Red Hat OpenShift Dev Spaces
Red Hat OpenShift DevSpaces is a container-based, in-browser development environment offered by Red Hat that facilitates cloud-native development directly within the OpenShift ecosystem. By leveraging OpenShift DevSpaces with fully configured, secure cloud development environments, developers can streamline their workflows, collaborate efficiently, and enhance their productivity - which is optimized for modern application development.
Browse the latest documentation
Latest security advisories
| Severity | Advisory/CVE | Synopsis | Date |
|---|---|---|---|
| Severity Moderate | Advisory/CVECVE-2026-44517 | Synopsis A flaw was found in Buildah. Insecure handling of temporary directories and symlinks during the image build process, specifically within `TempDirForURL`, `downloadToDirectory`, and `stdinToDirectory` functions, allows a malicious server supplying a Git repository or tar archive to cause files outside the build context directory to be included or copied into the build. This could lead to a build breakout, enabling an attacker to manipulate files on the host system. | Date |
| Severity Moderate | Advisory/CVECVE-2026-59296 | Synopsis A flaw was found in Micrometer's StatsD and Logging meter registries. This vulnerability allows a remote attacker to inject line terminators into metric data, such as names or tag values, due to insufficient sanitization of untrusted input. Exploitation can lead to the spoofing of arbitrary metrics, including critical system or business metrics, and the injection of false log entries, potentially impacting monitoring and auditing systems. | Date |
| Severity Important | Advisory/CVECVE-2026-71235 | Synopsis A flaw was found in Magistrala's Rules Engine. An authenticated low-privileged user can exploit this vulnerability by creating rules with embedded Go or Lua scripts. These scripts are executed server-side without sufficient validation, allowing for arbitrary file read and write operations, access to internal databases, and Server-Side Request Forgery (SSRF) against internal microservices. This could lead to significant data compromise and unauthorized system access. | Date |
| Severity Important | Advisory/CVE(RHSA-2026:48124) Red Hat OpenShift Dev Spaces 3.29.1 Release. | Synopsis Red Hat OpenShift Dev Spaces 3.29.1 Release. | Date |
| Severity Important | Advisory/CVECVE-2026-67214 | Synopsis A flaw was found in nanoid (Nano ID), a JavaScript library used for generating unique identifiers. This vulnerability allows an attacker to cause a Denial of Service (DoS) by providing a negative size input to the customAlphabet or nanoid functions within the library's non-secure module. When a negative size is provided, these functions enter an infinite loop, causing the application to hang indefinitely and disrupting service availability. | Date |
Top resources
Knowledgebase
Access articles and solutions to find answers to your questions.
Troubleshooting
Connect to the right information to self-solve issues quickly and efficiently.
Lifecycle
View the various levels of maintenance for each release of a product over a period from initial release to the end of maintenance.
Red Hat Developer
Learn more about Red Hat OpenShift Dev Spaces.
Get support
Support cases
Get answers quickly by opening a support case with us.
Live chat
Directly access our support engineers during weekday business hours.
Call or email
Speak directly with a Red Hat Support expert by phone or through email.