Skip to main content
EPSS 0.4%top 64%

Red Hat Security Advisory: Apicurio Registry (container images) release and security update [ 3.3.1 GA ]

0
High
Published: 08/25/2026 (08/25/2026, 10:07:13 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This release of Red Hat build of Apicurio Registry 3.3.1 GA includes the following security fixes. Security Fix(es): * DOMPurify: Cross-site scripting vulnerability allows code execution [rhint-serv-3] (CVE-2026-49978) * apicurio-registry: Unhardened SAXParser in content-type detection leads to blind XXE / SSRF / billion-laughs DoS [rhint-serv-3] (CVE-2026-12975) * apicurio-registry: SSRF via wsdl4j import dereference in WSDL FULL validation [rhint-serv-3] (CVE-2026-12992) * apicurio-registry: XML entity-expansion denial of service via internal DTD subset [rhint-serv-3] (CVE-2026-12993) * Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name [rhint-serv-3] (CVE-2026-44496) * DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization [rhint-serv-3] (CVE-2026-41240) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected software

Affected versions
=3.3.1Red HatRed Hat IntegrationRed Hat build of Apicurio Registry 3.3.1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 13:46:12 UTC

Technical Analysis

This Red Hat security advisory covers multiple vulnerabilities fixed in the Red Hat build of Apicurio Registry 3.3.1 GA container images. Key issues include CVE-2026-12975, where an unhardened SAXParser in content-type detection allows blind XXE, SSRF, and billion-laughs denial of service attacks due to insecure XML parsing without secure processing features or external entity resolution disabled. Other vulnerabilities fixed include SSRF via WSDL import dereference (CVE-2026-12992), XML entity-expansion DoS via internal DTD subset (CVE-2026-12993), client-side DoS in Axios from unescaped regex metacharacters in XSRF cookie names (CVE-2026-44496), and multiple DOMPurify XSS issues (CVE-2026-49978, CVE-2026-41240). The advisory references CVSS scores where available and provides links for further details. The vulnerabilities impact XML processing and client-side sanitization components, potentially allowing code execution, denial of service, and SSRF attacks.

Potential Impact

The vulnerabilities allow attackers to execute cross-site scripting attacks, cause denial of service through resource exhaustion, and perform server-side request forgery by exploiting XML parsing flaws and client-side sanitization issues. Specifically, CVE-2026-12975 enables attackers with artifact-write permission or unauthenticated attackers (under default configuration) to upload crafted XML documents that trigger blind SSRF or denial of service via entity expansion. The impact includes confidentiality loss through reading local files, availability impact via resource consumption, and potential bypass of protection mechanisms. The Axios vulnerability allows client-side denial of service. Overall, these issues pose a high security risk if unpatched.

Mitigation Recommendations

Red Hat has released updated container images for Apicurio Registry 3.3.1 GA that address these vulnerabilities. Users should apply this update promptly after ensuring all prior relevant errata are applied. Detailed update instructions are available from Red Hat's official documentation. No vendor advisory states that no action is required or that the issues are already mitigated; therefore, applying the official update is the recommended remediation. Monitor Red Hat advisories for any further updates or mitigations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:59360
Cve Count
6
Additional Cves
["CVE-2026-12992","CVE-2026-12993","CVE-2026-41240","CVE-2026-44496","CVE-2026-49978"]
State
PUBLISHED

Threat ID: 6a8effe2acd9273b490783ae

Added to database: 08/26/2026, 15:01:54 UTC

Last enriched: 09/08/2026, 13:46:12 UTC

Last updated: 10/10/2026, 18:48:17 UTC

Views: 57

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses