Threats Tagged 'cve-2026-39373'
View all threats tagged with 'cve-2026-39373'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-39373'
Click on any threat for detailed analysis and mitigation recommendations
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix UpdateCVE-2025-14550 0 Red Hat Ansible Automation Platform 2. 6 has multiple security vulnerabilities affecting components such as automation-controller, automation-gateway, automation-platform-ui, and various Python libraries. These issues include account hijacking via unverified email linking, denial of service through malformed inputs, buffer overflows, remote code execution via path traversal, and incorrect parsing of IPv6 literals. The vulnerabilities collectively pose risks of unauthorized access, denial of service, and remote code execution. Red Hat has issued an important security advisory with patches addressing these issues for supported versions of the platform. Join the discussion | GCVE Database | 05/04/2026, 14:10:09 UTC Added: 05/26/2026, 20:58:34 UTC |
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix UpdateCVE-2025-69534 0 Red Hat Ansible Automation Platform 2. 5 for RHEL 8 and 9 contains multiple security vulnerabilities including account hijacking via unverified email linking, denial of service through malformed HTML-like sequences and XML entity expansion, remote code execution via path traversal, memory exhaustion, and parsing errors. These issues affect various components such as automation-controller, automation-gateway, python libraries, and receptor. Red Hat has released an important security advisory (RHSA-2026:13512) addressing these vulnerabilities with updated packages. Users of affected versions should apply the provided updates to remediate these issues. Join the discussion | GCVE Database | 05/04/2026, 14:31:09 UTC Added: 05/26/2026, 20:58:34 UTC |
CVE-2026-39373: CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) in latchset jwcryptoCVE-2026-39373 0 JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the decompressed output size. An unauthenticated attacker can cause memory exhaustion on memory-constrained systems. A token under the 250KB input limit can decompress to approximately 100MB. This vulnerability is fixed in 1.5.7. Join the discussion | CVE Database V5 | 04/07/2026, 19:35:36 UTC Added: 04/07/2026, 20:01:11 UTC |
Showing 1 to 3 of 3 results