Threats Tagged 'cve-2026-48801'
View all threats tagged with 'cve-2026-48801'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-48801'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat Ansible Automation Platform 2.1 delivers an Ansible-first Red Hat Developer Hub user experience that simplifies the automation experience for Ansible users of all skill levels. The Ansible plug-ins provide curated content and features to accelerate Ansible learner onboarding and streamline Ansible use case adoption across your organization. Join the discussion | GCVE Database | 09/28/2026, 16:29:02 UTC Added: 07/30/2026, 05:46:42 UTC |
0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.16.71. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:67934 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ Join the discussion | GCVE Database | 09/24/2026, 10:04:10 UTC Added: 05/26/2026, 20:58:29 UTC |
0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.16.71. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:67934 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.16/html/release_notes/ Join the discussion | GCVE Database | 09/24/2026, 10:04:10 UTC Added: 05/26/2026, 20:58:23 UTC |
GCVE Database | 09/21/2026, 08:25:12 UTC Added: 07/02/2026, 22:57:35 UTC | |
0 Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.20.38. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:66375 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.20/html/release_notes/ Join the discussion | GCVE Database | 09/15/2026, 08:29:36 UTC Added: 07/30/2026, 05:46:10 UTC |
AMQ Broker is a high-performance messaging implementation based on ActiveMQ Artemis. It uses an asynchronous journal for fast message persistence, and supports multiple languages, protocols, and platforms. This release of Red Hat AMQ Broker 7.13.6 includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section. Security Fix(es): * (CVE-2026-10050) jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision * (CVE-2026-12143) form-data: form-data: Form field override via CRLF injection * (CVE-2026-12151) undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames * (CVE-2026-13149) brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity * (CVE-2026-13676) fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization * (CVE-2026-40984) micrometer-core: Micrometer: Denial of Service via specially crafted HTTP requests * (CVE-2026-42198) postgresql: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication * (CVE-2026-42264) axios: Axios: Prototype pollution allows information disclosure and request manipulation * (CVE-2026-42338) ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input * (CVE-2026-42578) netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation * (CVE-2026-42581) netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers * (CVE-2026-42584) netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion * (CVE-2026-42587) netty-codec-http: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression * (CVE-2026-42588) activemq-broker: Apache ActiveMQ: Arbitrary code execution via improper input validation in Jolokia JMX-HTTP bridge * (CVE-2026-44248) netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header * (CVE-2026-44249) netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation * (CVE-2026-44486) axios: Axios: Information disclosure of proxy credentials via HTTP redirects * (CVE-2026-44487) axios: Axios: Information disclosure of proxy credentials via redirect flows * (CVE-2026-44488) axios: Axios: Denial of Service due to unenforced request and response size limits * (CVE-2026-44492) axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization * (CVE-2026-44494) axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution * (CVE-2026-44495) axios: Axios: Information disclosure due to prototype pollution vulnerability * (CVE-2026-44496) axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name * (CVE-2026-45205) commons-configuration2: Apache Commons Configuration: Denial of Service via uncontrolled recursion with crafted YAML input * (CVE-2026-45416) netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake * (CVE-2026-45736) ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray` * (CVE-2026-48779) ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments * (CVE-2026-49362) artemis-server: artemis core protocol permits unauthed queue creation * (CVE-2026-49364) artemis-server: artemis cluster password leak via jgroups spoof * (CVE-2026-49432) artemis-stomp-protocol: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector * (CVE-2026-49978) dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution * (CVE-2026-50010) netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass * (CVE-2026-50734) activemq-client: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame * (CVE-2026-53916) artemis-stomp-protocol: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec * (CVE-2026-54512) jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass * (CVE-2026-54513) jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution * (CVE-2026-55831) netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing * (CVE-2026-55833) netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification * (CVE-2026-56745) netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec * (CVE-2026-56746) netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header * (CVE-2026-57967) artemis-server: Apache Artemis — session hijack via missing authentication * (CVE-2026-59869) js-yaml: js-yaml: Denial of Service via crafted YAML documents * (CVE-2026-59873) tar: node-tar: Denial of Service via crafted gzip bomb * (CVE-2026-598 Join the discussion | GCVE Database | 09/10/2026, 23:22:22 UTC Added: 07/08/2026, 13:21:09 UTC |
The Node.js package markdown-it, specifically its linkify-it component prior to version 5.0.1, contains an algorithmic complexity vulnerability in the LinkifyIt.prototype.match function. This function exhibits O(N²) complexity when processing inputs with many fuzzy links or emails due to repeated rescanning of progressively shorter input tails. This can lead to denial of service (DoS) conditions if untrusted Markdown with linkify enabled is synchronously rendered on a request hot path. The issue is resolved in version 5.0.1. Join the discussion | GCVE Database | 07/14/2026, 21:17:00 UTC Added: 06/26/2026, 22:04:26 UTC |
0 This update includes the following RPMs: rust: * cargo-1.97.0-1.1.hum1 (aarch64, x86_64) * clippy-1.97.0-1.1.hum1 (aarch64, x86_64) * rust-1.97.0-1.1.hum1 (aarch64, x86_64) * rust-analyzer-1.97.0-1.1.hum1 (aarch64, x86_64) * rust-debugger-common-1.97.0-1.1.hum1 (noarch) * rust-doc-1.97.0-1.1.hum1 (aarch64, x86_64) * rust-gdb-1.97.0-1.1.hum1 (noarch) * rust-lldb-1.97.0-1.1.hum1 (noarch) * rust-src-1.97.0-1.1.hum1 (noarch) * rust-std-static-1.97.0-1.1.hum1 (aarch64, x86_64) * rust-std-static-aarch64-unknown-none-softfloat-1.97.0-1.1.hum1 (noarch) * rust-std-static-aarch64-unknown-uefi-1.97.0-1.1.hum1 (noarch) * rust-std-static-i686-pc-windows-gnu-1.97.0-1.1.hum1 (noarch) * rust-std-static-wasm32-unknown-unknown-1.97.0-1.1.hum1 (noarch) * rust-std-static-wasm32-wasip1-1.97.0-1.1.hum1 (noarch) * rust-std-static-x86_64-pc-windows-gnu-1.97.0-1.1.hum1 (noarch) * rust-std-static-x86_64-unknown-none-1.97.0-1.1.hum1 (noarch) * rust-std-static-x86_64-unknown-uefi-1.97.0-1.1.hum1 (noarch) * rustfmt-1.97.0-1.1.hum1 (aarch64, x86_64) * rust-1.97.0-1.1.hum1.src (src) Join the discussion | GCVE Database | 07/11/2026, 01:14:07 UTC Added: 07/13/2026, 09:21:10 UTC |
Showing 1 to 8 of 8 results