Skip to main content
EPSS 0.7%top 50%

Red Hat Security Advisory: Red Hat Developer Hub 1.6.4 release.

0
High
Published: 08/27/2025 (08/27/2025, 15:50:11 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Developer Hub (RHDH) is Red Hat's enterprise-grade, self-managed, customizable developer portal based on Backstage.io. RHDH is supported on OpenShift and other major Kubernetes clusters (AKS, EKS, GKE). The core features of RHDH include a single pane of glass, a centralized software catalog, self-service via golden path templates, and Tech Docs. RHDH is extensible by plugins.

Affected software

Affected versions
<1.6.4Red HatRHDHRHDH 1.6amd64registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:48b72d96926999336505cbf097f873dd9ccb2dec814a5db7f7ffa630dea29dc5_amd64Red Hat Developer HubRed Hat Developer Hub 1.6Red Hat Developer Hub (RHDH)Red Hat Developer Hub (RHDH) 1.6

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 17:16:50 UTC

Technical Analysis

CVE-2025-7338 is a denial of service vulnerability in the Multer NPM library, which is a component of Red Hat Developer Hub (RHDH). The flaw allows an attacker to cause a process crash by sending a malformed multi-part upload request that triggers an unhandled exception (CWE-248). This vulnerability affects Red Hat Developer Hub versions prior to 1.6.4. Red Hat has released RHDH 1.6.4, but no direct patch for the Multer vulnerability is currently available or meets Red Hat's standards for deployment. The vulnerability has a Red Hat CVSS v3 base score of 5.3 (medium impact) but is rated as high severity by Red Hat Product Security. No known exploits are reported in the wild.

Potential Impact

Successful exploitation results in a denial of service condition by crashing the affected process, potentially disrupting availability of the Red Hat Developer Hub service. There is no impact on confidentiality or integrity reported. The vulnerability arises from an unhandled exception in processing malformed multi-part upload requests.

Mitigation Recommendations

Currently, no direct fix or patch is available that meets Red Hat's criteria for ease of use, deployment, and applicability. Users are advised to upgrade to Red Hat Developer Hub 1.6.4, which is the latest release. Red Hat does not provide additional mitigation options at this time. Customers with a Technical Account Manager (TAM) can consult directly for further guidance. Monitoring for updates from Red Hat is recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:14767
Cve Count
3
Additional Cves
["CVE-2025-9287","CVE-2025-9288"]

Threat ID: 6a3cc29c4853345fc16d324b

Added to database: 06/25/2026, 05:54:36 UTC

Last enriched: 08/16/2026, 17:16:50 UTC

Last updated: 09/10/2026, 19:36:52 UTC

Views: 34

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses