Threats Tagged 'cve-2026-45409'
View all threats tagged with 'cve-2026-45409'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-45409'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network. Join the discussion | GCVE Database | 08/31/2026, 21:39:55 UTC Added: 06/02/2026, 21:44:02 UTC |
0 Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network. Join the discussion | GCVE Database | 08/31/2026, 21:39:55 UTC Added: 06/02/2026, 21:44:02 UTC |
0 Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python-idna: idna: Denial of Service via specially crafted long inputs (CVE-2026-45409) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/13/2026, 08:40:09 UTC Added: 07/10/2026, 09:24:10 UTC |
0 Apache Superset versions prior to 6.0.0-r5 contain multiple security vulnerabilities that have been addressed in the 6.0.0-r5 release. These vulnerabilities include an issue in the idna Python package that could cause denial of service by consuming excessive resources when processing specially crafted inputs. The vulnerabilities have a medium severity rating. A patch is available in version 6.0.0-r5 to fix these issues. Join the discussion | GCVE Database | 07/30/2026, 07:10:53 UTC Added: 07/16/2026, 10:38:36 UTC |
0 This update includes the following RPMs: mariadb11.8: * mariadb-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-backup-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-client-utils-11.8.8-3.hum1 (noarch) * mariadb-common-11.8.8-3.hum1 (noarch) * mariadb-connect-engine-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-cracklib-password-check-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-devel-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-embedded-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-embedded-devel-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-errmsg-11.8.8-3.hum1 (noarch) * mariadb-gssapi-server-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-oqgraph-engine-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-pam-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-rocksdb-engine-11.8.8-3.hum1 (x86_64) * mariadb-s3-engine-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-server-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-server-galera-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-server-utils-11.8.8-3.hum1 (noarch) * mariadb-sphinx-engine-11.8.8-3.hum1 (aarch64, x86_64) * mariadb-test-11.8.8-3.hum1 (aarch64, x86_64) * mariadb11.8-11.8.8-3.hum1.src (src) Join the discussion | GCVE Database | 07/09/2026, 04:49:53 UTC Added: 05/31/2026, 21:00:25 UTC |
0 This update includes the following RPMs: opentelemetry-collector-contrib: * opentelemetry-collector-contrib-0.155.0-0.1.hum1 (aarch64, x86_64) * opentelemetry-collector-contrib-0.155.0-0.1.hum1.src (src) Join the discussion | GCVE Database | 06/25/2026, 05:48:38 UTC Added: 06/27/2026, 22:08:20 UTC |
Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior to 3.15, payloads such as `"\u0660" * N` or `"\u30fb" * N + "\u6f22"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process. This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. A specially crafted argument to the `idna.encode()` function could consume significant resources. This may lead to a denial-of-service. Starting in version 3.14, the function rejects long inputs as soon as practicable prior to any further processing to minimize resource consumption. In version 3.15, this approach was extended to lesser used alternate functions (i.e. per-label conversions and codec support). A workaround is available. Domain names cannot exceed 253 characters in length. If this length limit is enforced prior to passing the domain to the `idna.encode()` function, it should no longer consume significant resources. This is triggered by arbitrarily large inputs that would not occur in normal usage, but may be passed to the library assuming there is no preliminary input validation by the higher-level application. Join the discussion | CVE Database V5 | 06/05/2026, 22:06:07 UTC Added: 06/05/2026, 22:33:33 UTC |
Showing 1 to 7 of 7 results