Patch releases
The following release notes detail the updates for the Red Hat OpenShift Dev Spaces patch releases.
Security, bug fixes, and enhancements for Red Hat OpenShift Dev Spaces are released as asynchronous erratas. All Red Hat OpenShift Dev Spaces erratas are available on the This content is not included.Red Hat package browser.
As a Red Hat Customer Portal user, you can enable errata notifications in the account settings for Red Hat Subscription Management (RHSM). When errata notifications are enabled, you receive notifications through email whenever new erratas relevant to your registered systems are released.
Red Hat Customer Portal user accounts must have systems registered and consuming Red Hat OpenShift Dev Spaces entitlements for errata notification emails to generate.
Red Hat OpenShift Dev Spaces 3.29.1
This patch release for Red Hat OpenShift Dev Spaces 3.29 addresses security vulnerabilities across multiple container images and resolves a plugin registry startup failure on ARM architectures.
Bug fixes
Plugin registry pod no longer reports permission errors during startup: Before this update, the plugin registry pod logged chmod: Permission denied errors in the PostgreSQL data directory during startup. On ARM architectures, a stricter file permission on replorigin_checkpoint caused the pod to enter a CrashLoopBackOff state and fail to start. With this update, file permissions in the plugin registry container image are set correctly. As a result, the plugin registry pod starts successfully without permission errors. (Content from redhat.atlassian.net is not included.CRW-11943)
CVEs
The following CVEs are addressed in this release:
code-rhel9
- This content is not included.CVE-2026-6734:
undici-- Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing. (Content from redhat.atlassian.net is not included.CRW-11311) - This content is not included.CVE-2026-9697:
undici-- Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy. (Content from redhat.atlassian.net is not included.CRW-11339) - This content is not included.CVE-2026-12151:
undici-- Denial of Service due to unbounded memory growth via WebSocket frames. (Content from redhat.atlassian.net is not included.CRW-11356) - This content is not included.CVE-2026-12143:
form-data-- Form field override via CRLF injection. (Content from redhat.atlassian.net is not included.CRW-11377) - This content is not included.CVE-2026-45149:
brace-expansion-- Denial of Service due to excessive memory allocation when expanding large numeric ranges. (Content from redhat.atlassian.net is not included.CRW-11453)
dashboard-rhel9
- This content is not included.CVE-2026-12143:
form-data-- Form field override via CRLF injection. (Content from redhat.atlassian.net is not included.CRW-11376) - This content is not included.CVE-2026-13149:
brace-expansion-- Denial of Service due to exponential-time complexity. (Content from redhat.atlassian.net is not included.CRW-11663) - This content is not included.CVE-2026-13676:
fast-uri-- Security policy bypass due to improper Unicode hostname canonicalization. (Content from redhat.atlassian.net is not included.CRW-11535) - This content is not included.CVE-2026-44990:
sanitize-html-- Stored Cross-Site Scripting via HTML sanitizer bypass. (Content from redhat.atlassian.net is not included.CRW-11484) - This content is not included.CVE-2026-45149:
brace-expansion-- Denial of Service due to excessive memory allocation when expanding large numeric ranges. (Content from redhat.atlassian.net is not included.CRW-11450) - This content is not included.CVE-2026-59869:
js-yaml-- Denial of Service via crafted YAML documents. (Content from redhat.atlassian.net is not included.CRW-11823) - This content is not included.CVE-2026-59873:
node-tar-- Denial of Service via crafted gzip bomb. (Content from redhat.atlassian.net is not included.CRW-11758) - This content is not included.CVE-2026-59874:
node-tar-- Denial of Service via malformed tar archive header. (Content from redhat.atlassian.net is not included.CRW-11761)
jetbrains-ide-rhel9
- This content is not included.CVE-2026-13149:
brace-expansion-- Denial of Service due to exponential-time complexity. (Content from redhat.atlassian.net is not included.CRW-11662) - This content is not included.CVE-2026-44249:
netty-handler-- IPv6 subnet rule bypass due to incorrect masking operation. (Content from redhat.atlassian.net is not included.CRW-11401) - This content is not included.CVE-2026-48043:
netty-codec-http2-- Denial of Service due to resource leak. (Content from redhat.atlassian.net is not included.CRW-11271)
server-rhel9
- This content is not included.CVE-2026-50193:
jackson-databind-- Denial of Service via deeply nested JSON processing. (Content from redhat.atlassian.net is not included.CRW-11567) - This content is not included.CVE-2026-54512:
jackson-databind-- Arbitrary code execution via PolymorphicTypeValidator bypass. (Content from redhat.atlassian.net is not included.CRW-11557)