Threats Tagged 'cve-2026-59296'
View all threats tagged with 'cve-2026-59296'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-59296'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat build of Apache Camel 4.18.4 for Spring Boot patch release and security update is now available. The purpose of this text-only errata is to inform you about the security issues fixed. Security Fix(es): * vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects (CVE-2026-15075) * jetty-security: Eclipse Jetty: Authentication bypass via Digest authentication encoding collision (CVE-2026-10050) * rhaf-camel-spring-boot-maven-repository.zip: Apache Qpid Proton-J: Denial of Service via unbounded type nesting (CVE-2026-66274) * jetty-server: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections (CVE-2026-10051) * sshd-core: Apache MINA SSHD: Unauthorized command execution due to improper certificate validation (CVE-2026-56624) * cxf-rt-transports-jms: Apache CXF: Remote Code Execution via unsafe deserialization of JMS ObjectMessage (CVE-2026-66909) * cxf-rt-rs-security-oauth2: Apache CXF: Authorization code replay due to flaw in DefaultEncryptingCodeDataProvider (CVE-2026-68079) * cxf-rt-rs-security-oauth2: Apache CXF: Authorization Code Replay via Race Condition (CVE-2026-57818) * cxf: Apache CXF: Authorization Code Substitution via missing c_hash validation (CVE-2026-57817) * camel: Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers (CVE-2026-46457) * camel: Apache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers (CVE-2026-46456) * camel: Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields (CVE-2026-48203) * camel-amqp: Apache Camel: Information disclosure via deserialization of untrusted data (CVE-2026-42527) * proton-j: Apache Qpid Proton-J: Denial of Service due to excessive allocation (CVE-2026-66273) * proton-j: Apache Qpid Proton-J: Denial of Service via unbounded symbol value caching (CVE-2026-66257) * netty-codec-xml: Netty: Denial of Service via CPU Exhaustion in XmlFrameDecoder (CVE-2026-73507) * micrometer-core: Micrometer: Line-protocol and log injection via unsanitized input allows metric and log spoofing (CVE-2026-59296) * cxf-rt-rs-security-oauth2: Apache CXF: Security bypass due to improper handling of authorization parameters (CVE-2026-63687) * camel-knative: Apache Camel Knative: Header injection vulnerability allows server-side request forgery (CVE-2026-63621) * camel-main: Apache Camel: Improper authentication allows JWT bypass in Platform HTTP Main component (CVE-2026-66908) * netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration (CVE-2026-62243) * httpclient5-cache: Apache HttpComponents Client: Denial of Service due to connection leak (CVE-2026-64607) * jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser (CVE-2026-68494) * zstd-jni: zstd-jni: Data corruption or denial of service via use-after-free vulnerability (CVE-2026-87825) * zstd-jni: zstd-jni: Use-After-Free vulnerability allows memory corruption and denial of service (CVE-2026-87877) * zstd-jni: zstd-jni: Denial of Service (DoS) via out-of-bounds read in Zstd.trainFromBufferDirect (CVE-2026-87824) * zstd-jni: zstd-jni: Out-of-bounds read in ZstdDictCompress constructor leads to denial of service (CVE-2026-87795) * zstd-jni: zstd-jni: Information disclosure or denial of service via out-of-bounds read (CVE-2026-89046) * jackson-databind: jackson-databind: CPU Denial of Service via unbounded numeric parsing (CVE-2026-68497) * zstd-jni: zstd-jni: Denial of Service via out-of-bounds read in ZstdDictDecompress (CVE-2026-90560) * bcprov-jdk18on: Bouncy Castle for Java: Denial of Service via quadratic-time escaping of X.500 distinguished names (CVE-2026-58059) * bcprov-jdk18on: Bouncy Castle for Java: Cryptographic signature bypass in RSA PKCS#1 verification (CVE-2026-12860) * zstd-jni: luben zstd-jni: Remote use-after-free vulnerability in dictionary sharing (CVE-2026-90852) * netty-transport-sctp: Netty: Denial of Service via SCTP memory exhaustion (CVE-2026-59902) * camel-mail: Apache Camel: Injected MIME headers can manipulate route behavior (CVE-2026-59230) * netty-handler: Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext (CVE-2026-75595) Join the discussion | GCVE Database | 09/24/2026, 19:56:44 UTC Added: 07/23/2026, 01:18:08 UTC |
Red Hat Data Grid is an in-memory, distributed, NoSQL datastore solution. It increases application response times and allows for dramatically improving performance while providing availability, reliability, and elastic scale. Data Grid 8.6.3 replaces Data Grid 8.6.2 and includes bug fixes and enhancements. Find out more about Data Grid 8.6.3 in the Release Notes[3]. Security Fix(es): * CVE-2026-68494 jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser [jdg-8.6] (CVE-2026-68494) * CVE-2026-56745 datagrid-8/datagrid-8: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec [jdg-8.6] (CVE-2026-56745) * CVE-2026-62243 netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration [jdg-8.6] (CVE-2026-62243) * CVE-2026-73508 netty-codec-dns: Netty: Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names [jdg-8.6] (CVE-2026-73508) * CVE-2026-49978 dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution [jdg-8.6] (CVE-2026-49978) * CVE-2026-76844 redhat-datagrid-maven-repository.zip: webpack-dev-middleware: Information Disclosure via Path Traversal [jdg-8.6] (CVE-2026-76844) * CVE-2026-59901 netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) [jdg-8.6] (CVE-2026-59901) * CVE-2026-59899 netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) [jdg-8.6] (CVE-2026-59899) * CVE-2026-56820 netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack [jdg-8.6] (CVE-2026-56820) * CVE-2026-56819 netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak [jdg-8.6] (CVE-2026-56819) * CVE-2026-56817 netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability [jdg-8.6] (CVE-2026-56817) * CVE-2026-56746 netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header [jdg-8.6] (CVE-2026-56746) * CVE-2026-55851 netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message [jdg-8.6] (CVE-2026-55851) * CVE-2026-55831 netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing [jdg-8.6] (CVE-2026-55831) * CVE-2026-55833 netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification [jdg-8.6] (CVE-2026-55833) * CVE-2026-44891 netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder [jdg-8.6] (CVE-2026-44891) * CVE-2026-59296 micrometer-core: Micrometer: Line-protocol and log injection via unsanitized input allows metric and log spoofing [jdg-8.6] (CVE-2026-59296) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/21/2026, 12:19:52 UTC Added: 08/14/2026, 16:36:47 UTC |
Red Hat Data Grid is an in-memory, distributed, NoSQL datastore solution. It increases application response times and allows for dramatically improving performance while providing availability, reliability, and elastic scale. Data Grid 8.6.3 replaces Data Grid 8.6.2 and includes bug fixes and enhancements. Find out more about Data Grid 8.6.3 in the Release Notes[3]. Security Fix(es): * CVE-2026-68494 jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser [jdg-8.6] (CVE-2026-68494) * CVE-2026-56745 datagrid-8/datagrid-8: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec [jdg-8.6] (CVE-2026-56745) * CVE-2026-62243 netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration [jdg-8.6] (CVE-2026-62243) * CVE-2026-73508 netty-codec-dns: Netty: Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names [jdg-8.6] (CVE-2026-73508) * CVE-2026-49978 dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution [jdg-8.6] (CVE-2026-49978) * CVE-2026-76844 redhat-datagrid-maven-repository.zip: webpack-dev-middleware: Information Disclosure via Path Traversal [jdg-8.6] (CVE-2026-76844) * CVE-2026-59901 netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) [jdg-8.6] (CVE-2026-59901) * CVE-2026-59899 netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) [jdg-8.6] (CVE-2026-59899) * CVE-2026-56820 netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack [jdg-8.6] (CVE-2026-56820) * CVE-2026-56819 netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak [jdg-8.6] (CVE-2026-56819) * CVE-2026-56817 netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability [jdg-8.6] (CVE-2026-56817) * CVE-2026-56746 netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header [jdg-8.6] (CVE-2026-56746) * CVE-2026-55851 netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message [jdg-8.6] (CVE-2026-55851) * CVE-2026-55831 netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing [jdg-8.6] (CVE-2026-55831) * CVE-2026-55833 netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification [jdg-8.6] (CVE-2026-55833) * CVE-2026-44891 netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder [jdg-8.6] (CVE-2026-44891) * CVE-2026-59296 micrometer-core: Micrometer: Line-protocol and log injection via unsanitized input allows metric and log spoofing [jdg-8.6] (CVE-2026-59296) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/21/2026, 12:19:52 UTC Added: 08/14/2026, 16:36:44 UTC |
CVE-2026-59296 is a medium severity vulnerability in Spring Micrometer involving improper output neutralization for logs (CWE-117). It arises from using untrusted, non-normalized input directly in metrics data such as metric names, tag keys, or tag values. This can lead to injection issues affecting the integrity of logs or monitoring data. The affected versions include Micrometer 1.17.0, 1.16.0 through 1.16.6, 1.15.0 through 1.15.12, 1.14.0 through 1.14.16, and 1.9.18 and earlier. No known exploits are reported in the wild, and no official patch or remediation details are provided in the input data. Join the discussion | CVE Database V5 | 08/21/2026, 10:47:25 UTC Added: 08/21/2026, 10:52:58 UTC |
Showing 1 to 4 of 4 results