VYPR

Developer Hub

by Red Hat

CVEs (5)

  • CVE-2026-3118MedFeb 25, 2026
    risk 0.42cvss 6.5epss 0.01

    A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to insufficient input validation in GraphQL query handling. An authenticated user can inject specially crafted input into API requests, which disrupts backend…

  • CVE-2025-14874HigDec 18, 2025
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.

  • CVE-2025-5417MedAug 19, 2025
    risk 0.40cvss 6.1epss 0.00

    An insufficient access control vulnerability was found in the Red Hat Developer Hub rhdh/rhdh-hub-rhel9 container image. The Red Hat Developer Hub cluster admin/user, who has standard user access to the cluster, and the Red Hat Developer Hub namespace, can access the…

  • CVE-2026-44495HigJun 11, 2026
    risk 0.39cvss 7.0epss 0.01

    Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted…

  • CVE-2023-6944MedJan 4, 2024
    risk 0.30cvss 5.7epss 0.01

    A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw…