VDB
RHSA-2026%3A0531
RHSA-2026%3A0531
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in qs, a module used for parsing query strings. A remote attacker can exploit an improper input validation vulnerability by sending specially crafted HTTP requests that use bracket notation (e.g., `a[]=value`). This bypasses the `arrayLimit` option, which is designed to limit the size of parsed arrays and prevent resource exhaustion. Successful exploitation can lead to memory exhaustion, causing a Denial of Service (DoS) where the application crashes or becomes unresponsive, making the service unavailable to users.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:926035e11898ddff4ca044e19ec6daf5f159ad4dcf231ae3ab4a188f4c7ec0dd_amd64 as a component of Red Hat Developer Hub 1.8 | *, registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:926035e11898ddff4ca044e19ec6daf5f159ad4dcf231ae3ab4a188f4c7ec0dd_amd64, * |
| Red Hat | registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:926035e11898ddff4ca044e19ec6daf5f159ad4dcf231ae3ab4a188f4c7ec0dd_amd64 as a component of Red Hat Developer Hub 1.8 | registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:926035e11898ddff4ca044e19ec6daf5f159ad4dcf231ae3ab4a188f4c7ec0dd_amd64, registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:926035e11898ddff4ca044e19ec6daf5f159ad4dcf231ae3ab4a188f4c7ec0dd_amd64, registry.redhat.io/rhdh/rhdh-operator-bundle@sha256:926035e11898ddff4ca044e19ec6daf5f159ad4dcf231ae3ab4a188f4c7ec0dd_amd64 |
| Red Hat | registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:2075e690aa63b47dc2e0866bb0ca5eb6924a05176243a60c8f58c8885adf7e02_amd64 as a component of Red Hat Developer Hub 1.8 | registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:2075e690aa63b47dc2e0866bb0ca5eb6924a05176243a60c8f58c8885adf7e02_amd64, registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:2075e690aa63b47dc2e0866bb0ca5eb6924a05176243a60c8f58c8885adf7e02_amd64, * |
| Red Hat | registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:2075e690aa63b47dc2e0866bb0ca5eb6924a05176243a60c8f58c8885adf7e02_amd64 as a component of Red Hat Developer Hub 1.8 | registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:2075e690aa63b47dc2e0866bb0ca5eb6924a05176243a60c8f58c8885adf7e02_amd64, *, registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:2075e690aa63b47dc2e0866bb0ca5eb6924a05176243a60c8f58c8885adf7e02_amd64 |
| Red Hat | registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:7185a8f744022307c7a178d35e7ae32d7797eed4f9379b2dba8954e2856f2ed1_amd64 as a component of Red Hat Developer Hub 1.8 | registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:7185a8f744022307c7a178d35e7ae32d7797eed4f9379b2dba8954e2856f2ed1_amd64, registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:7185a8f744022307c7a178d35e7ae32d7797eed4f9379b2dba8954e2856f2ed1_amd64, registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:7185a8f744022307c7a178d35e7ae32d7797eed4f9379b2dba8954e2856f2ed1_amd64 |
| Red Hat | registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:7185a8f744022307c7a178d35e7ae32d7797eed4f9379b2dba8954e2856f2ed1_amd64 as a component of Red Hat Developer Hub 1.8 | registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:7185a8f744022307c7a178d35e7ae32d7797eed4f9379b2dba8954e2856f2ed1_amd64, *, registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:7185a8f744022307c7a178d35e7ae32d7797eed4f9379b2dba8954e2856f2ed1_amd64 |
Timeline
- Jan 13, 2026 CVE Published
- Apr 29, 2026 Security Advisory
- May 6, 2026 Security Advisory
- May 7, 2026 Distribution Patch
- May 8, 2026 Distribution Patch
- May 8, 2026 Security Advisory
- May 13, 2026 Security Advisory
- May 16, 2026 CVE Updated
References
- https://issues.redhat.com/browse/RHIDP-11242 advisory
- https://access.redhat.com/security/cve/CVE-2025-64756 advisory
- https://issues.redhat.com/browse/RHIDP-11116 advisory
- https://developers.redhat.com/rhdh/overview advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2425946 issue
- https://github.com/isaacs/node-glob/security/advisories/GHSA-5j98-mcp5-4vw2 advisory
- https://catalog.redhat.com/search?gs&searchType=containers&q=rhdh advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2415451 issue
- https://nvd.nist.gov/vuln/detail/CVE-2025-64756 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-15284 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_0531.json advisory
- https://www.cve.org/CVERecord?id=CVE-2025-15284 advisory
- https://access.redhat.com/errata/RHSA-2026:0531 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418904 issue
- https://access.redhat.com/security/cve/CVE-2025-15284 advisory
- https://issues.redhat.com/browse/RHIDP-11118 advisory
- https://github.com/ljharb/qs/security/advisories/GHSA-6rw7-vpxm-498p advisory
- https://www.cve.org/CVERecord?id=CVE-2025-64756 advisory
- https://access.redhat.com/security/cve/CVE-2025-65945 advisory
…and 7 more