was found in Axios, a widely used HTTP client. This vulnerability, known as prototype pollution, allows an attacker to inject malicious properties into core JavaScript objects. When another component in the same application environment is compromised and pollutes the system's object prototype, Axios can unknowingly use these manipulated values in its outbound network requests. This could lead to the disclosure of sensitive information or the alteration of network communications, compromising data confidentiality and integrity.

CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
Affected products
Fixed 4 products, the same list as for CVE-2026-8286
Known not affected 61 products, the same list as for CVE-2026-8286
Threats
Impact Important

A flaw was found in the `net/mail` package within the Go standard library. A remote attacker could provide specially crafted, pathological email addresses. When these malformed email addresses are parsed by the `consumePhrase` function, it can lead to excessive resource consumption due to quadratic string concatenation, resulting in a Denial of Service (DoS) condition.

CWE-1046 - Creation of Immutable Text Using String Concatenation
Affected products
Fixed 8 products, the same list as for CVE-2026-39820
Known not affected 57 products, the same list as for CVE-2026-39820
Threats
Impact Important

A flaw was found in tmp, a temporary file and directory creator for Node.js. This path traversal vulnerability allows an attacker to escape the intended temporary directory. By providing specially crafted input to the prefix, postfix or dir options, an attacker can create files outside the designated temporary directory. This could lead to unauthorized file creation at attacker-controlled locations with the privileges of the running process.

CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected products
Fixed 12 products, the same list as for CVE-2026-13149
Known not affected 53 products, the same list as for CVE-2026-13149
Threats
Impact Important

A flaw was found in the brace-expansion library. This vulnerability allows an attacker to cause a Denial of Service (DoS) by providing a large numeric range for expansion. The library allocates excessive memory to generate all intermediate elements before applying the maximum limit, leading to high memory consumption and potential application crashes. This can impact the availability of systems using the library.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Moderate

A flaw was found in Netty, a network application framework. A remote attacker can exploit this vulnerability by sending a crafted TLS (Transport Layer Security) ClientHello message. This can lead to an eager allocation of a large memory buffer, causing a Denial of Service (DoS) due to excessive memory consumption. The issue occurs in the `SslClientHelloHandler.decode()` method when processing the TLS handshake length.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Important

A flaw was found in PostCSS, a tool that processes CSS files. An attacker who provides specially crafted CSS input containing a malicious source map comment can cause the system to read arbitrary files from the local filesystem. This can lead to the disclosure of sensitive information, specifically the first few bytes of file content. Additionally, this vulnerability may be exploited to cause a Denial of Service (DoS) by targeting large files, making the system unavailable.

CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected products
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:560dd6062c5240e73ec60ecc13d402009b01e81ed452b6314c3817a2d116d575_amd64 —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:61a523a9663ff94b984f06fb72a570a18faf326b5efe6ef7d3ba55f96d4e422f_ppc64le —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:a4f8b673fd049befb193ee8f93ac8167b784cfe35b5de3584b19a95c726d9cff_s390x —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:b73b5fef7a238e3a16a0b724a8022588a4f69195743bf489f2bb01e4d3a59113_arm64 —
Vendor Fix fix
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:37194dd2cd72d6cdb57ca93fd1cfe6e4aa70ec826a3e86032cde0d0738262bd2_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:5fcb1e5c626c5d3aa85e0ec98062a44803d2815871236a3b7541b95078997c78_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:8f84e4d5f4cf71219fbed65092645ded0df00369b42b5487ddef7d0c6cac331b_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:e576efc0fbec5378a870880a7bce40327a86203f2ff426fb62d8c767f125761a_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:5093c89215a4dd74643a2911ce3e3f9e351fda5adf71ee897b7b702840025d47_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:803f8b179959a2b20c71876814b09bae7e5ee15cc2dc0a7e7e1fded75a52fc8c_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:af4e4fde13a96dd7fd6126bc67927e1873f12fc3263f749527603e60e75e8f5e_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:bce9235e326ab64aabbe7080ca74cbd24d6f9090819d82d9f2f7abb814e3b26f_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:0a1d01a849daf85556bea32c69dde2621021d28ed33c6f1268375345df1c9409_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:14a9baa0a9f39517264880f36689046f91f4ddadd383de1a28a56468de08c7bd_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b2cd6a2da440d20b39571dbee7bd31c49ad7a7411530735c8896ac38e30ce4b3_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b3bba37ab9e9d214ff805510072ea56ea9a2e0bc07c42244bc330dd595befedb_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:08bb9bfbb83303d07932903db066c32bfdd3f2acbffd99b40de60e61ab05175b_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:467c2c6858ff7ea5a2c6dca1bb95638c9bc4f99ebcda932bb3bfc65f82f82155_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:6ec7b2a574f90ee5629cae48ce32544fb429aadbbee22eb88992932e7e80a28a_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:ca56033e3eec4a8fc2432418141f5c76a4c7c52391d14ff023c67f5c315cae39_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:3f4b18a7d40ff1b17e6610ab2e6a79b77e3e9f9026b2d1a77f2892ae3ec7c4a0_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:562e100628a6d9b06f519e8d2a555bdaa43b79e7f30870dc94da9c87dac3fcb6_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:5b96816dc89ecd3b6db02011805a3ed9069f5db86b4158eac8b2f931f0e9532b_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:cd0d86c44dc30c77d2876540a75249fbcb0cb1b3ecf4d14394f6eebe2061f9a6_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:d98a5605205445fe1fd9a8f439b09918eb187eef468a0546a911c5ee1d00f851_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:130cf3c00d9042bdc07da56eee755b2682a13f77b9bd445ca9369e7aee9f02cf_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:5f5b25b4cbfa35f731247c948d83f31b100fa99c0126a964fbd46bab9c204b55_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:7f0a8c6cdbc3031e5e0193819310640f115a658ff4883914b1876c9a21dc010a_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:c722c2cdf62c8dc9953dde8a5cb283c3afece2e7925b4213c6cb6afa76004f29_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:188e877e1d78b19fa479d4b2815fc0d48fb8a048274d7f3aa37f5bf7e16523dd_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:36779d828279ae8078a29ce39ed42d8311fe40fb13347533e2d0652a23a2324f_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:8e216bcc9a9f70469bbd1b91e94d30e74d6fb8cc650bf2ca562a0aa6e82591f7_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:9889305d3ba264f5e015a58e355840b90807995d2e1fb672e64c42fd4d4f070b_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:10bcd975f5d03858c30d65f8969391b72a05ff69cdf881de3c27a89272bb39e8_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:99392ab8ee91b46131519490ea92adef817140751f84c5ef421a59369deb04da_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f69a7c87ff903073da4602b2daa377d714117960aacd7e5912b94ae752dfec08_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f7587af345f0bf512627705f8543b8533b0d92fd5e845fc3c6c84094c277cc1e_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:122bbd2d696d9ac1a98a6d587c4ebb503ae13eac888bd63c48695aeef5a3ec93_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:8e7d83f45214e9841238d396ecf3e89ce4b43910f951136bf9e792b224ab09e7_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:98164a2ff734c7d74b8bf9d55db9aafc2e1922baf8e4146efed21642e022a513_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:af08600dbbfde6a494e4a54ddfaae4f067778412b8bbaa0e0d6ff22018121438_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:121aee11bc25d5e983808691d3b82905048b5a67ffb01f61c86815867e4e8d08_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:7ba97ebd86b3442cd95ffa2605b7890e2f85731ae84ee696d18bae0633439afe_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:9eccdaac68f3ce6a42a435ceb511483d0f233fb21b3dee8343b8d70cbd67f2ac_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:f74ce43b7d8ade25e5b0f78a41f87db5c6005a85f48cde956b9a87a5892c3a87_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:1ad319aa2d1f00c745609246ea315955298a7028afe3fc5502a68c2d1b5c8467_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:29840664ab5a92cebe5aef4ca45e14c558fe92b832a9d2b8ddec426eaed93144_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:4e76c5cb1ed229c3c1d51beedad3e7970a29c55d32cfc0500153fded3dc8a1c9_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:908382349b4ba81195c2fdc9e650d304cd868ff94d809414d7e44947f2725e0c_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:38a0acf8e97a7d0c6a4c8d6815321e35df6ad35736a7338267ce9b5adb118662_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:8b8f3387a3764beb3d8ad6a027b05f42619ccf33165e733e8dc7b3f135895dc5_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:b338c1060dd859a8747e0812e176ab266d338aea799becd41e48afc50061fb82_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:ba0aebd6b6b6ceb676b6990d5bd9f3b7efe40cedd9407149da92c55435ef7db6_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:1e1215926b9d71cc0131148ad92f4ea8ea8b1e2ba72d6f73396601fceac5ee75_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4cd3b940aa076240f9c7e1fffd05c6bd739a76f31f94d2e4e80ce109fec27206_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4fb0b9f0ab3c37feeace62a178b6abd0e25797cb9ea326c4e1c079ad7791c7a2_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:b0b215ef0b00aff4be01e9c7718f92ef0c249782e37ad5fde717d9b76e112a92_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:1a1dc37c6638cf1bbbcdef28032f1e5e847d99566a8b76338376245798fdcf92_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:67a090d14c2859d30419de71d46f85b71d8bfb8ea0f831f103be9a236af1153c_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:6a14d27e13cfc97103437c822cb7becf22d9a6c2fcb94729c977d6d5ffecaa0d_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:eaab16b83d494e162ab01c2476c548907eababda4b20317666f41119467c6890_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:2ee7edad219c94eb91465132570a8180b038c0e1e94e4c20f15ac20388d443a2_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:3e9d56b1c640ac770ef67309529a662c36a24858b4c0d74273e72c6398181cf4_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:bde7602ad25518d0344589c2efe1ff51af32e3070292751cb4a3e1de9788d291_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:ee6cce6ce7461624def1638ac43fbf4cf81a9fc2f88a0729fca1399d19e78820_amd64 —
Threats
Impact Moderate

A flaw was found in Netty's DnsResolveContext. This vulnerability allows a remote attacker to achieve information disclosure or data manipulation by crafting malicious DNS responses. The flaw occurs because the DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses, which could enable an attacker to redirect network traffic or intercept sensitive data from affected applications.

CWE-346 - Origin Validation Error
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Important

A flaw was found in golang.org/x/crypto/ssh. A remote attacker could send specially crafted inputs to the AES-GCM packet decoder. This could lead to an incorrectly placed cast from bytes to an integer, causing a server-side panic and resulting in a Denial of Service (DoS) for the affected system.

CWE-681 - Incorrect Conversion between Numeric Types
Affected products
Fixed 4 products, the same list as for CVE-2026-27136
Known not affected 61 products, the same list as for CVE-2026-27136
Threats
Impact Important

A flaw was found in the `@nevware21/ts-utils` library. This vulnerability allows a remote attacker to manipulate the fundamental properties of objects within an application. By exploiting this, an attacker could potentially execute unauthorized code, leading to a complete compromise of the application.

CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
Affected products
Fixed 4 products, the same list as for CVE-2026-8286
Known not affected 61 products, the same list as for CVE-2026-8286
Threats
Impact Important

A flaw was found in Netty's `DnsResolveContext`. An attacker controlling an authoritative name server for a subdomain can exploit this vulnerability by providing crafted NS records that are insufficiently validated. This allows the attacker to poison the DNS cache for parent domains, bypassing standard bailiwick rules. Consequently, future DNS resolutions for the affected parent domain will use the poisoned cache, potentially redirecting users to malicious servers and leading to information disclosure or integrity compromise.

CWE-346 - Origin Validation Error
Affected products
Fixed 4 products, the same list as for CVE-2025-55163
Known not affected 61 products, the same list as for CVE-2025-55163
Threats
Impact Important

A flaw was found in Traefik, an HTTP reverse proxy and load balancer. This vulnerability exists in the StripPrefix middleware, allowing an unauthenticated attacker to bypass route-level authentication and authorization. By crafting a request path containing '..' or its percent-encoded form, an attacker can access protected backend paths, such as administrative or internal configuration endpoints, without proper authentication. This could lead to unauthorized information disclosure or modification of sensitive settings.

CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected products
Fixed 4 products, the same list as for CVE-2026-27136
Known not affected 61 products, the same list as for CVE-2026-27136
Threats
Impact Important

A flaw was found in @grpc/grpc-js, a pure JavaScript gRPC client and server library. An invalid incoming HTTP/2 stream initiation can cause a server process to crash. This vulnerability affects all servers created using @grpc/grpc-js, and no workaround is available. An unauthenticated remote attacker can exploit this to cause a denial of service by sending a malformed HTTP/2 stream to a gRPC server.

CWE-248 - Uncaught Exception
Affected products
Fixed 4 products, the same list as for CVE-2026-8286
Known not affected 61 products, the same list as for CVE-2026-8286
Threats
Impact Important

A flaw was found in Traefik, an HTTP reverse proxy and load balancer. This vulnerability allows an unauthenticated client to bypass mutual Transport Layer Security (TLS) enforcement, a security measure that verifies both client and server identities. The bypass occurs due to an issue in Traefik's domain-fronting protection (SNICheck), which incorrectly processes TLS options for HTTP Host headers. As a result, an attacker can gain unauthorized access to protected backend services without presenting a required client certificate.

CWE-807 - Reliance on Untrusted Inputs in a Security Decision
Affected products
Fixed 4 products, the same list as for CVE-2026-27136
Known not affected 61 products, the same list as for CVE-2026-27136
Threats
Impact Important

A flaw was found in DOMPurify, a tool designed to sanitize HTML, MathML, and SVG to prevent cross-site scripting (XSS) attacks. When performing in-place sanitization, DOMPurify could fail to properly process content within shadow DOM elements attached to a `<template>.content`. This oversight allows an attacker to embed malicious code, such as JavaScript, which could then execute when the sanitized template is used by an application, potentially leading to unauthorized actions or information disclosure.

CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected products
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:37194dd2cd72d6cdb57ca93fd1cfe6e4aa70ec826a3e86032cde0d0738262bd2_ppc64le —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:5fcb1e5c626c5d3aa85e0ec98062a44803d2815871236a3b7541b95078997c78_s390x —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:8f84e4d5f4cf71219fbed65092645ded0df00369b42b5487ddef7d0c6cac331b_amd64 —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:e576efc0fbec5378a870880a7bce40327a86203f2ff426fb62d8c767f125761a_arm64 —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:560dd6062c5240e73ec60ecc13d402009b01e81ed452b6314c3817a2d116d575_amd64 —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:61a523a9663ff94b984f06fb72a570a18faf326b5efe6ef7d3ba55f96d4e422f_ppc64le —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:a4f8b673fd049befb193ee8f93ac8167b784cfe35b5de3584b19a95c726d9cff_s390x —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:b73b5fef7a238e3a16a0b724a8022588a4f69195743bf489f2bb01e4d3a59113_arm64 —
Vendor Fix fix
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:5093c89215a4dd74643a2911ce3e3f9e351fda5adf71ee897b7b702840025d47_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:803f8b179959a2b20c71876814b09bae7e5ee15cc2dc0a7e7e1fded75a52fc8c_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:af4e4fde13a96dd7fd6126bc67927e1873f12fc3263f749527603e60e75e8f5e_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:bce9235e326ab64aabbe7080ca74cbd24d6f9090819d82d9f2f7abb814e3b26f_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:0a1d01a849daf85556bea32c69dde2621021d28ed33c6f1268375345df1c9409_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:14a9baa0a9f39517264880f36689046f91f4ddadd383de1a28a56468de08c7bd_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b2cd6a2da440d20b39571dbee7bd31c49ad7a7411530735c8896ac38e30ce4b3_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b3bba37ab9e9d214ff805510072ea56ea9a2e0bc07c42244bc330dd595befedb_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:08bb9bfbb83303d07932903db066c32bfdd3f2acbffd99b40de60e61ab05175b_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:467c2c6858ff7ea5a2c6dca1bb95638c9bc4f99ebcda932bb3bfc65f82f82155_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:6ec7b2a574f90ee5629cae48ce32544fb429aadbbee22eb88992932e7e80a28a_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:ca56033e3eec4a8fc2432418141f5c76a4c7c52391d14ff023c67f5c315cae39_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:3f4b18a7d40ff1b17e6610ab2e6a79b77e3e9f9026b2d1a77f2892ae3ec7c4a0_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:562e100628a6d9b06f519e8d2a555bdaa43b79e7f30870dc94da9c87dac3fcb6_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:5b96816dc89ecd3b6db02011805a3ed9069f5db86b4158eac8b2f931f0e9532b_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:cd0d86c44dc30c77d2876540a75249fbcb0cb1b3ecf4d14394f6eebe2061f9a6_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:d98a5605205445fe1fd9a8f439b09918eb187eef468a0546a911c5ee1d00f851_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:130cf3c00d9042bdc07da56eee755b2682a13f77b9bd445ca9369e7aee9f02cf_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:5f5b25b4cbfa35f731247c948d83f31b100fa99c0126a964fbd46bab9c204b55_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:7f0a8c6cdbc3031e5e0193819310640f115a658ff4883914b1876c9a21dc010a_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:c722c2cdf62c8dc9953dde8a5cb283c3afece2e7925b4213c6cb6afa76004f29_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:188e877e1d78b19fa479d4b2815fc0d48fb8a048274d7f3aa37f5bf7e16523dd_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:36779d828279ae8078a29ce39ed42d8311fe40fb13347533e2d0652a23a2324f_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:8e216bcc9a9f70469bbd1b91e94d30e74d6fb8cc650bf2ca562a0aa6e82591f7_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:9889305d3ba264f5e015a58e355840b90807995d2e1fb672e64c42fd4d4f070b_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:10bcd975f5d03858c30d65f8969391b72a05ff69cdf881de3c27a89272bb39e8_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:99392ab8ee91b46131519490ea92adef817140751f84c5ef421a59369deb04da_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f69a7c87ff903073da4602b2daa377d714117960aacd7e5912b94ae752dfec08_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f7587af345f0bf512627705f8543b8533b0d92fd5e845fc3c6c84094c277cc1e_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:122bbd2d696d9ac1a98a6d587c4ebb503ae13eac888bd63c48695aeef5a3ec93_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:8e7d83f45214e9841238d396ecf3e89ce4b43910f951136bf9e792b224ab09e7_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:98164a2ff734c7d74b8bf9d55db9aafc2e1922baf8e4146efed21642e022a513_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:af08600dbbfde6a494e4a54ddfaae4f067778412b8bbaa0e0d6ff22018121438_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:121aee11bc25d5e983808691d3b82905048b5a67ffb01f61c86815867e4e8d08_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:7ba97ebd86b3442cd95ffa2605b7890e2f85731ae84ee696d18bae0633439afe_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:9eccdaac68f3ce6a42a435ceb511483d0f233fb21b3dee8343b8d70cbd67f2ac_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:f74ce43b7d8ade25e5b0f78a41f87db5c6005a85f48cde956b9a87a5892c3a87_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:1ad319aa2d1f00c745609246ea315955298a7028afe3fc5502a68c2d1b5c8467_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:29840664ab5a92cebe5aef4ca45e14c558fe92b832a9d2b8ddec426eaed93144_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:4e76c5cb1ed229c3c1d51beedad3e7970a29c55d32cfc0500153fded3dc8a1c9_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:908382349b4ba81195c2fdc9e650d304cd868ff94d809414d7e44947f2725e0c_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:38a0acf8e97a7d0c6a4c8d6815321e35df6ad35736a7338267ce9b5adb118662_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:8b8f3387a3764beb3d8ad6a027b05f42619ccf33165e733e8dc7b3f135895dc5_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:b338c1060dd859a8747e0812e176ab266d338aea799becd41e48afc50061fb82_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:ba0aebd6b6b6ceb676b6990d5bd9f3b7efe40cedd9407149da92c55435ef7db6_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:1e1215926b9d71cc0131148ad92f4ea8ea8b1e2ba72d6f73396601fceac5ee75_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4cd3b940aa076240f9c7e1fffd05c6bd739a76f31f94d2e4e80ce109fec27206_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4fb0b9f0ab3c37feeace62a178b6abd0e25797cb9ea326c4e1c079ad7791c7a2_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:b0b215ef0b00aff4be01e9c7718f92ef0c249782e37ad5fde717d9b76e112a92_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:1a1dc37c6638cf1bbbcdef28032f1e5e847d99566a8b76338376245798fdcf92_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:67a090d14c2859d30419de71d46f85b71d8bfb8ea0f831f103be9a236af1153c_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:6a14d27e13cfc97103437c822cb7becf22d9a6c2fcb94729c977d6d5ffecaa0d_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:eaab16b83d494e162ab01c2476c548907eababda4b20317666f41119467c6890_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:2ee7edad219c94eb91465132570a8180b038c0e1e94e4c20f15ac20388d443a2_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:3e9d56b1c640ac770ef67309529a662c36a24858b4c0d74273e72c6398181cf4_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:bde7602ad25518d0344589c2efe1ff51af32e3070292751cb4a3e1de9788d291_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:ee6cce6ce7461624def1638ac43fbf4cf81a9fc2f88a0729fca1399d19e78820_amd64 —
Threats
Impact Important

A flaw was found in Netty, a network application framework. This vulnerability allows a remote attacker to bypass hostname verification due to improper handling of user-supplied trust managers. When a client is configured with a plain X.509 Trust Manager (X509TrustManager), it fails to perform necessary hostname checks, enabling an attacker to impersonate a legitimate server. This could lead to sensitive information disclosure or man-in-the-middle attacks.

CWE-347 - Improper Verification of Cryptographic Signature
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Important

A flaw was found in jackson-databind, a general-purpose data-binding library for Jackson Data Processor. A remote attacker can exploit this vulnerability by sending deeply nested JSON (JavaScript Object Notation) data to a service that reads and processes it. This can lead to a Denial of Service (DoS) by consuming significant system resources, making the service unavailable to legitimate users.

CWE-1050 - Excessive Platform Resource Consumption within a Loop
Affected products
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:10bcd975f5d03858c30d65f8969391b72a05ff69cdf881de3c27a89272bb39e8_ppc64le —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:99392ab8ee91b46131519490ea92adef817140751f84c5ef421a59369deb04da_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f69a7c87ff903073da4602b2daa377d714117960aacd7e5912b94ae752dfec08_arm64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f7587af345f0bf512627705f8543b8533b0d92fd5e845fc3c6c84094c277cc1e_amd64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:560dd6062c5240e73ec60ecc13d402009b01e81ed452b6314c3817a2d116d575_amd64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:61a523a9663ff94b984f06fb72a570a18faf326b5efe6ef7d3ba55f96d4e422f_ppc64le —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:a4f8b673fd049befb193ee8f93ac8167b784cfe35b5de3584b19a95c726d9cff_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:b73b5fef7a238e3a16a0b724a8022588a4f69195743bf489f2bb01e4d3a59113_arm64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:121aee11bc25d5e983808691d3b82905048b5a67ffb01f61c86815867e4e8d08_amd64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:7ba97ebd86b3442cd95ffa2605b7890e2f85731ae84ee696d18bae0633439afe_s390x —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:9eccdaac68f3ce6a42a435ceb511483d0f233fb21b3dee8343b8d70cbd67f2ac_arm64 —
Vendor Fix fix
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:f74ce43b7d8ade25e5b0f78a41f87db5c6005a85f48cde956b9a87a5892c3a87_ppc64le —
Vendor Fix fix
Workaround
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:37194dd2cd72d6cdb57ca93fd1cfe6e4aa70ec826a3e86032cde0d0738262bd2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:5fcb1e5c626c5d3aa85e0ec98062a44803d2815871236a3b7541b95078997c78_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:8f84e4d5f4cf71219fbed65092645ded0df00369b42b5487ddef7d0c6cac331b_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:e576efc0fbec5378a870880a7bce40327a86203f2ff426fb62d8c767f125761a_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:5093c89215a4dd74643a2911ce3e3f9e351fda5adf71ee897b7b702840025d47_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:803f8b179959a2b20c71876814b09bae7e5ee15cc2dc0a7e7e1fded75a52fc8c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:af4e4fde13a96dd7fd6126bc67927e1873f12fc3263f749527603e60e75e8f5e_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:bce9235e326ab64aabbe7080ca74cbd24d6f9090819d82d9f2f7abb814e3b26f_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:0a1d01a849daf85556bea32c69dde2621021d28ed33c6f1268375345df1c9409_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:14a9baa0a9f39517264880f36689046f91f4ddadd383de1a28a56468de08c7bd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b2cd6a2da440d20b39571dbee7bd31c49ad7a7411530735c8896ac38e30ce4b3_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b3bba37ab9e9d214ff805510072ea56ea9a2e0bc07c42244bc330dd595befedb_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:08bb9bfbb83303d07932903db066c32bfdd3f2acbffd99b40de60e61ab05175b_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:467c2c6858ff7ea5a2c6dca1bb95638c9bc4f99ebcda932bb3bfc65f82f82155_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:6ec7b2a574f90ee5629cae48ce32544fb429aadbbee22eb88992932e7e80a28a_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:ca56033e3eec4a8fc2432418141f5c76a4c7c52391d14ff023c67f5c315cae39_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:3f4b18a7d40ff1b17e6610ab2e6a79b77e3e9f9026b2d1a77f2892ae3ec7c4a0_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:562e100628a6d9b06f519e8d2a555bdaa43b79e7f30870dc94da9c87dac3fcb6_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:5b96816dc89ecd3b6db02011805a3ed9069f5db86b4158eac8b2f931f0e9532b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:cd0d86c44dc30c77d2876540a75249fbcb0cb1b3ecf4d14394f6eebe2061f9a6_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:d98a5605205445fe1fd9a8f439b09918eb187eef468a0546a911c5ee1d00f851_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:130cf3c00d9042bdc07da56eee755b2682a13f77b9bd445ca9369e7aee9f02cf_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:5f5b25b4cbfa35f731247c948d83f31b100fa99c0126a964fbd46bab9c204b55_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:7f0a8c6cdbc3031e5e0193819310640f115a658ff4883914b1876c9a21dc010a_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:c722c2cdf62c8dc9953dde8a5cb283c3afece2e7925b4213c6cb6afa76004f29_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:188e877e1d78b19fa479d4b2815fc0d48fb8a048274d7f3aa37f5bf7e16523dd_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:36779d828279ae8078a29ce39ed42d8311fe40fb13347533e2d0652a23a2324f_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:8e216bcc9a9f70469bbd1b91e94d30e74d6fb8cc650bf2ca562a0aa6e82591f7_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:9889305d3ba264f5e015a58e355840b90807995d2e1fb672e64c42fd4d4f070b_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:122bbd2d696d9ac1a98a6d587c4ebb503ae13eac888bd63c48695aeef5a3ec93_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:8e7d83f45214e9841238d396ecf3e89ce4b43910f951136bf9e792b224ab09e7_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:98164a2ff734c7d74b8bf9d55db9aafc2e1922baf8e4146efed21642e022a513_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:af08600dbbfde6a494e4a54ddfaae4f067778412b8bbaa0e0d6ff22018121438_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:1ad319aa2d1f00c745609246ea315955298a7028afe3fc5502a68c2d1b5c8467_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:29840664ab5a92cebe5aef4ca45e14c558fe92b832a9d2b8ddec426eaed93144_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:4e76c5cb1ed229c3c1d51beedad3e7970a29c55d32cfc0500153fded3dc8a1c9_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:908382349b4ba81195c2fdc9e650d304cd868ff94d809414d7e44947f2725e0c_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:38a0acf8e97a7d0c6a4c8d6815321e35df6ad35736a7338267ce9b5adb118662_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:8b8f3387a3764beb3d8ad6a027b05f42619ccf33165e733e8dc7b3f135895dc5_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:b338c1060dd859a8747e0812e176ab266d338aea799becd41e48afc50061fb82_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:ba0aebd6b6b6ceb676b6990d5bd9f3b7efe40cedd9407149da92c55435ef7db6_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:1e1215926b9d71cc0131148ad92f4ea8ea8b1e2ba72d6f73396601fceac5ee75_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4cd3b940aa076240f9c7e1fffd05c6bd739a76f31f94d2e4e80ce109fec27206_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4fb0b9f0ab3c37feeace62a178b6abd0e25797cb9ea326c4e1c079ad7791c7a2_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:b0b215ef0b00aff4be01e9c7718f92ef0c249782e37ad5fde717d9b76e112a92_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:1a1dc37c6638cf1bbbcdef28032f1e5e847d99566a8b76338376245798fdcf92_amd64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:67a090d14c2859d30419de71d46f85b71d8bfb8ea0f831f103be9a236af1153c_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:6a14d27e13cfc97103437c822cb7becf22d9a6c2fcb94729c977d6d5ffecaa0d_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:eaab16b83d494e162ab01c2476c548907eababda4b20317666f41119467c6890_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:2ee7edad219c94eb91465132570a8180b038c0e1e94e4c20f15ac20388d443a2_arm64 —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:3e9d56b1c640ac770ef67309529a662c36a24858b4c0d74273e72c6398181cf4_ppc64le —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:bde7602ad25518d0344589c2efe1ff51af32e3070292751cb4a3e1de9788d291_s390x —
Workaround
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:ee6cce6ce7461624def1638ac43fbf4cf81a9fc2f88a0729fca1399d19e78820_amd64 —
Workaround
Threats
Impact Important

A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) plugin, which manages container operations, fails to validate labels propagated from an image configuration to a container. This oversight could enable an attacker to execute arbitrary commands on the host system through a plugin that processes these unvalidated labels. The primary impact is host-root command execution, allowing unauthorized control over the underlying system.

CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Affected products
Fixed 4 products, the same list as for CVE-2026-27136
Known not affected 61 products, the same list as for CVE-2026-27136
Threats
Impact Important

A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) implementation, which allows Kubernetes to interact with container runtimes, improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. This vulnerability enables a user with permissions to create pods to bypass standard Kubernetes resource allocation and device plugin enforcement. Consequently, an attacker can inject arbitrary CDI edits, such as device nodes and host mounts, into the restored container, potentially leading to unauthorized resource access or privilege escalation.

CWE-807 - Reliance on Untrusted Inputs in a Security Decision
Affected products
Fixed 4 products, the same list as for CVE-2026-27136
Known not affected 61 products, the same list as for CVE-2026-27136
Threats
Impact Important

A flaw was found in Traefik, an HTTP reverse proxy and load balancer. This critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection allows unauthenticated clients to bypass router-specific mutual Transport Layer Security (mTLS) enforcement. When HTTP/3 is enabled and a router uses wildcard host rules or case-insensitive hostname matching with client certificate authentication, an attacker can complete the QUIC handshake without presenting a certificate. This bypass grants unauthorized access to a backend that should be protected by mTLS.

CWE-289 - Authentication Bypass by Alternate Name
Affected products
Fixed 4 products, the same list as for CVE-2026-27136
Known not affected 61 products, the same list as for CVE-2026-27136
Threats
Impact Important

A flaw was found in Apache HttpComponents Core. This uncontrolled resource consumption vulnerability in the HTTP/1.1 message parser allows a remote attacker to cause a denial of service through memory exhaustion. This can be triggered by sending messages with an excessive number of headers or excessive header length.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Important

A flaw was found in Apache HttpComponents Core. This vulnerability, located in the HTTP/2 HPACK decoder, allows a remote attacker to cause a denial of service. By sending oversized compressed header blocks, an attacker can exhaust memory resources before the system's configured header list size limit is applied. This can lead to the affected system becoming unresponsive.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Important

A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass the PolymorphicTypeValidator (PTV) when polymorphic typing is enabled and a type identifier contains generic parameters. By crafting a malicious type ID, an attacker can place a denied class as a generic type parameter of an allowed container. This leads to the loading and instantiation of arbitrary classes, potentially resulting in arbitrary code execution.

CWE-502 - Deserialization of Untrusted Data
Affected products
Fixed 12 products, the same list as for CVE-2026-50193
Known not affected 53 products, the same list as for CVE-2026-50193
Threats
Impact Important

A flaw was found in jackson-databind, a library used for processing data. This vulnerability allows an attacker to bypass security controls designed to validate data types. By sending specially crafted input, an attacker can force the system to process untrusted data, which may lead to the execution of malicious code. This could result in a complete compromise of the affected system, impacting its confidentiality, integrity, and availability.

CWE-184 - Incomplete List of Disallowed Inputs
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Important

A flaw was found in Traefik, an HTTP reverse proxy and load balancer. The BasicAuth, DigestAuth, and ForwardAuth middlewares in Traefik do not correctly treat underscore-variant header names. This allows a remote attacker to inject a specially crafted header that bypasses Traefik's security mechanisms. As a result, the attacker can spoof identity or authorization context to the backend, potentially gaining unauthorized access to protected resources.

CWE-178 - Improper Handling of Case Sensitivity
Affected products
Fixed 4 products, the same list as for CVE-2026-27136
Known not affected 61 products, the same list as for CVE-2026-27136
Threats
Impact Important

A flaw was found in Netty, a network application framework. A remote attacker, by sending a specially crafted SPDY/3.1 SETTINGS frame, could cause the SPDY SETTINGS decoder to create a large number of map entries. This excessive processing and memory allocation can lead to a denial of service (DoS) due to heap growth and increased CPU usage.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Important

A flaw was found in Netty, a network application framework. A remote attacker could exploit a vulnerability in the SPDY header decoding process. By sending a specially crafted, small compressed header block, the attacker can cause it to expand significantly during decompression, leading to excessive CPU usage and memory allocation. This can result in a denial of service (DoS) due to resource exhaustion.

CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Important

A flaw was found in Netty. A remote attacker can exploit a vulnerability in the `SpdyHttpDecoder` handler of Netty's SPDY-to-HTTP codec. When processing a client-initiated `SYN_STREAM` frame, the decoder fails to release allocated memory if the stream is reset or content limits are exceeded. This oversight leads to native memory exhaustion, which can result in a Denial of Service (DoS) for the affected system.

CWE-772 - Missing Release of Resource after Effective Lifetime
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Important

A flaw was found in Netty, a network application framework. A remote attacker can bypass security controls in the `CorsHandler` component by sending a specially crafted request with a null origin header. This bypasses the intended access restrictions, allowing unauthorized requests to reach the backend application. This could lead to a compromise of data integrity by allowing unauthorized actions.

CWE-807 - Reliance on Untrusted Inputs in a Security Decision
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Important

A flaw was found in Netty, a network application framework. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted HTTP/2 DATA frames to applications that use Netty and have HTTP/2 content decompression enabled. This can lead to memory exhaustion, causing the application to crash and resulting in a Denial of Service (DoS). The issue occurs because the framework fails to release retained memory buffers when processing DATA frames for a stream whose decompressor has already been closed.

CWE-911 - Improper Update of Reference Count
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Important

A flaw was found in Micrometer's StatsD and Logging meter registries. This vulnerability allows a remote attacker to inject line terminators into metric data, such as names or tag values, due to insufficient sanitization of untrusted input. Exploitation can lead to the spoofing of arbitrary metrics, including critical system or business metrics, and the injection of false log entries, potentially impacting monitoring and auditing systems.

CWE-93 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Moderate

A flaw was found in js-yaml, a JavaScript YAML parser and dumper. A remote attacker could exploit this vulnerability by providing a specially crafted YAML document containing a chain of mappings with merge keys. This could cause the parser to consume excessive CPU resources, leading to a Denial of Service (DoS) for the affected system.

CWE-606 - Unchecked Input for Loop Condition
Affected products
Fixed 8 products, the same list as for CVE-2026-49978
Known not affected 57 products, the same list as for CVE-2026-49978
Threats
Impact Important

A flaw was found in node-tar, a tar archive manipulation library for Node.js. This vulnerability allows a remote attacker to craft a small gzip bomb, which, when processed, can lead to the exhaustion of disk space and CPU resources. This occurs because node-tar does not enforce strict limits on the total decompressed data, the number of entries, or the decompression ratio during extraction and parsing. The primary impact is a Denial of Service (DoS), making the affected system or application unavailable.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 8 products, the same list as for CVE-2026-49978
Known not affected 57 products, the same list as for CVE-2026-49978
Threats
Impact Important

A flaw was found in node-tar, a tar archive manipulation library for Node.js. A remote attacker could exploit this vulnerability by providing a specially crafted tar archive with a negative entry size in its header. This malformed header causes the archive scanner to enter an infinite loop, repeatedly parsing the same header and preventing further processing. This can lead to a denial of service (DoS) condition, making the affected system or application unresponsive.

CWE-606 - Unchecked Input for Loop Condition
Affected products
Fixed 8 products, the same list as for CVE-2026-49978
Known not affected 57 products, the same list as for CVE-2026-49978
Threats
Impact Important

A flaw was found in protobufjs, a JavaScript (JS) library for compiling protobuf definitions. A remote attacker could exploit this vulnerability by providing a specially crafted .proto schema. This schema, designed to prematurely end an option declaration, can cause the library's parsing functions to loop indefinitely. This leads to a Denial of Service (DoS), making the affected system unresponsive.

CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
Affected products
Fixed 4 products, the same list as for CVE-2026-8286
Known not affected 61 products, the same list as for CVE-2026-8286
Threats
Impact Important

A flaw was found in jackson-databind. When Java Records use a PropertyNamingStrategy, an attacker can bypass the @JsonIgnore annotation during deserialization. This allows a renamed JSON key to be assigned to a Record constructor parameter, even if it was intended to be ignored. Consequently, an untrusted client could set internal or privileged components from external input, potentially leading to unauthorized modification or disclosure of sensitive data.

CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
Affected products
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:560dd6062c5240e73ec60ecc13d402009b01e81ed452b6314c3817a2d116d575_amd64 —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:61a523a9663ff94b984f06fb72a570a18faf326b5efe6ef7d3ba55f96d4e422f_ppc64le —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:a4f8b673fd049befb193ee8f93ac8167b784cfe35b5de3584b19a95c726d9cff_s390x —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/openvsx-rhel9@sha256:b73b5fef7a238e3a16a0b724a8022588a4f69195743bf489f2bb01e4d3a59113_arm64 —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:121aee11bc25d5e983808691d3b82905048b5a67ffb01f61c86815867e4e8d08_amd64 —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:7ba97ebd86b3442cd95ffa2605b7890e2f85731ae84ee696d18bae0633439afe_s390x —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:9eccdaac68f3ce6a42a435ceb511483d0f233fb21b3dee8343b8d70cbd67f2ac_arm64 —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/pluginregistry-rhel9@sha256:f74ce43b7d8ade25e5b0f78a41f87db5c6005a85f48cde956b9a87a5892c3a87_ppc64le —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:1ad319aa2d1f00c745609246ea315955298a7028afe3fc5502a68c2d1b5c8467_arm64 —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:29840664ab5a92cebe5aef4ca45e14c558fe92b832a9d2b8ddec426eaed93144_s390x —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:4e76c5cb1ed229c3c1d51beedad3e7970a29c55d32cfc0500153fded3dc8a1c9_ppc64le —
Vendor Fix fix
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/server-rhel9@sha256:908382349b4ba81195c2fdc9e650d304cd868ff94d809414d7e44947f2725e0c_amd64 —
Vendor Fix fix
Product Identifier Version Remediation
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:37194dd2cd72d6cdb57ca93fd1cfe6e4aa70ec826a3e86032cde0d0738262bd2_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:5fcb1e5c626c5d3aa85e0ec98062a44803d2815871236a3b7541b95078997c78_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:8f84e4d5f4cf71219fbed65092645ded0df00369b42b5487ddef7d0c6cac331b_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-rhel9@sha256:e576efc0fbec5378a870880a7bce40327a86203f2ff426fb62d8c767f125761a_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:5093c89215a4dd74643a2911ce3e3f9e351fda5adf71ee897b7b702840025d47_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:803f8b179959a2b20c71876814b09bae7e5ee15cc2dc0a7e7e1fded75a52fc8c_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:af4e4fde13a96dd7fd6126bc67927e1873f12fc3263f749527603e60e75e8f5e_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/code-sshd-rhel9@sha256:bce9235e326ab64aabbe7080ca74cbd24d6f9090819d82d9f2f7abb814e3b26f_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:0a1d01a849daf85556bea32c69dde2621021d28ed33c6f1268375345df1c9409_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:14a9baa0a9f39517264880f36689046f91f4ddadd383de1a28a56468de08c7bd_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b2cd6a2da440d20b39571dbee7bd31c49ad7a7411530735c8896ac38e30ce4b3_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/configbump-rhel9@sha256:b3bba37ab9e9d214ff805510072ea56ea9a2e0bc07c42244bc330dd595befedb_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:08bb9bfbb83303d07932903db066c32bfdd3f2acbffd99b40de60e61ab05175b_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:467c2c6858ff7ea5a2c6dca1bb95638c9bc4f99ebcda932bb3bfc65f82f82155_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:6ec7b2a574f90ee5629cae48ce32544fb429aadbbee22eb88992932e7e80a28a_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/dashboard-rhel9@sha256:ca56033e3eec4a8fc2432418141f5c76a4c7c52391d14ff023c67f5c315cae39_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:3f4b18a7d40ff1b17e6610ab2e6a79b77e3e9f9026b2d1a77f2892ae3ec7c4a0_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:562e100628a6d9b06f519e8d2a555bdaa43b79e7f30870dc94da9c87dac3fcb6_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:5b96816dc89ecd3b6db02011805a3ed9069f5db86b4158eac8b2f931f0e9532b_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:cd0d86c44dc30c77d2876540a75249fbcb0cb1b3ecf4d14394f6eebe2061f9a6_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/devspaces-rhel9-operator@sha256:d98a5605205445fe1fd9a8f439b09918eb187eef468a0546a911c5ee1d00f851_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:130cf3c00d9042bdc07da56eee755b2682a13f77b9bd445ca9369e7aee9f02cf_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:5f5b25b4cbfa35f731247c948d83f31b100fa99c0126a964fbd46bab9c204b55_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:7f0a8c6cdbc3031e5e0193819310640f115a658ff4883914b1876c9a21dc010a_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/imagepuller-rhel9@sha256:c722c2cdf62c8dc9953dde8a5cb283c3afece2e7925b4213c6cb6afa76004f29_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:188e877e1d78b19fa479d4b2815fc0d48fb8a048274d7f3aa37f5bf7e16523dd_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:36779d828279ae8078a29ce39ed42d8311fe40fb13347533e2d0652a23a2324f_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:8e216bcc9a9f70469bbd1b91e94d30e74d6fb8cc650bf2ca562a0aa6e82591f7_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/jetbrains-ide-rhel9@sha256:9889305d3ba264f5e015a58e355840b90807995d2e1fb672e64c42fd4d4f070b_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:10bcd975f5d03858c30d65f8969391b72a05ff69cdf881de3c27a89272bb39e8_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:99392ab8ee91b46131519490ea92adef817140751f84c5ef421a59369deb04da_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f69a7c87ff903073da4602b2daa377d714117960aacd7e5912b94ae752dfec08_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/multicluster-redirector-rhel9@sha256:f7587af345f0bf512627705f8543b8533b0d92fd5e845fc3c6c84094c277cc1e_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:122bbd2d696d9ac1a98a6d587c4ebb503ae13eac888bd63c48695aeef5a3ec93_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:8e7d83f45214e9841238d396ecf3e89ce4b43910f951136bf9e792b224ab09e7_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:98164a2ff734c7d74b8bf9d55db9aafc2e1922baf8e4146efed21642e022a513_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/oauth2-proxy-rhel9@sha256:af08600dbbfde6a494e4a54ddfaae4f067778412b8bbaa0e0d6ff22018121438_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:38a0acf8e97a7d0c6a4c8d6815321e35df6ad35736a7338267ce9b5adb118662_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:8b8f3387a3764beb3d8ad6a027b05f42619ccf33165e733e8dc7b3f135895dc5_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:b338c1060dd859a8747e0812e176ab266d338aea799becd41e48afc50061fb82_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/traefik-rhel9@sha256:ba0aebd6b6b6ceb676b6990d5bd9f3b7efe40cedd9407149da92c55435ef7db6_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:1e1215926b9d71cc0131148ad92f4ea8ea8b1e2ba72d6f73396601fceac5ee75_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4cd3b940aa076240f9c7e1fffd05c6bd739a76f31f94d2e4e80ce109fec27206_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:4fb0b9f0ab3c37feeace62a178b6abd0e25797cb9ea326c4e1c079ad7791c7a2_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel10@sha256:b0b215ef0b00aff4be01e9c7718f92ef0c249782e37ad5fde717d9b76e112a92_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:1a1dc37c6638cf1bbbcdef28032f1e5e847d99566a8b76338376245798fdcf92_amd64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:67a090d14c2859d30419de71d46f85b71d8bfb8ea0f831f103be9a236af1153c_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:6a14d27e13cfc97103437c822cb7becf22d9a6c2fcb94729c977d6d5ffecaa0d_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-base-rhel9@sha256:eaab16b83d494e162ab01c2476c548907eababda4b20317666f41119467c6890_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:2ee7edad219c94eb91465132570a8180b038c0e1e94e4c20f15ac20388d443a2_arm64 —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:3e9d56b1c640ac770ef67309529a662c36a24858b4c0d74273e72c6398181cf4_ppc64le —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:bde7602ad25518d0344589c2efe1ff51af32e3070292751cb4a3e1de9788d291_s390x —
Unresolved product id: Red Hat OpenShift Dev Spaces 3.30:registry.redhat.io/devspaces/udi-rhel9@sha256:ee6cce6ce7461624def1638ac43fbf4cf81a9fc2f88a0729fca1399d19e78820_amd64 —
Threats
Impact Moderate

A flaw was found in the Netty netty-codec-http component. A remote attacker can send HTTP requests containing highly compressed data. The HTTP decoder in netty-codec-http fails to properly limit the decompression of this content, causing the system to consume excessive memory. This can lead to memory exhaustion and a denial of service (DoS), making the service unavailable to legitimate users.

CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)
Affected products
Fixed 8 products, the same list as for CVE-2026-9563
Known not affected 57 products, the same list as for CVE-2026-9563
Threats
Impact Important

A flaw was found in Traefik. An unauthenticated remote attacker can bypass authentication due to a path traversal vulnerability in the ReplacePathRegex middleware. When this middleware is misconfigured, it forwards un-normalized paths, allowing a backend to resolve them to protected routes and grant unauthorized access. This bypass enables access to sensitive administrative interfaces.

CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected products
Fixed 4 products, the same list as for CVE-2026-27136
Known not affected 61 products, the same list as for CVE-2026-27136
Threats
Impact Low

A flaw was found in Traefik, a cloud-native edge router. A low-privileged user in a Kubernetes environment could exploit a namespace confusion vulnerability within the Kubernetes Gateway API provider. This flaw allows an attacker to bypass security controls by incorrectly binding a Traefik Middleware from a different namespace, potentially leading to the injection of trusted identity headers into network requests. This could result in unauthorized access or privilege escalation within the Kubernetes cluster.

CWE-348 - Use of Less Trusted Source
Affected products
Fixed 4 products, the same list as for CVE-2026-27136
Known not affected 61 products, the same list as for CVE-2026-27136
Threats
Impact Important

A flaw was found in nanoid (Nano ID), a small, secure, and URL-friendly unique string ID generator. An attacker could exploit this vulnerability by providing a zero-size input to the customAlphabet or customRandom functions. This would cause an infinite loop, leading to a denial of service (DoS) condition by hanging the application's calling thread.

CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
Affected products
Fixed 4 products, the same list as for CVE-2026-8286
Known not affected 61 products, the same list as for CVE-2026-8286
Threats
Impact Important

A flaw was found in nanoid (Nano ID), a JavaScript library used for generating unique identifiers. This vulnerability allows an attacker to cause a Denial of Service (DoS) by providing a negative size input to the customAlphabet or nanoid functions within the library's non-secure module. When a negative size is provided, these functions enter an infinite loop, causing the application to hang indefinitely and disrupting service availability.

CWE-839 - Numeric Range Comparison Without Minimum Check
Affected products
Fixed 8 products, the same list as for CVE-2026-49978
Known not affected 57 products, the same list as for CVE-2026-49978
Threats
Impact Important

A flaw was found in jackson-core. A remote attacker can exploit an incomplete fix in the non-blocking JSON parser by streaming specially crafted JSON data in small chunks. This bypasses the intended number length constraint, causing the parser to accumulate excessive memory per connection. This uncontrolled memory growth can lead to a denial of service (DoS) by exhausting the Java Virtual Machine (JVM) heap.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 12 products, the same list as for CVE-2026-59888
Known not affected 53 products, the same list as for CVE-2026-59888
Threats
Impact Important

A flaw was found in the brace-expansion library. The `expand()` function does not apply `maxLength` when constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled input to exhaust memory or block the event loop, resulting in a denial of service. This issue is due to an incomplete mitigation of CVE-2026-14257.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 4 products, the same list as for CVE-2026-8286
Known not affected 61 products, the same list as for CVE-2026-8286
Threats
Impact Important

A flaw was found in PostCSS. A remote attacker can exploit this vulnerability by providing a specially crafted sourceMappingURL when a specific configuration (the 'from' parameter) is not set. This can cause the application to read and expose unintended source-map files, potentially revealing sensitive information about the application's source code.

CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected products
Fixed 4 products, the same list as for CVE-2026-45623
Known not affected 61 products, the same list as for CVE-2026-45623
Threats
Impact Moderate

A flaw was found in nanoid, a JavaScript library for generating unique string IDs. A remote attacker could exploit an integer overflow vulnerability by providing a specific input to the `nanoid(size)` function. This issue causes the internal random number generator to become predictable, leading to the generation of identical identifiers for session tokens, security tokens (Cross-Site Request Forgery (CSRF) tokens), and API keys. Such predictability could allow an attacker to bypass security measures that rely on unique and random identifiers.

CWE-1241 - Use of Predictable Algorithm in Random Number Generator
Affected products
Fixed 4 products, the same list as for CVE-2026-8286
Known not affected 61 products, the same list as for CVE-2026-8286
Threats
Impact Important

A flaw was found in node-tar, a tar archive manipulation library for Node.js. A remote attacker could provide a specially crafted tar archive with a long-path header. When processing this archive with a non-empty member-selection list, an uncontrolled recursion in the `filesFilter` function can lead to a stack overflow. This issue results in a denial of service (DoS) by terminating Node.js applications that consume these archives.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 4 products, the same list as for CVE-2026-8286
Known not affected 61 products, the same list as for CVE-2026-8286
Threats
Impact Important

A flaw was found in PostCSS. An attacker can exploit a path traversal vulnerability by providing specially crafted `sourceMappingURL` values in untrusted CSS files. This allows the attacker to disclose sensitive `sourcesContent` from arbitrary `.map` files accessible on the system, leading to information disclosure.

CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected products
Fixed 4 products, the same list as for CVE-2026-45623
Known not affected 61 products, the same list as for CVE-2026-45623
Threats
Impact Important

A flaw was found in DOMPurify. This cross-site scripting vulnerability occurs during IN_PLACE sanitization, where element-removal hooks fail to neutralize detached subtrees. A remote attacker can exploit this by supplying specially crafted HTML with event handlers. This allows the execution of malicious scripts even after the HTML appears to be sanitized, leading to potential information disclosure or unauthorized actions.

CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected products
Fixed 4 products, the same list as for CVE-2026-45623
Known not affected 61 products, the same list as for CVE-2026-45623
Threats
Impact Moderate
References
URL Category
https://access.redhat.com/errata/RHSA-2026:62260 self
https://access.redhat.com/documentation/en-us/red… external
https://access.redhat.com/security/cve/CVE-2025-55163 external
https://access.redhat.com/security/cve/CVE-2026-10050 external
https://access.redhat.com/security/cve/CVE-2026-10051 external
https://access.redhat.com/security/cve/CVE-2026-12143 external
https://access.redhat.com/security/cve/CVE-2026-12151 external
https://access.redhat.com/security/cve/CVE-2026-13149 external
https://access.redhat.com/security/cve/CVE-2026-15075 external
https://access.redhat.com/security/cve/CVE-2026-15076 external
https://access.redhat.com/security/cve/CVE-2026-27136 external
https://access.redhat.com/security/cve/CVE-2026-34986 external
https://access.redhat.com/security/cve/CVE-2026-39820 external
https://access.redhat.com/security/cve/CVE-2026-39831 external
https://access.redhat.com/security/cve/CVE-2026-39835 external
https://access.redhat.com/security/cve/CVE-2026-40898 external
https://access.redhat.com/security/cve/CVE-2026-40983 external
https://access.redhat.com/security/cve/CVE-2026-40984 external
https://access.redhat.com/security/cve/CVE-2026-41242 external
https://access.redhat.com/security/cve/CVE-2026-41695 external
https://access.redhat.com/security/cve/CVE-2026-41716 external
https://access.redhat.com/security/cve/CVE-2026-42264 external
https://access.redhat.com/security/cve/CVE-2026-42499 external
https://access.redhat.com/security/cve/CVE-2026-44705 external
https://access.redhat.com/security/cve/CVE-2026-45149 external
https://access.redhat.com/security/cve/CVE-2026-45416 external
https://access.redhat.com/security/cve/CVE-2026-45623 external
https://access.redhat.com/security/cve/CVE-2026-45674 external
https://access.redhat.com/security/cve/CVE-2026-46597 external
https://access.redhat.com/security/cve/CVE-2026-46681 external
https://access.redhat.com/security/cve/CVE-2026-47691 external
https://access.redhat.com/security/cve/CVE-2026-48020 external
https://access.redhat.com/security/cve/CVE-2026-48068 external
https://access.redhat.com/security/cve/CVE-2026-48491 external
https://access.redhat.com/security/cve/CVE-2026-49978 external
https://access.redhat.com/security/cve/CVE-2026-50010 external
https://access.redhat.com/security/cve/CVE-2026-50193 external
https://access.redhat.com/security/cve/CVE-2026-53488 external
https://access.redhat.com/security/cve/CVE-2026-53492 external
https://access.redhat.com/security/cve/CVE-2026-53622 external
https://access.redhat.com/security/cve/CVE-2026-54399 external
https://access.redhat.com/security/cve/CVE-2026-54428 external
https://access.redhat.com/security/cve/CVE-2026-54512 external
https://access.redhat.com/security/cve/CVE-2026-54513 external
https://access.redhat.com/security/cve/CVE-2026-54763 external
https://access.redhat.com/security/cve/CVE-2026-55831 external
https://access.redhat.com/security/cve/CVE-2026-55833 external
https://access.redhat.com/security/cve/CVE-2026-56745 external
https://access.redhat.com/security/cve/CVE-2026-56746 external
https://access.redhat.com/security/cve/CVE-2026-56819 external
https://access.redhat.com/security/cve/CVE-2026-59296 external
https://access.redhat.com/security/cve/CVE-2026-59869 external
https://access.redhat.com/security/cve/CVE-2026-59873 external
https://access.redhat.com/security/cve/CVE-2026-59874 external
https://access.redhat.com/security/cve/CVE-2026-59877 external
https://access.redhat.com/security/cve/CVE-2026-59888 external
https://access.redhat.com/security/cve/CVE-2026-59899 external
https://access.redhat.com/security/cve/CVE-2026-65600 external
https://access.redhat.com/security/cve/CVE-2026-65601 external
https://access.redhat.com/security/cve/CVE-2026-67213 external
https://access.redhat.com/security/cve/CVE-2026-67214 external
https://access.redhat.com/security/cve/CVE-2026-68494 external
https://access.redhat.com/security/cve/CVE-2026-69152 external
https://access.redhat.com/security/cve/CVE-2026-69153 external
https://access.redhat.com/security/cve/CVE-2026-73086 external
https://access.redhat.com/security/cve/CVE-2026-73566 external
https://access.redhat.com/security/cve/CVE-2026-73646 external
https://access.redhat.com/security/cve/CVE-2026-75838 external
https://access.redhat.com/security/cve/CVE-2026-8286 external
https://access.redhat.com/security/cve/CVE-2026-9277 external
https://access.redhat.com/security/cve/CVE-2026-9547 external
https://access.redhat.com/security/cve/CVE-2026-9563 external
https://access.redhat.com/security/updates/classi… external
https://security.access.redhat.com/data/csaf/v2/a… self
https://access.redhat.com/security/cve/CVE-2025-55163 self
https://bugzilla.redhat.com/show_bug.cgi?id=2388252 external
https://www.cve.org/CVERecord?id=CVE-2025-55163 external
https://nvd.nist.gov/vuln/detail/CVE-2025-55163 external
https://github.com/netty/netty/security/advisorie… external
https://kb.cert.org/vuls/id/767506 external
https://access.redhat.com/security/cve/CVE-2026-8286 self
https://bugzilla.redhat.com/show_bug.cgi?id=2496763 external
https://www.cve.org/CVERecord?id=CVE-2026-8286 external
https://nvd.nist.gov/vuln/detail/CVE-2026-8286 external
https://curl.se/docs/CVE-2026-8286.html external
https://curl.se/docs/CVE-2026-8286.json external
https://hackerone.com/reports/3718195 external
https://access.redhat.com/security/cve/CVE-2026-9277 self
https://bugzilla.redhat.com/show_bug.cgi?id=2480741 external
https://www.cve.org/CVERecord?id=CVE-2026-9277 external
https://nvd.nist.gov/vuln/detail/CVE-2026-9277 external
https://github.com/ljharb/shell-quote external
https://github.com/ljharb/shell-quote/commit/1518179 external
https://github.com/ljharb/shell-quote/security/ad… external
https://www.npmjs.com/package/shell-quote external
https://access.redhat.com/security/cve/CVE-2026-9547 self
https://bugzilla.redhat.com/show_bug.cgi?id=2496758 external
https://www.cve.org/CVERecord?id=CVE-2026-9547 external
https://nvd.nist.gov/vuln/detail/CVE-2026-9547 external
https://curl.se/docs/CVE-2026-9547.html external
https://curl.se/docs/CVE-2026-9547.json external
https://hackerone.com/reports/3751712 external
https://access.redhat.com/security/cve/CVE-2026-9563 self
https://bugzilla.redhat.com/show_bug.cgi?id=2496411 external
https://www.cve.org/CVERecord?id=CVE-2026-9563 external
https://nvd.nist.gov/vuln/detail/CVE-2026-9563 external
https://github.com/eclipse-ee4j/parsson/commit/13… external
https://github.com/eclipse-ee4j/parsson/pull/169 external
https://github.com/eclipse-ee4j/parsson/tree/1.1.8 external
https://gitlab.eclipse.org/security/vulnerability… external
https://repo.maven.apache.org/maven2/org/eclipse/… external
https://access.redhat.com/security/cve/CVE-2026-10050 self
https://bugzilla.redhat.com/show_bug.cgi?id=2510732 external
https://www.cve.org/CVERecord?id=CVE-2026-10050 external
https://nvd.nist.gov/vuln/detail/CVE-2026-10050 external
https://access.redhat.com/security/cve/CVE-2026-10051 self
https://bugzilla.redhat.com/show_bug.cgi?id=2499928 external
https://www.cve.org/CVERecord?id=CVE-2026-10051 external
https://nvd.nist.gov/vuln/detail/CVE-2026-10051 external
https://gitlab.eclipse.org/security/cve-assignmen… external
https://access.redhat.com/security/cve/CVE-2026-12143 self
https://bugzilla.redhat.com/show_bug.cgi?id=2488480 external
https://www.cve.org/CVERecord?id=CVE-2026-12143 external
https://nvd.nist.gov/vuln/detail/CVE-2026-12143 external
https://cwe.mitre.org/data/definitions/93.html external
https://github.com/form-data/form-data/commit/641… external
https://github.com/form-data/form-data/commit/be3… external
https://github.com/form-data/form-data/commit/c71… external
https://github.com/form-data/form-data/security/a… external
https://html.spec.whatwg.org/multipage/form-contr… external
https://www.npmjs.com/package/form-data external
https://access.redhat.com/security/cve/CVE-2026-12151 self
https://bugzilla.redhat.com/show_bug.cgi?id=2489980 external
https://www.cve.org/CVERecord?id=CVE-2026-12151 external
https://nvd.nist.gov/vuln/detail/CVE-2026-12151 external
https://cna.openjsf.org/security-advisories.html external
https://github.com/nodejs/undici/security/advisor… external
https://access.redhat.com/security/cve/CVE-2026-13149 self
https://bugzilla.redhat.com/show_bug.cgi?id=2494813 external
https://www.cve.org/CVERecord?id=CVE-2026-13149 external
https://nvd.nist.gov/vuln/detail/CVE-2026-13149 external
https://github.com/juliangruber/brace-expansion/c… external
https://www.npmjs.com/package/brace-expansion external
https://access.redhat.com/security/cve/CVE-2026-15075 self
https://bugzilla.redhat.com/show_bug.cgi?id=2499919 external
https://www.cve.org/CVERecord?id=CVE-2026-15075 external
https://nvd.nist.gov/vuln/detail/CVE-2026-15075 external
https://gitlab.eclipse.org/security/cve-assignmen… external
https://access.redhat.com/security/cve/CVE-2026-15076 self
https://bugzilla.redhat.com/show_bug.cgi?id=2499914 external
https://www.cve.org/CVERecord?id=CVE-2026-15076 external
https://nvd.nist.gov/vuln/detail/CVE-2026-15076 external
https://gitlab.eclipse.org/security/cve-assignmen… external
https://access.redhat.com/security/cve/CVE-2026-27136 self
https://bugzilla.redhat.com/show_bug.cgi?id=2480757 external
https://www.cve.org/CVERecord?id=CVE-2026-27136 external
https://nvd.nist.gov/vuln/detail/CVE-2026-27136 external
https://go.dev/cl/781685 external
https://go.dev/issue/79575 external
https://groups.google.com/g/golang-announce/c/iI-… external
https://pkg.go.dev/vuln/GO-2026-5030 external
https://access.redhat.com/security/cve/CVE-2026-34986 self
https://bugzilla.redhat.com/show_bug.cgi?id=2455470 external
https://www.cve.org/CVERecord?id=CVE-2026-34986 external
https://nvd.nist.gov/vuln/detail/CVE-2026-34986 external
https://github.com/go-jose/go-jose/security/advis… external
https://pkg.go.dev/github.com/go-jose/go-jose/v4#… external
https://access.redhat.com/security/cve/CVE-2026-39820 self
https://bugzilla.redhat.com/show_bug.cgi?id=2467820 external
https://www.cve.org/CVERecord?id=CVE-2026-39820 external
https://nvd.nist.gov/vuln/detail/CVE-2026-39820 external
https://go.dev/cl/759940 external
https://go.dev/issue/78566 external
https://groups.google.com/g/golang-announce/c/qcC… external
https://pkg.go.dev/vuln/GO-2026-4986 external
https://access.redhat.com/security/cve/CVE-2026-39831 self
https://bugzilla.redhat.com/show_bug.cgi?id=2480675 external
https://www.cve.org/CVERecord?id=CVE-2026-39831 external
https://nvd.nist.gov/vuln/detail/CVE-2026-39831 external
https://go.dev/cl/781662 external
https://go.dev/issue/79566 external
https://groups.google.com/g/golang-announce/c/a08… external
https://pkg.go.dev/vuln/GO-2026-5019 external
https://access.redhat.com/security/cve/CVE-2026-39835 self
https://bugzilla.redhat.com/show_bug.cgi?id=2480680 external
https://www.cve.org/CVERecord?id=CVE-2026-39835 external
https://nvd.nist.gov/vuln/detail/CVE-2026-39835 external
https://go.dev/cl/781660 external
https://go.dev/issue/79563 external
https://pkg.go.dev/vuln/GO-2026-5015 external
https://access.redhat.com/security/cve/CVE-2026-40898 self
https://bugzilla.redhat.com/show_bug.cgi?id=2484875 external
https://www.cve.org/CVERecord?id=CVE-2026-40898 external
https://nvd.nist.gov/vuln/detail/CVE-2026-40898 external
https://github.com/quic-go/quic-go/releases/tag/v0.59.1 external
https://github.com/quic-go/quic-go/security/advis… external
https://access.redhat.com/security/cve/CVE-2026-40983 self
https://bugzilla.redhat.com/show_bug.cgi?id=2486697 external
https://www.cve.org/CVERecord?id=CVE-2026-40983 external
https://nvd.nist.gov/vuln/detail/CVE-2026-40983 external
https://spring.io/security/cve-2026-40983 external
https://access.redhat.com/security/cve/CVE-2026-40984 self
https://bugzilla.redhat.com/show_bug.cgi?id=2486716 external
https://www.cve.org/CVERecord?id=CVE-2026-40984 external
https://nvd.nist.gov/vuln/detail/CVE-2026-40984 external
https://spring.io/security/cve-2026-40984 external
https://access.redhat.com/security/cve/CVE-2026-41242 self
https://bugzilla.redhat.com/show_bug.cgi?id=2459442 external
https://www.cve.org/CVERecord?id=CVE-2026-41242 external
https://nvd.nist.gov/vuln/detail/CVE-2026-41242 external
https://github.com/protobufjs/protobuf.js/commit/… external
https://github.com/protobufjs/protobuf.js/commit/… external
https://github.com/protobufjs/protobuf.js/release… external
https://github.com/protobufjs/protobuf.js/release… external
https://github.com/protobufjs/protobuf.js/securit… external
https://access.redhat.com/security/cve/CVE-2026-41695 self
https://bugzilla.redhat.com/show_bug.cgi?id=2487386 external
https://www.cve.org/CVERecord?id=CVE-2026-41695 external
https://nvd.nist.gov/vuln/detail/CVE-2026-41695 external
https://spring.io/security/cve-2026-41695 external
https://access.redhat.com/security/cve/CVE-2026-41716 self
https://bugzilla.redhat.com/show_bug.cgi?id=2487394 external
https://www.cve.org/CVERecord?id=CVE-2026-41716 external
https://nvd.nist.gov/vuln/detail/CVE-2026-41716 external
https://spring.io/security/cve-2026-41716 external
https://access.redhat.com/security/cve/CVE-2026-42264 self
https://bugzilla.redhat.com/show_bug.cgi?id=2467927 external
https://www.cve.org/CVERecord?id=CVE-2026-42264 external
https://nvd.nist.gov/vuln/detail/CVE-2026-42264 external
https://github.com/axios/axios/commit/47915144662… external
https://github.com/axios/axios/pull/10779 external
https://github.com/axios/axios/releases/tag/v1.15.2 external
https://github.com/axios/axios/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-42499 self
https://bugzilla.redhat.com/show_bug.cgi?id=2467809 external
https://www.cve.org/CVERecord?id=CVE-2026-42499 external
https://nvd.nist.gov/vuln/detail/CVE-2026-42499 external
https://go.dev/cl/771520 external
https://go.dev/issue/78987 external
https://pkg.go.dev/vuln/GO-2026-4977 external
https://access.redhat.com/security/cve/CVE-2026-44705 self
https://bugzilla.redhat.com/show_bug.cgi?id=2487946 external
https://www.cve.org/CVERecord?id=CVE-2026-44705 external
https://nvd.nist.gov/vuln/detail/CVE-2026-44705 external
https://github.com/raszi/node-tmp/security/adviso… external
https://access.redhat.com/security/cve/CVE-2026-45149 self
https://bugzilla.redhat.com/show_bug.cgi?id=2483481 external
https://www.cve.org/CVERecord?id=CVE-2026-45149 external
https://nvd.nist.gov/vuln/detail/CVE-2026-45149 external
https://github.com/juliangruber/brace-expansion/s… external
https://access.redhat.com/security/cve/CVE-2026-45416 self
https://bugzilla.redhat.com/show_bug.cgi?id=2488391 external
https://www.cve.org/CVERecord?id=CVE-2026-45416 external
https://nvd.nist.gov/vuln/detail/CVE-2026-45416 external
https://github.com/netty/netty/releases/tag/netty… external
https://github.com/netty/netty/releases/tag/netty… external
https://github.com/netty/netty/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-45623 self
https://bugzilla.redhat.com/show_bug.cgi?id=2507595 external
https://www.cve.org/CVERecord?id=CVE-2026-45623 external
https://nvd.nist.gov/vuln/detail/CVE-2026-45623 external
https://github.com/postcss/postcss/security/advis… external
https://access.redhat.com/security/cve/CVE-2026-45674 self
https://bugzilla.redhat.com/show_bug.cgi?id=2488400 external
https://www.cve.org/CVERecord?id=CVE-2026-45674 external
https://nvd.nist.gov/vuln/detail/CVE-2026-45674 external
https://github.com/netty/netty/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-46597 self
https://bugzilla.redhat.com/show_bug.cgi?id=2480678 external
https://www.cve.org/CVERecord?id=CVE-2026-46597 external
https://nvd.nist.gov/vuln/detail/CVE-2026-46597 external
https://go.dev/cl/781620 external
https://go.dev/issue/79561 external
https://pkg.go.dev/vuln/GO-2026-5013 external
https://access.redhat.com/security/cve/CVE-2026-46681 self
https://bugzilla.redhat.com/show_bug.cgi?id=2503661 external
https://www.cve.org/CVERecord?id=CVE-2026-46681 external
https://nvd.nist.gov/vuln/detail/CVE-2026-46681 external
https://github.com/nevware21/ts-utils/commit/5e88… external
https://github.com/nevware21/ts-utils/security/ad… external
https://access.redhat.com/security/cve/CVE-2026-47691 self
https://bugzilla.redhat.com/show_bug.cgi?id=2488439 external
https://www.cve.org/CVERecord?id=CVE-2026-47691 external
https://nvd.nist.gov/vuln/detail/CVE-2026-47691 external
https://github.com/netty/netty/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-48020 self
https://bugzilla.redhat.com/show_bug.cgi?id=2491915 external
https://www.cve.org/CVERecord?id=CVE-2026-48020 external
https://nvd.nist.gov/vuln/detail/CVE-2026-48020 external
https://github.com/traefik/traefik/releases/tag/v… external
https://github.com/traefik/traefik/releases/tag/v3.6.19 external
https://github.com/traefik/traefik/releases/tag/v3.7.3 external
https://github.com/traefik/traefik/security/advis… external
https://access.redhat.com/security/cve/CVE-2026-48068 self
https://bugzilla.redhat.com/show_bug.cgi?id=2499682 external
https://www.cve.org/CVERecord?id=CVE-2026-48068 external
https://nvd.nist.gov/vuln/detail/CVE-2026-48068 external
https://github.com/grpc/grpc-node/security/adviso… external
https://access.redhat.com/security/cve/CVE-2026-48491 self
https://bugzilla.redhat.com/show_bug.cgi?id=2491923 external
https://www.cve.org/CVERecord?id=CVE-2026-48491 external
https://nvd.nist.gov/vuln/detail/CVE-2026-48491 external
https://github.com/traefik/traefik/security/advis… external
https://access.redhat.com/security/cve/CVE-2026-49978 self
https://bugzilla.redhat.com/show_bug.cgi?id=2500695 external
https://www.cve.org/CVERecord?id=CVE-2026-49978 external
https://nvd.nist.gov/vuln/detail/CVE-2026-49978 external
https://github.com/cure53/DOMPurify/commit/ca30f0… external
https://github.com/cure53/DOMPurify/releases/tag/3.4.7 external
https://github.com/cure53/DOMPurify/security/advi… external
https://access.redhat.com/security/cve/CVE-2026-50010 self
https://bugzilla.redhat.com/show_bug.cgi?id=2488429 external
https://www.cve.org/CVERecord?id=CVE-2026-50010 external
https://nvd.nist.gov/vuln/detail/CVE-2026-50010 external
https://github.com/netty/netty/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-50193 self
https://bugzilla.redhat.com/show_bug.cgi?id=2491999 external
https://www.cve.org/CVERecord?id=CVE-2026-50193 external
https://nvd.nist.gov/vuln/detail/CVE-2026-50193 external
https://github.com/FasterXML/jackson-databind/com… external
https://github.com/FasterXML/jackson-databind/iss… external
https://github.com/FasterXML/jackson-databind/sec… external
https://access.redhat.com/security/cve/CVE-2026-53488 self
https://bugzilla.redhat.com/show_bug.cgi?id=2495815 external
https://www.cve.org/CVERecord?id=CVE-2026-53488 external
https://nvd.nist.gov/vuln/detail/CVE-2026-53488 external
https://github.com/containerd/containerd/security… external
https://access.redhat.com/security/cve/CVE-2026-53492 self
https://bugzilla.redhat.com/show_bug.cgi?id=2496130 external
https://www.cve.org/CVERecord?id=CVE-2026-53492 external
https://nvd.nist.gov/vuln/detail/CVE-2026-53492 external
https://github.com/containerd/containerd/security… external
https://access.redhat.com/security/cve/CVE-2026-53622 self
https://bugzilla.redhat.com/show_bug.cgi?id=2491924 external
https://www.cve.org/CVERecord?id=CVE-2026-53622 external
https://nvd.nist.gov/vuln/detail/CVE-2026-53622 external
https://github.com/traefik/traefik/security/advis… external
https://access.redhat.com/security/cve/CVE-2026-54399 self
https://bugzilla.redhat.com/show_bug.cgi?id=2496101 external
https://www.cve.org/CVERecord?id=CVE-2026-54399 external
https://nvd.nist.gov/vuln/detail/CVE-2026-54399 external
http://www.openwall.com/lists/oss-security/2026/07/01/4 external
https://lists.apache.org/thread/zmxh1pl2zohov5ntd… external
https://access.redhat.com/security/cve/CVE-2026-54428 self
https://bugzilla.redhat.com/show_bug.cgi?id=2496106 external
https://www.cve.org/CVERecord?id=CVE-2026-54428 external
https://nvd.nist.gov/vuln/detail/CVE-2026-54428 external
http://www.openwall.com/lists/oss-security/2026/07/01/3 external
https://lists.apache.org/thread/5zjp8vczvxq19pw2r… external
https://access.redhat.com/security/cve/CVE-2026-54512 self
https://bugzilla.redhat.com/show_bug.cgi?id=2492015 external
https://www.cve.org/CVERecord?id=CVE-2026-54512 external
https://nvd.nist.gov/vuln/detail/CVE-2026-54512 external
https://github.com/FasterXML/jackson-databind/com… external
https://github.com/FasterXML/jackson-databind/iss… external
https://github.com/FasterXML/jackson-databind/sec… external
https://access.redhat.com/security/cve/CVE-2026-54513 self
https://bugzilla.redhat.com/show_bug.cgi?id=2492010 external
https://www.cve.org/CVERecord?id=CVE-2026-54513 external
https://nvd.nist.gov/vuln/detail/CVE-2026-54513 external
https://github.com/FasterXML/jackson-databind/com… external
https://github.com/FasterXML/jackson-databind/com… external
https://github.com/FasterXML/jackson-databind/iss… external
https://github.com/FasterXML/jackson-databind/iss… external
https://github.com/FasterXML/jackson-databind/pull/5984 external
https://github.com/FasterXML/jackson-databind/sec… external
https://access.redhat.com/security/cve/CVE-2026-54763 self
https://bugzilla.redhat.com/show_bug.cgi?id=2497551 external
https://www.cve.org/CVERecord?id=CVE-2026-54763 external
https://nvd.nist.gov/vuln/detail/CVE-2026-54763 external
https://github.com/traefik/traefik/commit/108a526… external
https://github.com/traefik/traefik/pull/13262 external
https://github.com/traefik/traefik/security/advis… external
https://access.redhat.com/security/cve/CVE-2026-55831 self
https://bugzilla.redhat.com/show_bug.cgi?id=2503103 external
https://www.cve.org/CVERecord?id=CVE-2026-55831 external
https://nvd.nist.gov/vuln/detail/CVE-2026-55831 external
https://github.com/netty/netty/commit/5b68c61f37a… external
https://github.com/netty/netty/commit/bb2ff68a1fb… external
https://github.com/netty/netty/releases/tag/netty… external
https://github.com/netty/netty/releases/tag/netty… external
https://github.com/netty/netty/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-55833 self
https://bugzilla.redhat.com/show_bug.cgi?id=2503101 external
https://www.cve.org/CVERecord?id=CVE-2026-55833 external
https://nvd.nist.gov/vuln/detail/CVE-2026-55833 external
https://github.com/netty/netty/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-56745 self
https://bugzilla.redhat.com/show_bug.cgi?id=2505911 external
https://www.cve.org/CVERecord?id=CVE-2026-56745 external
https://nvd.nist.gov/vuln/detail/CVE-2026-56745 external
https://github.com/netty/netty/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-56746 self
https://bugzilla.redhat.com/show_bug.cgi?id=2505422 external
https://www.cve.org/CVERecord?id=CVE-2026-56746 external
https://nvd.nist.gov/vuln/detail/CVE-2026-56746 external
https://github.com/netty/netty/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-56819 self
https://bugzilla.redhat.com/show_bug.cgi?id=2505980 external
https://www.cve.org/CVERecord?id=CVE-2026-56819 external
https://nvd.nist.gov/vuln/detail/CVE-2026-56819 external
https://github.com/netty/netty/commit/5b68c61f37a… external
https://github.com/netty/netty/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-59296 self
https://bugzilla.redhat.com/show_bug.cgi?id=2520949 external
https://www.cve.org/CVERecord?id=CVE-2026-59296 external
https://nvd.nist.gov/vuln/detail/CVE-2026-59296 external
https://spring.io/security/cve-2026-59296 external
https://access.redhat.com/security/cve/CVE-2026-59869 self
https://bugzilla.redhat.com/show_bug.cgi?id=2498122 external
https://www.cve.org/CVERecord?id=CVE-2026-59869 external
https://nvd.nist.gov/vuln/detail/CVE-2026-59869 external
https://github.com/nodeca/js-yaml/commit/24f13e79… external
https://github.com/nodeca/js-yaml/commit/59423c6f… external
https://github.com/nodeca/js-yaml/releases/tag/3.15.0 external
https://github.com/nodeca/js-yaml/releases/tag/4.3.0 external
https://github.com/nodeca/js-yaml/security/adviso… external
https://access.redhat.com/security/cve/CVE-2026-59873 self
https://bugzilla.redhat.com/show_bug.cgi?id=2498120 external
https://www.cve.org/CVERecord?id=CVE-2026-59873 external
https://nvd.nist.gov/vuln/detail/CVE-2026-59873 external
https://github.com/isaacs/node-tar/commit/2812e93… external
https://github.com/isaacs/node-tar/releases/tag/v7.5.19 external
https://github.com/isaacs/node-tar/security/advis… external
https://access.redhat.com/security/cve/CVE-2026-59874 self
https://bugzilla.redhat.com/show_bug.cgi?id=2498116 external
https://www.cve.org/CVERecord?id=CVE-2026-59874 external
https://nvd.nist.gov/vuln/detail/CVE-2026-59874 external
https://github.com/isaacs/node-tar/commit/9e78bf0… external
https://github.com/isaacs/node-tar/releases/tag/v7.5.18 external
https://github.com/isaacs/node-tar/security/advis… external
https://access.redhat.com/security/cve/CVE-2026-59877 self
https://bugzilla.redhat.com/show_bug.cgi?id=2498127 external
https://www.cve.org/CVERecord?id=CVE-2026-59877 external
https://nvd.nist.gov/vuln/detail/CVE-2026-59877 external
https://github.com/protobufjs/protobuf.js/commit/… external
https://github.com/protobufjs/protobuf.js/commit/… external
https://github.com/protobufjs/protobuf.js/pull/2352 external
https://github.com/protobufjs/protobuf.js/release… external
https://github.com/protobufjs/protobuf.js/release… external
https://github.com/protobufjs/protobuf.js/securit… external
https://access.redhat.com/security/cve/CVE-2026-59888 self
https://bugzilla.redhat.com/show_bug.cgi?id=2500096 external
https://www.cve.org/CVERecord?id=CVE-2026-59888 external
https://nvd.nist.gov/vuln/detail/CVE-2026-59888 external
https://github.com/FasterXML/jackson-databind/com… external
https://github.com/FasterXML/jackson-databind/com… external
https://github.com/FasterXML/jackson-databind/pull/5974 external
https://github.com/FasterXML/jackson-databind/sec… external
https://access.redhat.com/security/cve/CVE-2026-59899 self
https://bugzilla.redhat.com/show_bug.cgi?id=2507482 external
https://www.cve.org/CVERecord?id=CVE-2026-59899 external
https://nvd.nist.gov/vuln/detail/CVE-2026-59899 external
https://github.com/netty/netty/security/advisorie… external
https://netty.io/news/2026/07/09/4-1-136-Final.html external
https://access.redhat.com/security/cve/CVE-2026-65600 self
https://bugzilla.redhat.com/show_bug.cgi?id=2506097 external
https://www.cve.org/CVERecord?id=CVE-2026-65600 external
https://nvd.nist.gov/vuln/detail/CVE-2026-65600 external
https://github.com/traefik/traefik/pull/13466 external
https://github.com/traefik/traefik/security/advis… external
https://www.vulncheck.com/advisories/traefik-befo… external
https://access.redhat.com/security/cve/CVE-2026-65601 self
https://bugzilla.redhat.com/show_bug.cgi?id=2506094 external
https://www.cve.org/CVERecord?id=CVE-2026-65601 external
https://nvd.nist.gov/vuln/detail/CVE-2026-65601 external
https://github.com/traefik/traefik/commit/26c96a3… external
https://github.com/traefik/traefik/security/advis… external
https://www.vulncheck.com/advisories/traefik-befo… external
https://access.redhat.com/security/cve/CVE-2026-67213 self
https://bugzilla.redhat.com/show_bug.cgi?id=2508406 external
https://www.cve.org/CVERecord?id=CVE-2026-67213 external
https://nvd.nist.gov/vuln/detail/CVE-2026-67213 external
https://github.com/ai/nanoid/commit/cb3626d0f3342… external
https://github.com/ai/nanoid/releases/tag/5.1.6 external
https://www.vulncheck.com/advisories/nanoid-befor… external
https://access.redhat.com/security/cve/CVE-2026-67214 self
https://bugzilla.redhat.com/show_bug.cgi?id=2508411 external
https://www.cve.org/CVERecord?id=CVE-2026-67214 external
https://nvd.nist.gov/vuln/detail/CVE-2026-67214 external
https://github.com/ai/nanoid/commit/6ccc67bbaba71… external
https://github.com/ai/nanoid/releases/tag/5.1.16 external
https://www.vulncheck.com/advisories/nanoid-befor… external
https://access.redhat.com/security/cve/CVE-2026-68494 self
https://bugzilla.redhat.com/show_bug.cgi?id=2511026 external
https://www.cve.org/CVERecord?id=CVE-2026-68494 external
https://nvd.nist.gov/vuln/detail/CVE-2026-68494 external
https://github.com/FasterXML/jackson-core/commit/… external
https://github.com/FasterXML/jackson-core/commit/… external
https://github.com/FasterXML/jackson-core/commit/… external
https://github.com/FasterXML/jackson-core/pull/1611 external
https://github.com/FasterXML/jackson-core/securit… external
https://github.com/advisories/GHSA-72hv-8253-57qq external
https://www.cve.org/CVERecord?id=CVE-2026-18401 external
https://access.redhat.com/security/cve/CVE-2026-69152 self
https://bugzilla.redhat.com/show_bug.cgi?id=2510722 external
https://www.cve.org/CVERecord?id=CVE-2026-69152 external
https://nvd.nist.gov/vuln/detail/CVE-2026-69152 external
https://github.com/juliangruber/brace-expansion/c… external
https://github.com/juliangruber/brace-expansion/c… external
https://github.com/juliangruber/brace-expansion/c… external
https://github.com/juliangruber/brace-expansion/c… external
https://github.com/juliangruber/brace-expansion/s… external
https://access.redhat.com/security/cve/CVE-2026-69153 self
https://bugzilla.redhat.com/show_bug.cgi?id=2510719 external
https://www.cve.org/CVERecord?id=CVE-2026-69153 external
https://nvd.nist.gov/vuln/detail/CVE-2026-69153 external
https://github.com/postcss/postcss/commit/7beca13… external
https://github.com/postcss/postcss/releases/tag/8.5.19 external
https://github.com/postcss/postcss/security/advis… external
https://access.redhat.com/security/cve/CVE-2026-73086 self
https://bugzilla.redhat.com/show_bug.cgi?id=2514175 external
https://www.cve.org/CVERecord?id=CVE-2026-73086 external
https://nvd.nist.gov/vuln/detail/CVE-2026-73086 external
https://github.com/ai/nanoid/commit/7087969281cab… external
https://github.com/ai/nanoid/commit/821dfed7b5db7… external
https://github.com/ai/nanoid/commit/b0036ed60dc9f… external
https://github.com/ai/nanoid/releases/tag/3.3.12 external
https://github.com/ai/nanoid/releases/tag/5.1.11 external
https://github.com/ai/nanoid/security/advisories/… external
https://access.redhat.com/security/cve/CVE-2026-73566 self
https://bugzilla.redhat.com/show_bug.cgi?id=2515509 external
https://www.cve.org/CVERecord?id=CVE-2026-73566 external
https://nvd.nist.gov/vuln/detail/CVE-2026-73566 external
https://github.com/isaacs/node-tar/commit/631ae59… external
https://github.com/isaacs/node-tar/security/advis… external
https://access.redhat.com/security/cve/CVE-2026-73646 self
https://bugzilla.redhat.com/show_bug.cgi?id=2517456 external
https://www.cve.org/CVERecord?id=CVE-2026-73646 external
https://nvd.nist.gov/vuln/detail/CVE-2026-73646 external
https://github.com/postcss/postcss/commit/95663d3… external
https://github.com/postcss/postcss/releases/tag/8.5.18 external
https://github.com/postcss/postcss/security/advis… external
https://access.redhat.com/security/cve/CVE-2026-75838 self
https://bugzilla.redhat.com/show_bug.cgi?id=2517772 external
https://www.cve.org/CVERecord?id=CVE-2026-75838 external
https://nvd.nist.gov/vuln/detail/CVE-2026-75838 external
https://github.com/cure53/DOMPurify/security/advi… external
https://www.vulncheck.com/advisories/dompurify-be… external

Loading 3.3 MB of JSON…



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…