Red Hat Connectivity Link
Red Hat Connectivity Link is a cloud-native solution for application connectivity, API management, and policy management in single and multi-cluster Kubernetes environments on hybrid cloud.
Browse the latest documentation
Red Hat Connectivity LinkDiscover
Release notesWhat's New
Install Connectivity LinkInstall
Deploy Red Hat Connectivity LinkConfigure
ObservabilityObserve
TroubleshootTroubleshoot
Get supportSupport
Latest security advisories
| Severity | Advisory/CVE | Synopsis | Date |
|---|---|---|---|
| Severity Important | Advisory/CVECVE-2026-56859 | Synopsis A flaw was found in the `encoding/xml` package of Go. The `DecodeElement` function failed to correctly track recursion depth, which could lead to stack exhaustion. A remote attacker could exploit this vulnerability by providing a specially crafted XML input, resulting in a Denial of Service (DoS) for the affected application. | Date |
| Severity Important | Advisory/CVECVE-2026-71235 | Synopsis A flaw was found in Magistrala's Rules Engine. An authenticated low-privileged user can exploit this vulnerability by creating rules with embedded Go or Lua scripts. These scripts are executed server-side without sufficient validation, allowing for arbitrary file read and write operations, access to internal databases, and Server-Side Request Forgery (SSRF) against internal microservices. This could lead to significant data compromise and unauthorized system access. | Date |
| Severity Important | Advisory/CVECVE-2026-67214 | Synopsis A flaw was found in nanoid (Nano ID), a JavaScript library used for generating unique identifiers. This vulnerability allows an attacker to cause a Denial of Service (DoS) by providing a negative size input to the customAlphabet or nanoid functions within the library's non-secure module. When a negative size is provided, these functions enter an infinite loop, causing the application to hang indefinitely and disrupting service availability. | Date |
| Severity Important | Advisory/CVECVE-2026-67213 | Synopsis A flaw was found in nanoid (Nano ID), a small, secure, and URL-friendly unique string ID generator. An attacker could exploit this vulnerability by providing a zero-size input to the customAlphabet or customRandom functions. This would cause an infinite loop, leading to a denial of service (DoS) condition by hanging the application's calling thread. | Date |
| Severity Important | Advisory/CVECVE-2026-41178 | Synopsis A flaw was found in OpenTelemetry-Go. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by sending oversized or invalid baggage headers. The `Parse` function, in affected versions, failed to reject raw-length inputs, leading to excessive processing and error logging when handling these large inputs. | Date |
Top resources
Lifecycle
View the various levels of maintenance for each release of a product over a period from initial release to the end of maintenance.
Supported configurations
See your Red Hat-provided production or development support for supported configurations.
Go to Developers
Go to Developers
Request early access
Request early access to Red Hat Connectivity Link.
Get support
Support cases
Get answers quickly by opening a support case with us.
Live chat
Directly access our support engineers during weekday business hours.
Call or email
Speak directly with a Red Hat Support expert by phone or through email.