live wire
AI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLMAI · Red Hat documents usage-based admission fair sharing for Kueue 1.4 on OpenShiftRed Hat DeveloperAI: Red Hat maps governed firewall changes from ServiceNow through Ansible and two human approval gatesRed Hat DeveloperCLUSTER MGMT · ACM 2.17 makes Submariner 0.24 GA with Important-rated fixesRed Hat ErrataPLATFORM · Red Hat makes on-premises Lightspeed recommendations GA for Satellite 6.18Red Hat ErrataSECURITY · Red Hat Hardened Images updates Tomcat 10 for nine authentication, access-control and DoS flawsRed Hat ErrataAI · Open Data Hub 3.6.0 EA1 bundles Trainer, MLflow and llm-d componentsOpen Data HubAI · Speculators 0.6.0 adds P-EAGLE parallel drafting for vLLM speculative decodingRed Hat DeveloperSECURITY · OpenShift 4.17.57 fixes seven Go and TLS CVEs in an Important-rated updateRed Hat ErrataAI · Red Hat benchmarks local LLM guardrails with EvalHub, exposing regex accuracy and latency trade-offsRed Hat DeveloperAI · Red Hat maps silent tool-call failures across agentic pipelinesRed HatAPI · Kuadrant 1.5.3 adds GRPCRoute policies and developer-portal API-key workflowsKuadrantAI · (Aug 25) IBM releases Apache-2.0 Granite 4.2 reasoning models in 3B, 8B and 30B sizesIBM ResearchJAVA · Red Hat build of Quarkus 3.33.3.SP1 fixes 13 CVEs in an Important-rated updateRed Hat errataAI · vLLM moves Kimi K2 RL weight sync across 384 H100s in 7.53 seconds (Aug 22)vLLM
upstreambeat.ai
newsSECURITY

Developer Hub 1.10.3 updates the portal, operator and AI content images

The Important security release spans 14 CVEs and also corrects catalog image and dynamic-plugin resolution problems from 1.10.2.

By The News Desk· Aug 21, 2026

Red Hat Developer Hub 1.10.3 is an Important security update covering 14 CVEs. Operators should treat it as a portal-stack update rather than a single application patch: Red Hat publishes replacement images for the Developer Hub application, operator, operator bundle, must-gather utility and RAG content service.

What is affected

The primary runtime image is rhdh-hub-rhel9, which carries the Backstage-based portal used for the software catalog, templates, TechDocs and installed dynamic plugins. The rhdh-rhel9-operator and rhdh-operator-bundle control deployment and upgrades. The advisory also replaces rhdh-rag-content-rhel9, used by Developer Hub’s AI-oriented content path, and rhdh-must-gather-rhel9, the support-data collector.

Red Hat lists 14 CVEs but does not reduce the advisory to one exploit path. Exposure triage should start with what is actually enabled and reachable: portal routes and authentication, catalog ingestion, software templates, TechDocs, dynamic plugins, and any Lightspeed or RAG integration. Clusters that retained 1.10.2 catalog metadata deserve extra attention because the same release fixes two non-CVE packaging defects.

One fix corrects outdated catalog digests and references that pointed Lightspeed at ghcr.io images and supplied invalid Orchestrator digests. A second corrects {{inherit}} resolution that could select older Orchestrator frontend, backend and form-widget plugin versions than the preceding 1.10.1 operator. Those defects make image provenance and plugin inventory part of the post-update check, not an optional cleanup.

Operator checklist

  1. Inventory the current Developer Hub CSV, application image digest and enabled dynamic plugins. Record whether Lightspeed, Orchestrator or RAG content is deployed.
  2. Update through the supported operator channel to 1.10.3 and wait for the operator and Developer Hub custom resource to settle without reconciliation errors.
  3. Compare running image IDs with the amd64 digests in RHSA-2026:49642 for the hub, operator, bundle, must-gather and RAG content images.
  4. Inspect catalog-source and subscription status. Confirm the deployment no longer resolves Lightspeed to unexpected ghcr.io content or Orchestrator plugins to stale versions.
  5. Exercise the exposed paths: sign in, read the catalog, render TechDocs, create a test component from an approved template and load each business-critical dynamic plugin.
  6. If AI features are enabled, test Lightspeed or RAG retrieval separately and verify the rhdh-rag-content-rhel9 image was replaced.
  7. Review network and identity logs for unusual portal access during the pre-update window; prioritize public routes and highly privileged template actions.

A successful upgrade is the combination of corrected digests, expected plugin versions and working portal flows. The version label alone cannot prove that the old application or plugin artifacts have left the cluster.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.