Threats Tagged 'cve-2026-34481'
View all threats tagged with 'cve-2026-34481'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-34481'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.17.57. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:60018 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.17/html/release_notes/ Join the discussion | GCVE Database | 09/03/2026, 07:53:39 UTC Added: 05/26/2026, 20:58:28 UTC |
0 Oracle released a Critical Security Patch Update (CSPU) in August 2026 that addresses multiple vulnerabilities in various Oracle Financial Services Enterprise modules and other Oracle products. The update includes 943 security patches targeting Oracle code and third-party components. Oracle strongly recommends applying these patches promptly to mitigate risks, as some vulnerabilities have been subject to attempted exploitation. The advisory covers a wide range of Oracle products and versions, including financial services, databases, middleware, and more. No CVSS score is provided for these vulnerabilities. Join the discussion | GCVE Database | 08/19/2026, 09:55:40 UTC Added: 08/19/2026, 13:50:27 UTC |
0 Red Hat build of Apache Camel 4.18.3 for Spring Boot patch release and security update is now available. The purpose of this text-only errata is to inform you about the security issues fixed. Security Fix(es): * vertx-core: eclipse-vertx/vert.x: Denial of Service via TLS handshake with wildcard server name (CVE-2026-6860) * jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) * jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing (CVE-2026-50193) * c3p0: c3p0: Remote code execution via deserialization vulnerability (CVE-2026-55223) * mchange-commons-java: mchange-commons-java: Remote code execution via JNDI injection (CVE-2026-55153) * jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513) * httpcore: Apache HttpComponents Core: Denial of Service via excessive HTTP headers (CVE-2026-54399) * camel-jms: Apache Camel JMS components: Arbitrary Exchange state injection (CVE-2026-43866) * camel-vertx-websocket: Apache Camel Vertx Websocket: Server-Side Request Forgery and sensitive data exposure (CVE-2026-46726) * camel-cxf-common: Apache Camel CXF SOAP: Remote attacker can execute unintended operations via header manipulation (CVE-2026-46592) * camel-mail: Apache Camel Mail Component: Credential exposure and information disclosure via improper input validation of mail headers (CVE-2026-46584) * camel-vertx-http: Apache Camel (camel-vertx-http): Remote Code Execution via Deserialization of Untrusted Data (CVE-2026-40859) * httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks (CVE-2026-54428) * httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers (CVE-2026-54399) * commons-configuration2: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input (CVE-2026-45205) * netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder (CVE-2026-44891) * vertx-web-client: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation (CVE-2026-15076) * netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification (CVE-2026-55833) * netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing (CVE-2026-55831) * netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message (CVE-2026-55851) * netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec (CVE-2026-56745) * netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header (CVE-2026-56746) * netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability (CVE-2026-56817) * netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak (CVE-2026-56819) * netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack (CVE-2026-56820) * netty-codec-http: Netty: Memory exhaustion in netty-codec-http (CVE-2026-59899) Join the discussion | GCVE Database | 08/13/2026, 14:50:50 UTC Added: 06/18/2026, 18:45:00 UTC |
0 Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot patch release and security update is now available. The purpose of this text-only errata is to inform you about the security issues fixed. Security Fix(es): * cxf-services-xkms-x509-repo-ldap: Apache CXF: Information Disclosure via LDAP Injection (CVE-2026-44930) * cxf-rt-transports-jms: Apache CXF: Arbitrary code execution via untrusted JMS configuration (CVE-2026-50632) * cxf-rt-rs-security-oauth2-saml: Apache CXF: Token Confusion/Routing attacks due to improper validation of JWT audience claims (CVE-2026-50627) * cxf-rt-rs-security-oauth2: Apache CXF: Token Confusion/Routing attacks due to improper validation of JWT audience claims (CVE-2026-50627) * cxf-rt-rs-security-oauth2-saml: cxf: Unauthorized access due to logic error in OAuthRequestFilter (CVE-2026-50628) * cxf-rt-rs-security-oauth2: cxf: Unauthorized access due to logic error in OAuthRequestFilter (CVE-2026-50628) * cxf-integration-jca: Apache CXF: Arbitrary code execution via JNDI Injection (CVE-2026-50633) * cxf-core: Apache CXF: Information disclosure via out-of-band external entity resolution due to missing JAXP hardening (CVE-2026-49875) * netty-codec-redis: Netty: Denial of Service via malicious Redis array header (CVE-2026-50011) * netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays (CVE-2026-44250) * netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads (CVE-2026-44890) * netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments (CVE-2026-46340) * netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass (CVE-2026-50010) * netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator (CVE-2026-48006) * netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records (CVE-2026-47691) * netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers (CVE-2026-48059) * netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak (CVE-2026-48043) * netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message (CVE-2026-44893) * netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation (CVE-2026-44249) * assertj-core: AssertJ: Information disclosure and denial of service via XML External Entity (XXE) (CVE-2026-24400) * cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration (CVE-2026-44417) * netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header (CVE-2026-44248) * netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression (CVE-2026-42587) * netty-codec-http: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression (CVE-2026-42587) * netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation (CVE-2026-42578) * netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder (CVE-2026-42586) * netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers (CVE-2026-42581) * netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion (CVE-2026-42584) * netty-codec-dns: Netty: High integrity impact due to improper DNS domain name constraint enforcement (CVE-2026-42579) * log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames (CVE-2026-34478) * log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging (CVE-2026-34480) * log4j-layout-template-json: Apache Log4j JsonTemplateLayout: Denial of Service via invalid JSON output (CVE-2026-34481) * micrometer-core: Micrometer: Denial of Service via specially crafted HTTP requests (CVE-2026-40984) * netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake (CVE-2026-45416) * netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation (CVE-2026-45674) Join the discussion | GCVE Database | 07/09/2026, 15:29:15 UTC Added: 07/10/2026, 09:25:27 UTC |
0 This Red Hat Offline Knowledge Portal release upgrades from Solr 9.8.1 to Solr 10.0.0, and fixes several CVEs. It also includes content updates as of May 26 2026. Join the discussion | GCVE Database | 05/28/2026, 22:46:23 UTC Added: 05/29/2026, 21:01:50 UTC |
An update is now available for Red Hat OpenShift GitOps. Bug Fix(es) and Enhancement(s): * GITOPS-8784 (Service-CA annotation removed from argocd-server Service during v1.12.3 -> v1.12.4 upgrade path, persists in later versions) Join the discussion | GCVE Database | 05/26/2026, 14:49:30 UTC Added: 05/26/2026, 20:57:56 UTC |
0 Red Hat OpenShift Data Foundation 4.16.26 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-6193: Backport to odf-4.16.26 ocs-operator should not use image gcr.io/kubebuilder/kube-rbac-proxy DFBUGS-5940: Backport to odf-4.16.z [External Mode]: noobaa-default-backing-store is in creating state due to "CheckExternalConnection Status=UNKNOWN_FAILURE Error=SELF_SIGNED_CERT_IN_CHAIN" Join the discussion | GCVE Database | 05/14/2026, 11:50:27 UTC Added: 05/26/2026, 20:58:28 UTC |
0 Red Hat OpenShift Data Foundation 4.20.10 security, enhancement & bug fix update FIXED BUGS: ========== DFBUGS-6171: RHODF 4.20.10 release DFBUGS-6016: Backport to odf-4.20.z [GSS] No public access to buckets after ODF upgrade to 4.20 DFBUGS-5941: Backport to odf-4.20.z [External Mode]: noobaa-default-backing-store is in creating state due to "CheckExternalConnection Status=UNKNOWN_FAILURE Error=SELF_SIGNED_CERT_IN_CHAIN" DFBUGS-5818: [Backport to odf-4.20.z] [IBM_Support][Fusion HCI]"storageclient-xxxxx-status-reporter job" doesn't inherits the tolerations defined in "ocs-client-operator-controller-manager" deployment DFBUGS-5801: [Backport to odf-4.20.z] must-gather causes default RGW pools to be created and PGs to be stuck at 1 DFBUGS-5115: [csi] Handle race conditions during relocate/failover of RBD based workloads DFBUGS-4747: Unable to select NAD from dropdown list when creating storage cluster when using Multus CVEs: ========== CVE-2026-4800 CVE-2026-34986 CVE-2026-33186 CVE-2026-33036 CVE-2026-27942 Join the discussion | GCVE Database | 04/30/2026, 11:25:14 UTC Added: 05/26/2026, 20:58:27 UTC |
0 The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities. Security Fix(es): * tornado-python: Tornado: Denial of Service via large multipart bodies (CVE-2026-31958) * lodash: lodash: Arbitrary code execution via untrusted input in template imports (CVE-2026-4800) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 04/29/2026, 05:59:14 UTC Added: 05/26/2026, 20:58:28 UTC |
In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request. Join the discussion | GCVE Database | 04/14/2026, 10:59:10 UTC Added: 06/02/2026, 21:43:30 UTC |
Showing 1 to 10 of 11 results