live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
newsINTEGRATION

Apicurio Registry 3.3.1 closes XSS, SSRF and XML parsing flaws

Red Hat’s new Service Registry container images address six vulnerabilities, including an Important DOMPurify issue described as allowing code execution.

Six vulnerabilities fixed in Apicurio Registry 3.3.1.
AI-generated illustration
By The News Desk· Aug 25, 2026

Red Hat has released Apicurio Registry 3.3.1 GA container images with fixes for six security vulnerabilities affecting Red Hat Integration Service Registry. The August 25 advisory rates the update Important and tells administrators to apply it after any earlier errata relevant to their systems.

What changed

The update addresses two DOMPurify cross-site scripting issues. Red Hat describes CVE-2026-49978 as a cross-site scripting vulnerability that allows code execution and CVE-2026-41240 as an inconsistent tag-sanitization flaw.

Three of the fixes are specific to Apicurio Registry’s handling of XML-related inputs. CVE-2026-12975 concerns an unhardened SAX parser used during content-type detection; the advisory says it can lead to blind XML external entity processing, server-side request forgery or a “billion laughs” denial of service. CVE-2026-12992 covers SSRF through import dereferencing during full WSDL validation. CVE-2026-12993 addresses denial of service through XML entity expansion in an internal DTD subset.

The sixth issue, CVE-2026-44496, is an Axios client-side denial-of-service flaw involving unescaped regular-expression metacharacters in an XSRF cookie name.

Who is affected

Red Hat lists Red Hat Integration — Service Registry 1 on x86_64 as the affected product and says the update is delivered through new Red Hat build of Apicurio Registry container images in the Red Hat Container Catalog.

The most relevant exposure depends on how a registry deployment accepts and validates content. Environments that process untrusted schemas, WSDL documents or XML-derived formats should pay particular attention to the parser, import-dereferencing and entity-expansion fixes. The two DOMPurify items affect the client-side sanitization boundary, while the Axios issue is a denial-of-service condition.

The advisory does not collapse all six issues into one exploit path. Operators should treat the release as a bundle of fixes across the registry’s server-side validation and browser-facing dependency surface rather than assume that every deployment has the same exposure.

What operators should do

Red Hat’s prescribed action is to apply Apicurio Registry 3.3.1 GA after ensuring that previously released errata relevant to the system are installed. Teams running Service Registry should identify the deployed container image, plan a controlled image update and verify registry functions that parse or validate XML and WSDL content after rollout.

Because the advisory names both code-execution and server-side request-forgery consequences, delaying the update leaves more than a routine availability risk. Platform teams should also review whether registry endpoints accept content from less-trusted tenants or automated pipelines, since those input paths determine where the XML and WSDL validation flaws are reachable.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.