Skip to main content

Threats Tagged 'cve-2026-45409'

View all threats tagged with 'cve-2026-45409'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-45409

Threats Tagged 'cve-2026-45409'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network.

Join the discussion

Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network.

Join the discussion
0

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python-idna: idna: Denial of Service via specially crafted long inputs (CVE-2026-45409) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Apache Superset versions prior to 6.0.0-r5 contain multiple security vulnerabilities that have been addressed in the 6.0.0-r5 release. These vulnerabilities include an issue in the idna Python package that could cause denial of service by consuming excessive resources when processing specially crafted inputs. The vulnerabilities have a medium severity rating. A patch is available in version 6.0.0-r5 to fix these issues.

Join the discussion

This update includes the following RPMs: mariadb11.8: * mariadb-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-backup-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-client-utils-11.8.8-3.hum1 (noarch) * mariadb-common-11.8.8-3.hum1 (noarch) * mariadb-connect-engine-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-cracklib-password-check-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-devel-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-embedded-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-embedded-devel-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-errmsg-11.8.8-3.hum1 (noarch) * mariadb-gssapi-server-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-oqgraph-engine-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-pam-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-rocksdb-engine-11.8.8-3.hum1 (x86_64) * mariadb-s3-engine-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-server-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-server-galera-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-server-utils-11.8.8-3.hum1 (noarch) * mariadb-sphinx-engine-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-test-11.8.8-3.hum1 (aarch64, x86_64) * mariadb11.8-11.8.8-3.hum1.src (src)

Join the discussion

This update includes the following RPMs: opentelemetry-collector-contrib: * opentelemetry-collector-contrib-0.155.0-0.1.hum1 (aarch64, x86_64) * opentelemetry-collector-contrib-0.155.0-0.1.hum1.src (src)

Join the discussion

Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `"\u0660" * N` or `"\u30fb" * N + "\u6f22"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. A specially crafted argument to the `idna.encode()` function could consume significant resources. This may lead to a denial-of-service. Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support). A workaround is available. Domain names cannot exceed 253 characters in length. If this length limit is enforced prior to passing the domain to the `idna.encode()` function, it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Tag: cve-2026-45409
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses