RHSA-2025:14090HighCVSS 8.1

Red Hat Security Advisory: Red Hat Developer Hub 1.7.0 release.

Published
August 19, 2025
Last Modified
July 20, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2025-5417 — rhdh: Red Hat Developer Hub user permissions CVE-2025-6545 — pbkdf2: pbkdf2 silently returns predictable key material CVE-2025-7338 — multer: Multer Denial of Service CVE-2025-22870 — golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net CVE-2025-32996 — http-proxy-middleware: Always-Incorrect Control Flow Implementation in http-proxy-middleware CVE-2025-32997 — http-proxy-middleware: Improper Check for Unusual or Exceptional Conditions in http-proxy-middleware CVE-2025-48387 — tar-fs: tar-fs has issue where extract can write outside the specified dir with a specific tarball CVE-2025-48997 — multer: Multer vulnerable to Denial of Service via unhandled exception CVE-2025-54419 — @node-saml/node-saml: Node-SAML Signature Verification Vulnerability

🔗 References (18)