Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 A memory leak vulnerability exists in aiohttp when middleware is enabled and a request triggers a MatchInfoError due to a non-allowed HTTP method. This occurs because each MatchInfoError creates a unique cache entry, causing unbounded memory growth. An attacker could exploit this by sending large volumes of such requests, potentially exhausting server memory. A patch is available to address this issue. Join the discussion | GCVE Database | 08/13/2026, 16:38:28 UTC Added: 10/10/2026, 21:26:52 UTC |
The llhttp library version 8.1.1 contains two request smuggling vulnerabilities. These vulnerabilities affect the aiohttp library versions from 1.16.2 up to but not including 1.16.27, as aiohttp includes llhttp as a dependency. The vulnerabilities are resolved by upgrading to llhttp version 9 or later, which is included in aiohttp version 3.8.6 and above. No detailed technical information or exploitation details have been disclosed yet. Join the discussion | GCVE Database | 08/13/2026, 16:38:28 UTC Added: 10/10/2026, 21:26:46 UTC |
CVE-2026-69243 is a high-severity vulnerability in the bzt product involving HTTP request smuggling via WebSocket upgrade. It affects versions from 1.16.2 up to but not including 1.16.51_2. Red Hat has issued an important security advisory and provides a patched container image to mitigate this issue. The vulnerability relates to Red Hat Lightspeed in Satellite, which analyzes system health locally without sending data externally. No known exploits are reported in the wild. Join the discussion | GCVE Database | 08/13/2026, 16:38:28 UTC Added: 09/29/2026, 21:03:45 UTC |
0 The bzt tool has a vulnerability (CVE-2026-22815) related to aiohttp's handling of trailer headers, allowing unlimited trailer headers which can lead to uncapped memory usage. This can cause memory exhaustion when processing attacker-controlled requests or responses. Typical reverse proxy configurations can mitigate this risk. A patch is available to address this issue. Join the discussion | GCVE Database | 08/13/2026, 16:38:28 UTC Added: 09/17/2026, 01:59:20 UTC |
CVE-2026-50269 is a CRLF injection vulnerability in the aiohttp library's multipart headers handling. It occurs when attacker-controlled input is included in multipart/payload headers, allowing modification of requests to inject additional headers or alter request contents. This vulnerability affects specific versions of the bzt product that use aiohttp. The issue arises if user-controlled strings are passed into MultipartWriter.append(headers=...) or Payload.headers. A patch is available to address this vulnerability. Join the discussion | GCVE Database | 08/13/2026, 16:38:28 UTC Added: 09/17/2026, 01:59:06 UTC |
0 This security update for python-aiohttp addresses three vulnerabilities affecting versions >=0.19.0 <0.20.0_8 and >=1.16.2 <1.16.51_2. CVE-2026-59881 involves excessive resource consumption due to a WebSocket client accepting compressed frames without negotiated permessage-deflate. CVE-2026-69243 is an HTTP request smuggling vulnerability via the WebSocket upgrade procedure. CVE-2026-69244 is an out-of-bounds heap read in the C response parser triggered by malformed responses. A patch is available to remediate these issues. Join the discussion | GCVE Database | 08/13/2026, 16:38:28 UTC Added: 09/17/2026, 01:58:54 UTC |
Red Hat Enterprise Linux AI 3.3.6 update addresses multiple security vulnerabilities affecting the AI Inference Server Model Optimization Tools. The update provides enhanced container images to mitigate these issues. The vulnerabilities include a range of weaknesses such as improper input validation and memory handling errors. The update is classified as important and addresses several CVEs. No active exploits are known in the wild at this time. Join the discussion | GCVE Database | 08/13/2026, 16:38:28 UTC Added: 08/31/2026, 15:42:17 UTC |
0 An out-of-bounds heap read vulnerability exists in the C HTTP response parser used by bzt when processing malformed chunked HTTP responses. This vulnerability can lead to a denial of service (DoS) if triggered by an attacker-controlled server or an accidental malformed response. A patch is available to fix the issue. As a workaround, users can disable the vulnerable C parser by setting the environment variable AIOHTTP_NO_EXTENSIONS=1 to force usage of the unaffected Python parser. Join the discussion | GCVE Database | 08/13/2026, 16:38:28 UTC Added: 08/14/2026, 16:37:04 UTC |
0 CVE-2024-52304 is a vulnerability in aiohttp's Python parser that incorrectly handles newlines in chunk extensions, enabling HTTP request smuggling attacks under specific conditions. This affects aiohttp when used in pure Python mode without C extensions or when the AIOHTTP_NO_EXTENSIONS environment variable is enabled. Red Hat has released patches for affected products, including Ansible Automation Platform 2.5. Exploitation could allow attackers to bypass firewall or proxy protections. The vulnerability has a medium severity rating and a patch is available. Join the discussion | GCVE Database | 08/13/2026, 16:38:28 UTC Added: 06/02/2026, 21:43:51 UTC |
Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. For details about this release, refer to the release notes listed in the References section. Join the discussion | GCVE Database | 08/13/2026, 16:38:28 UTC Added: 05/26/2026, 20:58:21 UTC |
Showing 1 to 10 of 12 results