Red Hat Security Advisory: Red Hat Developer Hub 1.9.4 release.
Red Hat Developer Hub (RHDH) is Red Hat's enterprise-grade, self-managed, customizable developer portal based on Backstage.io. RHDH is supported on OpenShift and other major Kubernetes clusters (AKS, EKS, GKE). The core features of RHDH include a single pane of glass, a centralized software catalog, self-service via golden path templates, and Tech Docs. RHDH is extensible by plugins.
AI Analysis
Technical Summary
CVE-2025-62718 is a security flaw in Axios where hostname normalization is improperly handled when evaluating NO_PROXY rules. This allows attackers to craft requests to loopback addresses (e.g., localhost or [::1]) that bypass NO_PROXY and are routed through the configured proxy, enabling SSRF attacks. The vulnerability requires that the application uses Axios server-side with both HTTP_PROXY and NO_PROXY configured, and that the proxy is positioned to intercept or be compromised to misuse the rerouted traffic. Red Hat has identified this vulnerability affecting multiple products including Red Hat Developer Hub and multicluster engine for Kubernetes. The advisory notes no current patch or mitigation meeting Red Hat's standards is available. The CVSS score is not provided by Red Hat, but the severity is rated critical based on impact.
Potential Impact
Successful exploitation can lead to Server-Side Request Forgery (SSRF), allowing attackers to access sensitive internal or loopback services that should be protected by NO_PROXY rules. However, exploitation is limited by the need for specific conditions: attacker-controlled URLs passed to Axios in a server-side context, presence of both HTTP_PROXY and NO_PROXY environment variables, and a proxy capable of intercepting or being compromised to misuse the traffic. This vulnerability could expose internal network resources and services to attackers.
Mitigation Recommendations
Currently, there is no official fix or mitigation that meets Red Hat's criteria for ease of use, applicability, or stability. Users should monitor Red Hat advisories for updates. Given the complexity and limited exploit conditions, review application usage of Axios with proxy configurations and consider restricting attacker control over URLs passed to Axios. Engage with Red Hat support or Technical Account Managers for guidance. Avoid relying solely on NO_PROXY configurations for security until a fix is available.
Red Hat Security Advisory: Red Hat Developer Hub 1.9.4 release.
Description
Red Hat Developer Hub (RHDH) is Red Hat's enterprise-grade, self-managed, customizable developer portal based on Backstage.io. RHDH is supported on OpenShift and other major Kubernetes clusters (AKS, EKS, GKE). The core features of RHDH include a single pane of glass, a centralized software catalog, self-service via golden path templates, and Tech Docs. RHDH is extensible by plugins.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-62718 is a security flaw in Axios where hostname normalization is improperly handled when evaluating NO_PROXY rules. This allows attackers to craft requests to loopback addresses (e.g., localhost or [::1]) that bypass NO_PROXY and are routed through the configured proxy, enabling SSRF attacks. The vulnerability requires that the application uses Axios server-side with both HTTP_PROXY and NO_PROXY configured, and that the proxy is positioned to intercept or be compromised to misuse the rerouted traffic. Red Hat has identified this vulnerability affecting multiple products including Red Hat Developer Hub and multicluster engine for Kubernetes. The advisory notes no current patch or mitigation meeting Red Hat's standards is available. The CVSS score is not provided by Red Hat, but the severity is rated critical based on impact.
Potential Impact
Successful exploitation can lead to Server-Side Request Forgery (SSRF), allowing attackers to access sensitive internal or loopback services that should be protected by NO_PROXY rules. However, exploitation is limited by the need for specific conditions: attacker-controlled URLs passed to Axios in a server-side context, presence of both HTTP_PROXY and NO_PROXY environment variables, and a proxy capable of intercepting or being compromised to misuse the traffic. This vulnerability could expose internal network resources and services to attackers.
Mitigation Recommendations
Currently, there is no official fix or mitigation that meets Red Hat's criteria for ease of use, applicability, or stability. Users should monitor Red Hat advisories for updates. Given the complexity and limited exploit conditions, review application usage of Axios with proxy configurations and consider restricting attacker control over URLs passed to Axios. Engage with Red Hat support or Technical Account Managers for guidance. Avoid relying solely on NO_PROXY configurations for security until a fix is available.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:13826
- Cve Count
- 25
- Additional Cves
- ["CVE-2025-69534","CVE-2026-1525","CVE-2026-1526","CVE-2026-1528","CVE-2026-2229","CVE-2026-3118","CVE-2026-4800","CVE-2026-4926","CVE-2026-27601","CVE-2026-27904","CVE-2026-29063","CVE-2026-29074","CVE-2026-29186","CVE-2026-32141","CVE-2026-32280","CVE-2026-32282","CVE-2026-33228","CVE-2026-33891","CVE-2026-33894","CVE-2026-33895","CVE-2026-33896","CVE-2026-39983","CVE-2026-40175","CVE-2026-40895"]
Threat ID: 6a160974e29bf47b5063da1d
Added to database: 05/26/2026, 20:58:28 UTC
Last enriched: 08/14/2026, 22:48:18 UTC
Last updated: 09/15/2026, 01:45:46 UTC
Views: 155
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.