Red Hat Developer Hub
Red Hat Developer Hub is Red Hat's enterprise-grade, self-managed, customizable developer portal based on Backstage.io. It's supported on Red Hat OpenShift and other major Kubernetes clusters (AKS, EKS, GKE). Its core features include a single, centralized software catalog, self-service via gold path templates, technical documentation, and is extensible by plugins.
Browse the latest documentation
Latest security advisories
| Severity | Advisory/CVE | Synopsis | Date |
|---|---|---|---|
| Severity Low | Advisory/CVECVE-2026-63074 | Synopsis A flaw was found in OpenSSL. The CMP (Certificate Management Protocol) implementation does not clear cached additional certificates when an invalid message is received, leading to excessive memory consumption. This allows a malicious client to repeatedly send requests containing unique extra certificates to cause memory exhaustion, eventually resulting in a denial of service. | Date |
| Severity Low | Advisory/CVECVE-2026-63073 | Synopsis A flaw was found in OpenSSL. A malicious CMP (Certificate Management Protocol) endpoint can send an unexpected distinguished name (DN) directly as the format string argument to ERR_raise_data(), causing the application to dereference and write to unrelated stack contents. This can lead to a crash in the CMP client, resulting in a denial of service. | Date |
| Severity Low | Advisory/CVECVE-2026-54874 | Synopsis A flaw was found in OpenSSL. Receiving a DTLS (Datagram Transport Layer Security) record for a future epoch while a handshake is in progress causes OpenSSL to buffer an excessive amount of memory. This allows a peer to cause memory exhaustion, eventually resulting in a denial of service, using a small amount of network traffic. | Date |
| Severity Moderate | Advisory/CVECVE-2026-63076 | Synopsis A flaw was found in OpenSSL. A crafted CMP (Certificate Management Protocol) message can cause an invalid pointer dereference due to a missing type check in the password-based protection verification. A remote, unauthenticated attacker can crash applications acting as a CMP server or client, resulting in a denial of service. | Date |
| Severity Low | Advisory/CVECVE-2026-14457 | Synopsis A flaw was found in OpenSSL. In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, where only the private key (with no certificate) is configured, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted "signature_algorithms_cert" TLS extension. This issue results in a denial of service. | Date |
Top resources
Knowledgebase
Access articles and solutions to find answers to your questions.
Red Hat Developer Hub Support Policy
Red Hat offers services for each major release of Red Hat Developer Hub with designated support policies.
Troubleshooting
Connect to the right information to self-solve issues quickly and efficiently.
Lifecycle
View the various levels of maintenance for each release of a product over a period from initial release to the end of maintenance.
Get support
Support cases
Get answers quickly by opening a support case with us.
Live chat
Directly access our support engineers during weekday business hours.
Call or email
Speak directly with a Red Hat Support expert by phone or through email.