CVEs
The following release notes detail the CVEs addressed for the Red Hat OpenShift Dev Spaces 3.30 general availability release.
This release of Red Hat OpenShift Dev Spaces addresses security vulnerabilities in container base images and Universal Base Image (UBI) dependencies. All Red Hat OpenShift Dev Spaces container images are rebuilt with the latest UBI packages containing fixes for publicly disclosed CVEs.
For details on specific CVEs addressed in Red Hat OpenShift Dev Spaces container images, see the This content is not included.Red Hat security advisories for OpenShift Dev Spaces.
The following CVEs are addressed in this release:
code-rhel9
- This content is not included.CVE-2026-12143:
form-data-- Form field override via CRLF injection. (Content from redhat.atlassian.net is not included.CRW-12379) - This content is not included.CVE-2026-13149:
Brace-expansion-- Denial of Service due to exponential-time complexity. (Content from redhat.atlassian.net is not included.CRW-11666) - This content is not included.CVE-2026-41242:
protobufjs-- Arbitrary code execution via injected protobuf definition type fields. (Content from redhat.atlassian.net is not included.CRW-12670) - This content is not included.CVE-2026-42264:
Axios-- Prototype pollution allows information disclosure and request manipulation. (Content from redhat.atlassian.net is not included.CRW-11639) - This content is not included.CVE-2026-44705:
tmp-- Path Traversal via unsanitized prefix/postfix enables directory escape. (Content from redhat.atlassian.net is not included.CRW-12260) - This content is not included.CVE-2026-46681:
@nevware21/ts-utils-- Arbitrary Code Execution via Prototype Pollution. (Content from redhat.atlassian.net is not included.CRW-12110) - This content is not included.CVE-2026-48068:
@grpc/grpc-js-- Server crash via malformed HTTP/2 stream initiation. (Content from redhat.atlassian.net is not included.CRW-11970) - This content is not included.CVE-2026-49978:
DOMPurify-- Cross-site scripting vulnerability allows code execution. (Content from redhat.atlassian.net is not included.CRW-11874) - This content is not included.CVE-2026-59869:
js-yaml-- Denial of Service via crafted YAML documents. (Content from redhat.atlassian.net is not included.CRW-11824) - This content is not included.CVE-2026-59873:
node-tar-- Denial of Service via crafted gzip bomb. (Content from redhat.atlassian.net is not included.CRW-11759) - This content is not included.CVE-2026-59874:
Node-tar-- Denial of Service via malformed tar archive header. (Content from redhat.atlassian.net is not included.CRW-11762) - This content is not included.CVE-2026-59877:
protobufjs-- Denial of Service via crafted .proto schema. (Content from redhat.atlassian.net is not included.CRW-11936) - This content is not included.CVE-2026-67213:
nanoid-- Denial of Service via infinite loop in random ID generation. (Content from redhat.atlassian.net is not included.CRW-12642) - This content is not included.CVE-2026-67214:
nanoid-- Denial of Service via negative size input in non-secure module functions. (Content from redhat.atlassian.net is not included.CRW-12673) - This content is not included.CVE-2026-69152:
brace-expansion-- Denial of Service via unbounded intermediate arrays. (Content from redhat.atlassian.net is not included.CRW-12223) - This content is not included.CVE-2026-73086:
nanoid-- Predictable ID generation due to integer overflow. (Content from redhat.atlassian.net is not included.CRW-12361) - This content is not included.CVE-2026-8286:
curl-- Insecure connection establishment due to TLS configuration mismatch. (Content from redhat.atlassian.net is not included.CRW-11694) - This content is not included.CVE-2026-9277:
shell-quote-- Arbitrary code execution via command injection due to unescaped line terminators. (Content from redhat.atlassian.net is not included.CRW-12134) - This content is not included.CVE-2026-9547:
curl-- Man-in-the-middle attack via SSH host key bypass. (Content from redhat.atlassian.net is not included.CRW-11686)
configbump-rhel9
- This content is not included.CVE-2026-39820:
Go net/mail-- Denial of Service via crafted email inputs. (Content from redhat.atlassian.net is not included.CRW-11391) - This content is not included.CVE-2026-42499:
net/mail-- Denial of Service via pathological email address parsing. (Content from redhat.atlassian.net is not included.CRW-11385)
dashboard-rhel9
- This content is not included.CVE-2026-12151:
undici-- Denial of Service due to unbounded memory growth via WebSocket frames. (Content from redhat.atlassian.net is not included.CRW-12297)
multicluster-redirector-rhel9
- This content is not included.CVE-2026-47691:
Netty-- Insufficient Bailiwick Validation for NS Records. (Content from redhat.atlassian.net is not included.CRW-11834)
oauth2-proxy-rhel9
- This content is not included.CVE-2026-34986:
Go JOSE-- Denial of Service via crafted JSON Web Encryption (JWE) object. (Content from redhat.atlassian.net is not included.CRW-11845)
openvsx-rhel9
- This content is not included.CVE-2026-10050:
Eclipse Jetty-- Authentication bypass via Digest authentication encoding collision. (Content from redhat.atlassian.net is not included.CRW-12231) - This content is not included.CVE-2026-10051:
Eclipse Jetty-- Information disclosure due to retained HTTP/1.1 trailers across connections. (Content from redhat.atlassian.net is not included.CRW-12291) - This content is not included.CVE-2026-12151:
undici-- Denial of Service due to unbounded memory growth via WebSocket frames. (Content from redhat.atlassian.net is not included.CRW-12296) - This content is not included.CVE-2026-13149:
Brace-expansion-- Denial of Service due to exponential-time complexity. (Content from redhat.atlassian.net is not included.CRW-11661) - This content is not included.CVE-2026-40983:
Micrometer-- Denial of Service via specially crafted gRPC requests. (Content from redhat.atlassian.net is not included.CRW-12011) - This content is not included.CVE-2026-40984:
Micrometer-- Denial of Service via specially crafted HTTP requests. (Content from redhat.atlassian.net is not included.CRW-11783) - This content is not included.CVE-2026-41695:
Spring Data Commons-- Denial of Service via crafted property path strings. (Content from redhat.atlassian.net is not included.CRW-11594) - This content is not included.CVE-2026-41716:
Spring Data Commons-- Denial of Service due to cache exhaustion via attacker-supplied strings. (Content from redhat.atlassian.net is not included.CRW-11597) - This content is not included.CVE-2026-44705:
tmp-- Path traversal via unsanitized prefix/postfix enables directory escape. (Content from redhat.atlassian.net is not included.CRW-12261) - This content is not included.CVE-2026-45149:
brace-expansion-- Denial of Service due to excessive memory allocation when expanding large numeric ranges. (Content from redhat.atlassian.net is not included.CRW-11454) - This content is not included.CVE-2026-45416:
Netty-- Denial of Service due to eager buffer allocation in TLS handshake. (Content from redhat.atlassian.net is not included.CRW-12314) - This content is not included.CVE-2026-45623:
PostCSS-- Information disclosure and denial of service via crafted CSS input. (Content from redhat.atlassian.net is not included.CRW-12159) - This content is not included.CVE-2026-45674:
Netty-- Information disclosure and data manipulation due to improper CNAME record validation. (Content from redhat.atlassian.net is not included.CRW-12306) - This content is not included.CVE-2026-49978:
DOMPurify-- Cross-site scripting vulnerability allows code execution. (Content from redhat.atlassian.net is not included.CRW-11881) - This content is not included.CVE-2026-50010:
Netty-- Improper trust manager handling leads to hostname verification bypass. (Content from redhat.atlassian.net is not included.CRW-12304) - This content is not included.CVE-2026-50193:
Jackson-databind-- Denial of Service via deeply nested JSON processing. (Content from redhat.atlassian.net is not included.CRW-11568) - This content is not included.CVE-2026-54399:
Apache HttpComponents Core-- Denial of Service via excessive HTTP headers. (Content from redhat.atlassian.net is not included.CRW-11801) - This content is not included.CVE-2026-54428:
Apache HttpComponents Core-- Denial of Service via oversized HTTP/2 HPACK header blocks. (Content from redhat.atlassian.net is not included.CRW-11809) - This content is not included.CVE-2026-54512:
jackson-databind-- Arbitrary code execution via PolymorphicTypeValidator bypass. (Content from redhat.atlassian.net is not included.CRW-11554) - This content is not included.CVE-2026-55831:
Netty-- Denial of Service via SPDY SETTINGS frame processing. (Content from redhat.atlassian.net is not included.CRW-12024) - This content is not included.CVE-2026-55833:
Netty-- Denial of Service via SPDY header decompression amplification. (Content from redhat.atlassian.net is not included.CRW-11989) - This content is not included.CVE-2026-56745:
Netty-- Denial of Service via memory exhaustion in SPDY-to-HTTP codec. (Content from redhat.atlassian.net is not included.CRW-12094) - This content is not included.CVE-2026-56746:
Netty-- Security control bypass allows unauthorized requests via null origin header. (Content from redhat.atlassian.net is not included.CRW-12076) - This content is not included.CVE-2026-56819:
Netty-- Denial of Service via HTTP/2 DATA frame memory leak. (Content from redhat.atlassian.net is not included.CRW-12059) - This content is not included.CVE-2026-59869:
js-yaml-- Denial of Service via crafted YAML documents. (Content from redhat.atlassian.net is not included.CRW-11822) - This content is not included.CVE-2026-59873:
node-tar-- Denial of Service via crafted gzip bomb. (Content from redhat.atlassian.net is not included.CRW-11751) - This content is not included.CVE-2026-59874:
Node-tar-- Denial of Service via malformed tar archive header. (Content from redhat.atlassian.net is not included.CRW-11773) - This content is not included.CVE-2026-59888:
jackson-databind-- @JsonIgnore bypass in Java Records. (Content from redhat.atlassian.net is not included.CRW-12142) - This content is not included.CVE-2026-59899:
Netty-- Memory exhaustion in netty-codec-http (decompression bomb). (Content from redhat.atlassian.net is not included.CRW-12041) - This content is not included.CVE-2026-68494:
jackson-core-- Denial of Service via incomplete fix in async JSON parser. (Content from redhat.atlassian.net is not included.CRW-12250) - This content is not included.CVE-2026-69153:
PostCSS-- Information disclosure via crafted sourceMappingURL. (Content from redhat.atlassian.net is not included.CRW-12203) - This content is not included.CVE-2026-9563:
Eclipse Parsson-- Denial of Service via uncontrolled resource consumption in JSON parsing. (Content from redhat.atlassian.net is not included.CRW-11768)
pluginregistry-rhel9
- This content is not included.CVE-2026-10050:
Eclipse Jetty-- Authentication bypass via Digest authentication encoding collision. (Content from redhat.atlassian.net is not included.CRW-12232) - This content is not included.CVE-2026-10051:
Eclipse Jetty-- Information disclosure due to retained HTTP/1.1 trailers across connections. (Content from redhat.atlassian.net is not included.CRW-12292) - This content is not included.CVE-2026-12151:
undici-- Denial of Service due to unbounded memory growth via WebSocket frames. (Content from redhat.atlassian.net is not included.CRW-12295) - This content is not included.CVE-2026-13149:
Brace-expansion-- Denial of Service due to exponential-time complexity. (Content from redhat.atlassian.net is not included.CRW-11665) - This content is not included.CVE-2026-40983:
Micrometer-- Denial of Service via specially crafted gRPC requests. (Content from redhat.atlassian.net is not included.CRW-12010) - This content is not included.CVE-2026-40984:
Micrometer-- Denial of Service via specially crafted HTTP requests. (Content from redhat.atlassian.net is not included.CRW-11786) - This content is not included.CVE-2026-41695:
Spring Data Commons-- Denial of Service via crafted property path strings. (Content from redhat.atlassian.net is not included.CRW-11591) - This content is not included.CVE-2026-41716:
Spring Data Commons-- Denial of Service due to cache exhaustion via attacker-supplied strings. (Content from redhat.atlassian.net is not included.CRW-11600) - This content is not included.CVE-2026-44705:
tmp-- Path traversal via unsanitized prefix/postfix enables directory escape. (Content from redhat.atlassian.net is not included.CRW-12266) - This content is not included.CVE-2026-45149:
brace-expansion-- Denial of Service due to excessive memory allocation when expanding large numeric ranges. (Content from redhat.atlassian.net is not included.CRW-11447) - This content is not included.CVE-2026-45416:
Netty-- Denial of Service due to eager buffer allocation in TLS handshake. (Content from redhat.atlassian.net is not included.CRW-12311) - This content is not included.CVE-2026-45674:
Netty-- Information disclosure and data manipulation due to improper CNAME record validation. (Content from redhat.atlassian.net is not included.CRW-12309) - This content is not included.CVE-2026-50010:
Netty-- Improper trust manager handling leads to hostname verification bypass. (Content from redhat.atlassian.net is not included.CRW-12303) - This content is not included.CVE-2026-50193:
Jackson-databind-- Denial of Service via deeply nested JSON processing. (Content from redhat.atlassian.net is not included.CRW-11571) - This content is not included.CVE-2026-54399:
Apache HttpComponents Core-- Denial of Service via excessive HTTP headers. (Content from redhat.atlassian.net is not included.CRW-11803) - This content is not included.CVE-2026-54428:
Apache HttpComponents Core-- Denial of Service via oversized HTTP/2 HPACK header blocks. (Content from redhat.atlassian.net is not included.CRW-11810) - This content is not included.CVE-2026-54512:
jackson-databind-- Arbitrary code execution via PolymorphicTypeValidator bypass. (Content from redhat.atlassian.net is not included.CRW-11555) - This content is not included.CVE-2026-55831:
Netty-- Denial of Service via SPDY SETTINGS frame processing. (Content from redhat.atlassian.net is not included.CRW-12025) - This content is not included.CVE-2026-55833:
Netty-- Denial of Service via SPDY header decompression amplification. (Content from redhat.atlassian.net is not included.CRW-11990) - This content is not included.CVE-2026-56745:
Netty-- Denial of Service via memory exhaustion in SPDY-to-HTTP codec. (Content from redhat.atlassian.net is not included.CRW-12095) - This content is not included.CVE-2026-56746:
Netty-- Security control bypass allows unauthorized requests via null origin header. (Content from redhat.atlassian.net is not included.CRW-12077) - This content is not included.CVE-2026-56819:
Netty-- Denial of Service via HTTP/2 DATA frame memory leak. (Content from redhat.atlassian.net is not included.CRW-12060) - This content is not included.CVE-2026-59888:
jackson-databind-- @JsonIgnore bypass in Java Records. (Content from redhat.atlassian.net is not included.CRW-12146) - This content is not included.CVE-2026-59899:
Netty-- Memory exhaustion in netty-codec-http (decompression bomb). (Content from redhat.atlassian.net is not included.CRW-12042) - This content is not included.CVE-2026-68494:
jackson-core-- Denial of Service via incomplete fix in async JSON parser. (Content from redhat.atlassian.net is not included.CRW-12252) - This content is not included.CVE-2026-9563:
Eclipse Parsson-- Denial of Service via uncontrolled resource consumption in JSON parsing. (Content from redhat.atlassian.net is not included.CRW-11769)
server-rhel9
- This content is not included.CVE-2026-15075:
Eclipse Vert.x-- Information disclosure via improper handling of HTTP 30x redirects. (Content from redhat.atlassian.net is not included.CRW-11868) - This content is not included.CVE-2026-15076:
Eclipse Vert.x Web Client-- Information disclosure via improper cookie domain validation. (Content from redhat.atlassian.net is not included.CRW-12123) - This content is not included.CVE-2026-59888:
jackson-databind-- @JsonIgnore bypass in Java Records. (Content from redhat.atlassian.net is not included.CRW-12147) - This content is not included.CVE-2026-68494:
jackson-core-- Denial of Service via incomplete fix in async JSON parser. (Content from redhat.atlassian.net is not included.CRW-12253)
traefik-rhel9
- This content is not included.CVE-2026-27136:
golang.org/x/net/html-- Cross-Site Scripting via HTML parsing bypass. (Content from redhat.atlassian.net is not included.CRW-11618) - This content is not included.CVE-2026-34986:
Go JOSE-- Denial of Service via crafted JSON Web Encryption (JWE) object. (Content from redhat.atlassian.net is not included.CRW-11842) - This content is not included.CVE-2026-39820:
Go net/mail-- Denial of Service via crafted email inputs. (Content from redhat.atlassian.net is not included.CRW-11390) - This content is not included.CVE-2026-39831:
golang.org/x/crypto/ssh-- Security key bypass due to missing user presence check. (Content from redhat.atlassian.net is not included.CRW-11716) - This content is not included.CVE-2026-39835:
golang.org/x/crypto/ssh-- Denial of Service via crafted SSH certificate. (Content from redhat.atlassian.net is not included.CRW-11525) - This content is not included.CVE-2026-40898:
quic-go-- Denial of Service via excessive memory allocation in HTTP/3 trailers. (Content from redhat.atlassian.net is not included.CRW-11746) - This content is not included.CVE-2026-42499:
net/mail-- Denial of Service via pathological email address parsing. (Content from redhat.atlassian.net is not included.CRW-11386) - This content is not included.CVE-2026-46597:
golang.org/x/crypto/ssh-- Denial of Service via crafted AES-GCM packet decoder inputs. (Content from redhat.atlassian.net is not included.CRW-11726) - This content is not included.CVE-2026-48020:
Traefik-- Authentication bypass in StripPrefix middleware allows unauthorized access to protected paths. (Content from redhat.atlassian.net is not included.CRW-11487) - This content is not included.CVE-2026-48491:
Traefik-- Unauthorized access due to mutual TLS bypass. (Content from redhat.atlassian.net is not included.CRW-11480) - This content is not included.CVE-2026-53488:
containerd-- Host-root command execution via unvalidated image config labels in CRI plugin. (Content from redhat.atlassian.net is not included.CRW-11583) - This content is not included.CVE-2026-53492:
containerd-- Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration. (Content from redhat.atlassian.net is not included.CRW-11638) - This content is not included.CVE-2026-53622:
Traefik-- MTLS enforcement bypass due to HTTP/3 TLS configuration flaw. (Content from redhat.atlassian.net is not included.CRW-11476) - This content is not included.CVE-2026-54763:
Traefik-- Identity spoofing via improper header handling in authentication middlewares. (Content from redhat.atlassian.net is not included.CRW-11965) - This content is not included.CVE-2026-65600:
Traefik-- Authentication bypass via path traversal in ReplacePathRegex middleware. (Content from redhat.atlassian.net is not included.CRW-11972) - This content is not included.CVE-2026-65601:
Traefik-- Privilege Escalation via Kubernetes Gateway API Namespace Confusion. (Content from redhat.atlassian.net is not included.CRW-11962)
udi-rhel9
- This content is not included.CVE-2026-34986:
Go JOSE-- Denial of Service via crafted JSON Web Encryption (JWE) object. (Content from redhat.atlassian.net is not included.CRW-11843)