Threats Tagged 'cve-2026-49844'
View all threats tagged with 'cve-2026-49844'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-49844'
Click on any threat for detailed analysis and mitigation recommendations
0 Multiple security vulnerabilities affecting the flink software have been addressed in version 2.1.3-r1. This update fixes six distinct vulnerabilities including CVE-2026-49844. The affected versions include various specific releases prior to 2.1.3-r1 and some other versions explicitly listed. The severity of these vulnerabilities is assessed as medium. A patch is available to remediate these issues. Join the discussion | GCVE Database | 09/01/2026, 11:17:16 UTC Added: 07/16/2026, 10:38:09 UTC |
0 Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing. Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values. Join the discussion | CVE Database V5 | 07/10/2026, 21:14:59 UTC Added: 07/10/2026, 21:33:03 UTC |
Showing 1 to 2 of 2 results