Red Hat 3scale API Management
Red Hat 3scale API Management makes it easy to manage your APIs. Share, secure, distribute, control, and monetize your APIs on an infrastructure platform built for performance, customer control, and future growth.
Browse the latest documentation
Release Notes for Red Hat 3scale API Management 2.16 On-premisesRelease information
Installing Red Hat 3scale API ManagementFirst Steps with 3scale API Management
Admin Portal GuideAdmin Portal
Creating the Developer PortalDeveloper Portal
Administering the API GatewayAPI Gateway
Liquid ReferenceReference
Operating Red Hat 3scale API ManagementOperational Management of 3scale API Management
Latest security advisories
| Severity | Advisory/CVE | Synopsis | Date |
|---|---|---|---|
| Severity Important | Advisory/CVECVE-2026-67214 | Synopsis A flaw was found in nanoid (Nano ID), a JavaScript library used for generating unique identifiers. This vulnerability allows an attacker to cause a Denial of Service (DoS) by providing a negative size input to the customAlphabet or nanoid functions within the library's non-secure module. When a negative size is provided, these functions enter an infinite loop, causing the application to hang indefinitely and disrupting service availability. | Date |
| Severity Moderate | Advisory/CVECVE-2026-65902 | Synopsis A flaw was found in DOMPurify. An attacker can exploit a vulnerability in how DOMPurify handles its sanitization hooks when default configurations are used. By manipulating the uponSanitizeElement or uponSanitizeAttribute hooks, an attacker can permanently alter the allowed HTML tags and attributes. This allows malicious content to bypass sanitization, potentially leading to cross-site scripting (XSS) attacks and compromising the integrity of web applications. | Date |
| Severity Moderate | Advisory/CVECVE-2026-65901 | Synopsis A flaw was found in DOMPurify. This cross-site scripting (XSS) vulnerability exists in IN_PLACE mode, where the software trusts attacker-controlled nodeName on live non-form nodes. A remote attacker can supply hostile live Document Object Model (DOM) objects with script children. These scripts can execute when the sanitized tree is inserted into a live document, potentially leading to information disclosure or arbitrary code execution. | Date |
| Severity Moderate | Advisory/CVECVE-2026-65899 | Synopsis A flaw was found in DOMPurify where the clearConfig() function does not properly reset the retained Trusted Types policy. This can lead to a DOMPurify instance, when reused across different security contexts, remaining bound to a previously supplied and potentially unsafe policy. An attacker could leverage this to execute malicious scripts, resulting in client-side arbitrary code execution. | Date |
| Severity Moderate | Advisory/CVECVE-2026-54464 | Synopsis A flaw was found in the `websocket-driver` library. When used with the `permessage-deflate` extension, a remote attacker can send compressed WebSocket messages that, upon decompression, exceed the configured maximum message size. This occurs because the size limit is checked against the compressed data rather than the decompressed data. This can lead to a denial of service (DoS) due to excessive resource consumption in applications accepting these larger-than-expected messages. | Date |
Top resources
Get support
Support cases
Get answers quickly by opening a support case with us.
Live chat
Directly access our support engineers during weekday business hours.
Call or email
Speak directly with a Red Hat Support expert by phone or through email.