Red Hat 3scale API Management
Red Hat 3scale API Management makes it easy to manage your APIs. Share, secure, distribute, control, and monetize your APIs on an infrastructure platform built for performance, customer control, and future growth.
Browse the latest documentation
Release Notes for Red Hat 3scale API Management 2.16 On-premisesRelease information
Installing Red Hat 3scale API ManagementFirst Steps with 3scale API Management
Admin Portal GuideAdmin Portal
Creating the Developer PortalDeveloper Portal
Administering the API GatewayAPI Gateway
Liquid ReferenceReference
Operating Red Hat 3scale API ManagementOperational Management of 3scale API Management
Latest security advisories
| Severity | Advisory/CVE | Synopsis | Date |
|---|---|---|---|
| Severity Moderate | Advisory/CVECVE-2026-65902 | Synopsis A flaw was found in DOMPurify. An attacker can exploit a vulnerability in how DOMPurify handles its sanitization hooks when default configurations are used. By manipulating the uponSanitizeElement or uponSanitizeAttribute hooks, an attacker can permanently alter the allowed HTML tags and attributes. This allows malicious content to bypass sanitization, potentially leading to cross-site scripting (XSS) attacks and compromising the integrity of web applications. | Date |
| Severity Moderate | Advisory/CVECVE-2026-65901 | Synopsis A flaw was found in DOMPurify. This cross-site scripting (XSS) vulnerability exists in IN_PLACE mode, where the software trusts attacker-controlled nodeName on live non-form nodes. A remote attacker can supply hostile live Document Object Model (DOM) objects with script children. These scripts can execute when the sanitized tree is inserted into a live document, potentially leading to information disclosure or arbitrary code execution. | Date |
| Severity Moderate | Advisory/CVECVE-2026-65899 | Synopsis A flaw was found in DOMPurify where the clearConfig() function does not properly reset the retained Trusted Types policy. This can lead to a DOMPurify instance, when reused across different security contexts, remaining bound to a previously supplied and potentially unsafe policy. An attacker could leverage this to execute malicious scripts, resulting in client-side arbitrary code execution. | Date |
| Severity Moderate | Advisory/CVECVE-2026-65898 | Synopsis A flaw was found in DOMPurify. When the `setConfig()` function is used with an `uponSanitizeAttribute` hook, the `ALLOWED_ATTR` allowlist is not properly cloned. This allows an attacker to register a hook that can permanently modify the shared allowlist, enabling the conditional allowance of dangerous attributes. Consequently, an attacker can submit untrusted content that inherits the polluted allowlist, leading to stored Cross-site Scripting (XSS) and the execution of event handlers. | Date |
| Severity Moderate | Advisory/CVECVE-2025-61780 | Synopsis A potential information disclosure vulnerability has been identified in the RubyGem Rack affecting Rack::Sendfile when used behind a proxy that supports x-sendfile headers (e.g., Nginx). When processing untrusted x-sendfile-type or x-accel-mapping headers, the middleware could misinterpret them as proxy directives, causing the proxy to make unintended internal requests. An attacker could exploit this by sending crafted headers and requesting paths that trigger proxy-based acceleration, potentially accessing internal application endpoints that are normally protected. The issue does not allow arbitrary file reads, code execution, or denial of service. | Date |
Top resources
Get support
Support cases
Get answers quickly by opening a support case with us.
Live chat
Directly access our support engineers during weekday business hours.
Call or email
Speak directly with a Red Hat Support expert by phone or through email.