Technology · Red Hat
Red Hat Developer Hub vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 28 vulnerabilities in Red Hat Developer Hub: 0 in the last 7 days and 0 in the last 90 days, 10 of them critical and 0 exploited in the wild. The most recent, CVE-2026-43999, was published on 13 May 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 10
- Exploited in the wild
- 0
About Red Hat Developer Hub
Internal developer portal based on Backstage for managing software development life cycles.
Latest Red Hat Developer Hub vulnerabilities
- CVE-2026-43999: patriksimek vm2 remote code execution via NodeVM allowlist bypasscriticalCVSS 9.9EPSS 1.0%
- CVE-2026-43998: patriksimek vm2 remote code execution via symlink traversal in NodeVMhighCVSS 8.5EPSS 0.9%
- CVE-2026-44293: protobufjs code injection in toObject function generationhighCVSS 8.8EPSS 0.7%
- CVE-2026-6322: Fastify fast-uri host confusion via percent-encoded authority delimitershighCVSS 7.5EPSS 0.7%
- CVE-2026-6321: OpenJS Foundation fast-uri path traversal via percent-encoded dot segmentshighCVSS 7.5EPSS 0.8%
- CVE-2026-26956: patriksimek vm2 sandbox escape via WebAssembly JSTagcriticalCVSS 9.8EPSS 0.9%
- CVE-2026-26332: patriksimek vm2 sandbox escape via SuppressedErrorcriticalCVSS 9.8EPSS 0.7%
- CVE-2026-24120: patriksimek vm2 sandbox escape via Promise species bypasscriticalCVSS 9.8EPSS 0.9%
- CVE-2026-24118: patriksimek vm2 sandbox breakout via descriptor-chain bypasscriticalCVSS 9.8EPSS 0.9%
- CVE-2026-40906: ElectricSQL SQL injection in /v1/shape API order_by parametercriticalCVSS 9.9EPSS 0.4%
- CVE-2026-40895: follow-redirects sensitive header leak in cross-domain redirectshighCVSS 7.5EPSS 0.8%
- CVE-2026-39983: patrickjuchli basic-ftp FTP command injection via CRLF sequenceshighCVSS 8.6EPSS 2.8%
- CVE-2026-33896: Digital Bazaar node-forge certificate validation bypass in verifyCertificateChainhighCVSS 7.4EPSS 0.5%
- CVE-2026-33894: Digital Bazaar node-forge signature forgery in RSASSA PKCS#1 v1.5highCVSS 7.5EPSS 0.4%
- CVE-2026-33891: Digital Bazaar node-forge infinite loop in BigInteger.modInversehighCVSS 7.5EPSS 0.9%
- CVE-2026-4926: path-to-regexp denial of service via sequential optional groupshighCVSS 7.5EPSS 0.9%
- CVE-2026-33228: WebReflection flatted prototype pollution in parse functioncriticalCVSS 9.8EPSS 1.0%
- CVE-2026-33001: Jenkins arbitrary file write via symbolic link extraction in archiveshighCVSS 8.8EPSS 0.7%
- CVE-2025-69196: PrefectHQ FastMCP improper resource handling in OAuth ProxymediumCVSS 6.5EPSS 0.4%
- CVE-2026-29186: Backstage TechDocs arbitrary code execution via MkDocs configuration bypasshighCVSS 7.7EPSS 0.9%
- CVE-2026-25896: NaturalIntelligence fast-xml-parser XSS via regex injection in DOCTYPEcriticalCVSS 9.3EPSS 0.5%
- CVE-2026-26318: sebhildebrandt systeminformation command injection in versions functionhighCVSS 8.8EPSS 1.3%
- CVE-2026-26280: sebhildebrandt systeminformation command injection in wifiNetworkshighCVSS 8.4EPSS 1.5%
- CVE-2026-26278: NaturalIntelligence fast-xml-parser denial of service via entity expansionhighCVSS 7.5EPSS 1.0%
- CVE-2026-1615: dchester jsonpath code injection via unsafe evaluationcriticalCVSS 9.8EPSS 1.1%
Most severe Red Hat Developer Hub vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-43999: patriksimek vm2 remote code execution via NodeVM allowlist bypasscriticalCVSS 9.9EPSS 1.0%
- CVE-2026-40906: ElectricSQL SQL injection in /v1/shape API order_by parametercriticalCVSS 9.9EPSS 0.4%
- CVE-2026-1615: dchester jsonpath code injection via unsafe evaluationcriticalCVSS 9.8EPSS 1.1%
- CVE-2026-33228: WebReflection flatted prototype pollution in parse functioncriticalCVSS 9.8EPSS 1.0%
- CVE-2026-24118: patriksimek vm2 sandbox breakout via descriptor-chain bypasscriticalCVSS 9.8EPSS 0.9%
- CVE-2026-24120: patriksimek vm2 sandbox escape via Promise species bypasscriticalCVSS 9.8EPSS 0.9%
- CVE-2026-26956: patriksimek vm2 sandbox escape via WebAssembly JSTagcriticalCVSS 9.8EPSS 0.9%
- CVE-2026-26332: patriksimek vm2 sandbox escape via SuppressedErrorcriticalCVSS 9.8EPSS 0.7%
- CVE-2025-61140: dchester jsonpath prototype pollution in value functioncriticalCVSS 9.8EPSS 0.4%
- CVE-2026-25896: NaturalIntelligence fast-xml-parser XSS via regex injection in DOCTYPEcriticalCVSS 9.3EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/developer-hub.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Red Hat Developer Hub vulnerabilities", https://junglewise.ai/threats/technologies/developer-hub, 26 September 2026.