RHSA-2026:59360: Important: Apicurio Registry (container images) release and security update [ 3.3.1 GA ]
Important: Apicurio Registry (container images) release and security update [ 3.3.1 GA ]
Other sources
This release of Red Hat build of Apicurio Registry 3.3.1 GA includes the following security fixes.Security Fix(es): DOMPurify: Cross-site scripting vulnerability allows code execution [rhint-serv-3] (CVE-2026-49978) apicurio-registry: Unhardened SAXParser in content-type detection leads to blind XXE / SSRF / billion-laughs DoS [rhint-serv-3] (CVE-2026-12975) apicurio-registry: SSRF via wsdl4j import dereference in WSDL FULL validation [rhint-serv-3] (CVE-2026-12992) apicurio-registry: XML entity-expansion denial of service via internal DTD subset [rhint-serv-3] (CVE-2026-12993) Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name [rhint-serv-3] (CVE-2026-44496) DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization [rhint-serv-3] (CVE-2026-41240) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apicurio Registry (container images)to a version that resolves this vulnerability.Fixed in 3.3.1 GA - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch rhint-serv-3
Event History
Frequently Asked Questions
Which deployment artifact is covered by this update?
The update covers Apicurio Registry container images for Red Hat Integration - Service Registry.
What release is identified in the advisory?
The advisory identifies the 3.3.1 GA release.
How urgent is this advisory according to the provided rating?
It is rated high severity, with a risk value of 33.