Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. From 4.3.0 to before 4.10.22, 3.10.6, and 3.8.14, TimeConverterRegistrar caches DateTimeFormatter instances in an unbounded ConcurrentHashMap<String, DateTimeFormatter> whose key is derived from the @Format annotation pattern concatenated with the locale from the HTTP Accept-Language header. Because Locale.forLanguageTag() accepts arbitrary BCP 47 private-use extensions (en-x-a001, en-x-a002, …), an unauthenticated attacker can generate an unlimited number of unique cache keys by sending requests with novel locale tags, growing the cache until heap memory is exhausted and the JVM crashes. This vulnerability is fixed in 4.10.22, 3.10.6, and 3.8.14. Join the discussion | CVE Database V5 | 05/12/2026, 21:20:45 UTC Added: 05/12/2026, 21:51:26 UTC |
0 CVE-2026-44242 is a low severity vulnerability in the Micronaut Framework's micronaut-core component prior to version 4.10.22. It involves uncontrolled resource consumption where an unauthenticated attacker can exhaust heap memory by sending many unique HTTP Accept-Language headers. This triggers unbounded growth of the bundleCache, which is keyed by locale and baseName. The issue affects applications that register a ResourceBundleMessageSource bean and serve HTML error responses. The vulnerability is fixed in version 4.10.22. Join the discussion | CVE Database V5 | 05/12/2026, 21:17:52 UTC Added: 05/12/2026, 21:51:26 UTC |
0 Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both 4.10.16 and 3.10.5 do not correctly handle descending array index order during form-urlencoded body binding in theJsonBeanPropertyBinder::expandArrayToThreshold, which allows remote attackers to cause a DoS (non-terminating loop, CPU exhaustion, and OutOfMemoryError) via crafted indexed form parameters (e.g., authors[1].name followed by authors[0].name). This issue has been fixed in versions 4.10.16 and 3.10.5. Join the discussion | CVE Database V5 | 03/20/2026, 04:47:42 UTC Added: 03/20/2026, 05:24:20 UTC |
0 Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions 4.7.0 through 4.10.16 used an unbounded ConcurrentHashMap cache with no eviction policy in its DefaultHtmlErrorResponseBodyProvider. If the application throws an exception whose message may be influenced by an attacker, (for example, including request query value parameters) it could be used by remote attackers to cause an unbounded heap growth and OutOfMemoryError, leading to DoS. This issue has been fixed in version 4.10.7. Join the discussion | CVE Database V5 | 03/20/2026, 04:43:07 UTC Added: 03/20/2026, 05:24:20 UTC |
Showing 1 to 4 of 4 results