Threats Tagged 'cve-2026-40984'
View all threats tagged with 'cve-2026-40984'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-40984'
Click on any threat for detailed analysis and mitigation recommendations
Red Hat OpenShift Dev Spaces provides a cloud developer workspace server and a browser-based IDE built for teams and organizations. Dev Spaces runs in OpenShift and is well-suited for container-based development. The 3.30 release is based on Eclipse Che 7.121 and uses the DevWorkspace engine to provide support for workspaces based on devfile v2.1 and v2.2. Users still using the v1 standard should migrate as soon as possible. https://devfile.io/docs/2.2.0/migrating-to-devfile-v2 Dev Spaces supports OpenShift EUS releases v4.16 and higher. Users are expected to update to supported OpenShift releases in order to continue to get Dev Spaces updates. https://access.redhat.com/support/policy/updates/openshift#crw Join the discussion | GCVE Database | 09/01/2026, 18:22:22 UTC Added: 06/10/2026, 11:41:49 UTC |
0 Red Hat build of Apache Camel 4.18.3 for Spring Boot patch release and security update is now available. The purpose of this text-only errata is to inform you about the security issues fixed. Security Fix(es): * vertx-core: eclipse-vertx/vert.x: Denial of Service via TLS handshake with wildcard server name (CVE-2026-6860) * jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) * jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing (CVE-2026-50193) * c3p0: c3p0: Remote code execution via deserialization vulnerability (CVE-2026-55223) * mchange-commons-java: mchange-commons-java: Remote code execution via JNDI injection (CVE-2026-55153) * jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513) * httpcore: Apache HttpComponents Core: Denial of Service via excessive HTTP headers (CVE-2026-54399) * camel-jms: Apache Camel JMS components: Arbitrary Exchange state injection (CVE-2026-43866) * camel-vertx-websocket: Apache Camel Vertx Websocket: Server-Side Request Forgery and sensitive data exposure (CVE-2026-46726) * camel-cxf-common: Apache Camel CXF SOAP: Remote attacker can execute unintended operations via header manipulation (CVE-2026-46592) * camel-mail: Apache Camel Mail Component: Credential exposure and information disclosure via improper input validation of mail headers (CVE-2026-46584) * camel-vertx-http: Apache Camel (camel-vertx-http): Remote Code Execution via Deserialization of Untrusted Data (CVE-2026-40859) * httpcore5-h2: Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks (CVE-2026-54428) * httpcore5: Apache HttpComponents Core: Denial of Service via excessive HTTP headers (CVE-2026-54399) * commons-configuration2: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input (CVE-2026-45205) * netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder (CVE-2026-44891) * vertx-web-client: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation (CVE-2026-15076) * netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification (CVE-2026-55833) * netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing (CVE-2026-55831) * netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message (CVE-2026-55851) * netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec (CVE-2026-56745) * netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header (CVE-2026-56746) * netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability (CVE-2026-56817) * netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak (CVE-2026-56819) * netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack (CVE-2026-56820) * netty-codec-http: Netty: Memory exhaustion in netty-codec-http (CVE-2026-59899) Join the discussion | GCVE Database | 08/13/2026, 14:50:50 UTC Added: 06/18/2026, 18:45:00 UTC |
Red Hat build of Keycloak is an integrated sign-on solution, available as a Red Hat JBoss Middleware for OpenShift containerized image. The Red Hat build of Keycloak for OpenShift image provides an authentication server that you can use to log in centrally, log out, and register. You can also manage user accounts for web applications, mobile applications, and RESTful web services. Red Hat build of Keycloak Operator for OpenShift simplifies deployment and management of Keycloak 26.6.5 clusters. This erratum releases new images for Red Hat build of Keycloak 26.6.5 for use within the OpenShift Container Platform cloud computing Platform-as-a-Service (PaaS) for on-premise or private cloud deployments, aligning with the standalone product release. Security fixes: * Authorization Bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of Keycloak (CVE-2026-11986) * Admin UI extension brute-force-user endpoint bypasses FGAPv2 user view restrictions (CVE-2026-14209) * FGAP v2 client scope assignment bypass via ClientResource (CVE-2026-14614) * FGAP v2 parent group children endpoint bypasses per-child view permission filter (CVE-2026-14615) * DCR protocol mapper type-swap policy bypass allows privilege escalation (CVE-2026-15572) * Authorization bypass via unnormalized URI matching in PathMatcher (CVE-2026-15573) * LDAP entry-DN user search bypasses configured users DN boundary (CVE-2026-16071) * Unbounded metric cardinality in user event metrics via request-controlled error text (CVE-2026-16100) * Default DCR policy allows role forgery via User Property mappers (CVE-2026-16102) * Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service (CVE-2026-16308) * SAML IdP-initiated broker login bypasses link-only restriction (CVE-2026-16442) * SAML broker metadata import disables response signature validation (CVE-2026-16443) * Denial of Service via specially crafted gRPC requests (CVE-2026-40983) * Denial of Service via specially crafted HTTP requests (CVE-2026-40984) * Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) * Security bypass allows arbitrary code execution (CVE-2026-54513) * HTTP Parameter Pollution in OIDC redirect URI allows response parameter duplication - #GHI-604 (CVE-2026-9689) * Security policy bypass in JWE-encrypted request object processing (CVE-2026-9793) * Brute-force protection bypass in CIBA flow (CVE-2026-9798) Join the discussion | GCVE Database | 08/05/2026, 16:20:31 UTC Added: 08/05/2026, 18:46:50 UTC |
0 Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot patch release and security update is now available. The purpose of this text-only errata is to inform you about the security issues fixed. Security Fix(es): * cxf-services-xkms-x509-repo-ldap: Apache CXF: Information Disclosure via LDAP Injection (CVE-2026-44930) * cxf-rt-transports-jms: Apache CXF: Arbitrary code execution via untrusted JMS configuration (CVE-2026-50632) * cxf-rt-rs-security-oauth2-saml: Apache CXF: Token Confusion/Routing attacks due to improper validation of JWT audience claims (CVE-2026-50627) * cxf-rt-rs-security-oauth2: Apache CXF: Token Confusion/Routing attacks due to improper validation of JWT audience claims (CVE-2026-50627) * cxf-rt-rs-security-oauth2-saml: cxf: Unauthorized access due to logic error in OAuthRequestFilter (CVE-2026-50628) * cxf-rt-rs-security-oauth2: cxf: Unauthorized access due to logic error in OAuthRequestFilter (CVE-2026-50628) * cxf-integration-jca: Apache CXF: Arbitrary code execution via JNDI Injection (CVE-2026-50633) * cxf-core: Apache CXF: Information disclosure via out-of-band external entity resolution due to missing JAXP hardening (CVE-2026-49875) * netty-codec-redis: Netty: Denial of Service via malicious Redis array header (CVE-2026-50011) * netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays (CVE-2026-44250) * netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads (CVE-2026-44890) * netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments (CVE-2026-46340) * netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass (CVE-2026-50010) * netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator (CVE-2026-48006) * netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records (CVE-2026-47691) * netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers (CVE-2026-48059) * netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak (CVE-2026-48043) * netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message (CVE-2026-44893) * netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation (CVE-2026-44249) * assertj-core: AssertJ: Information disclosure and denial of service via XML External Entity (XXE) (CVE-2026-24400) * cxf-rt-transports-jms: Apache CXF: Remote Code Execution via untrusted JMS configuration (CVE-2026-44417) * netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header (CVE-2026-44248) * netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression (CVE-2026-42587) * netty-codec-http: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression (CVE-2026-42587) * netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation (CVE-2026-42578) * netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder (CVE-2026-42586) * netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers (CVE-2026-42581) * netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion (CVE-2026-42584) * netty-codec-dns: Netty: High integrity impact due to improper DNS domain name constraint enforcement (CVE-2026-42579) * log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames (CVE-2026-34478) * log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging (CVE-2026-34480) * log4j-layout-template-json: Apache Log4j JsonTemplateLayout: Denial of Service via invalid JSON output (CVE-2026-34481) * micrometer-core: Micrometer: Denial of Service via specially crafted HTTP requests (CVE-2026-40984) * netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake (CVE-2026-45416) * netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation (CVE-2026-45674) Join the discussion | GCVE Database | 07/09/2026, 15:29:15 UTC Added: 07/10/2026, 09:25:27 UTC |
0 An update for Red Hat Build of Apache Camel 4.18 for Quarkus 3.33 update is now available (RHBQ 3.33.2.SP2). The purpose of this text-only errata is to inform you about the enhancements that improve your developer experience and ensure the security and stability of your products: * jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution [rhboac-camel-quarkus-3] (CVE-2026-54513) * jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass [rhboac-camel-quarkus-3] (CVE-2026-54512) * micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests [rhboac-camel-quarkus-3] (CVE-2026-40983) * micrometer-core: Micrometer: Denial of Service via specially crafted HTTP requests [rhboac-camel-quarkus-3] (CVE-2026-40984) * cxf-core: Apache CXF: Information disclosure via out-of-band external entity resolution due to missing JAXP hardening [rhboac-camel-quarkus-3] (CVE-2026-49875) Join the discussion | GCVE Database | 07/08/2026, 18:28:22 UTC Added: 07/09/2026, 09:39:02 UTC |
In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Affected versions: micrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18; 1.9.0 through 1.9.17. micrometer-jetty11 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18. micrometer-jetty12 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18. Join the discussion | CVE Database V5 | 06/09/2026, 03:47:46 UTC Added: 06/09/2026, 04:48:41 UTC |
Showing 1 to 6 of 6 results