Skip to main content
EPSS 1.1%top 35%

Red Hat Security Advisory: Red Hat Developer Hub 1.7.2 release.

0
Medium
Published: 11/03/2025 (11/03/2025, 21:56:14 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Kiali 2.11.4, for Red Hat OpenShift Service Mesh 3.1, provides observability for the service mesh by offering a visual representation of the mesh topology and metrics, helping users monitor, trace, and manage efficiently. Security Fix(es): * kiali-ossmc-rhel9: Axios DoS via lack of data size check (CVE-2025-58754) * kiali-rhel9: Axios DoS via lack of data size check (CVE-2025-58754)

Affected software

Affected versions
>=1.6.0 <1.6.5Red HatRed Hat Developer HubRed Hat Developer Hub 1.7amd64registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:385d0b730e3f14f6878221d817b58d31da560c2edc52235b74bbbd8324b29389_amd64Red Hat Advanced Cluster SecurityRed Hat Advanced Cluster Security 4.7registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:fc1cebb18febc72175ebaee8b32b3dd6bd6bda4ccef9b2fdf3c8da09b2979ffa_amd64Red Hat Developer Hub 1.6registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:7498105e03c741dd2ac9c39ad4ff9f22c4fee7dd40b2fd9c599996a7e67b3562_amd64Red Hat Developer Hub (RHDH)Red Hat Developer Hub (RHDH) 1.6Red Hat OpenShift Service MeshRed Hat OpenShift Service Mesh 3.1registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:672ba265f8b4745d4d7cb324ae8f883e732986499bad4a72dee82f37567623f8_amd64Red Hat Advanced Cluster Security 4.8registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:51fbb1551be13e73fc2f8af5d0918eafabc9ff12660d75a1f98ebdd578f37f65_amd64registry.redhat.io/advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:83cf26fecffc10ac1e2500caeffdb8d1dba5d0271494fa8cdbdf478633d7e54c_amd64RHDHRHDH 1.6

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 20:21:18 UTC

Technical Analysis

CVE-2025-58754 describes a denial of service vulnerability in the Axios npm package when running on Node.js. When Axios is given a URL with the data: scheme, it bypasses HTTP processing and decodes the entire payload into memory without enforcing maxContentLength or maxBodyLength limits. This allows an attacker to supply a large data URI, causing unbounded memory allocation and crashing the application process. The vulnerability affects Red Hat Developer Hub versions from 1.6.0 up to but not including 1.6.5. The impact is limited to the application bundling Axios and does not affect the underlying Red Hat system. Red Hat Developer Hub 1.6.5 release addresses this issue.

Potential Impact

The vulnerability allows an attacker to cause a denial of service by forcing the affected application to allocate excessive memory and crash. This impacts availability of the Red Hat Developer Hub application but does not compromise confidentiality or integrity. The host system remains unaffected. There are no known exploits in the wild at this time.

Mitigation Recommendations

Red Hat Developer Hub 1.6.5 includes a fix for this vulnerability. Users should upgrade affected versions (>=1.6.0 <1.6.5) to 1.6.5 or later to remediate the issue. No other mitigation is currently available or meets Red Hat's criteria for ease of use and stability. Since this is an application-level issue, remediation requires updating the affected software.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:19529
Cve Count
2
Additional Cves
["CVE-2025-59343"]

Threat ID: 6a32706b0b89be68881d6741

Added to database: 06/17/2026, 10:01:15 UTC

Last enriched: 08/13/2026, 20:21:18 UTC

Last updated: 09/10/2026, 20:10:26 UTC

Views: 72

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses