Threats Tagged 'cve-2026-64607'
View all threats tagged with 'cve-2026-64607'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-64607'
Click on any threat for detailed analysis and mitigation recommendations
0 Elasticsearch versions prior to 9.5.2-r1 contain multiple vulnerabilities, including CVE-2026-64607. The package version 9.5.2-r1 includes security fixes addressing these issues. No CVSS score is provided for CVE-2026-64607, and no known exploits are reported in the wild. Join the discussion | GCVE Database | 09/01/2026, 11:17:16 UTC Added: 09/02/2026, 15:48:37 UTC |
0 Elasticsearch version 9.5.2-r2 addresses three security vulnerabilities including CVE-2026-64607. The package update fixes these issues to improve security. No CVSS score is available for CVE-2026-64607, and there are no known exploits in the wild. The vulnerability affects versions prior to 9.5.2-r2. Join the discussion | GCVE Database | 09/01/2026, 11:17:16 UTC Added: 09/02/2026, 15:48:37 UTC |
A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue exists in the component responsible for looking up data values (ReflectionValueResolver), which fails to properly block access to sensitive Java internal functions when processing certain data types like Enums. An attacker who can provide or influence the template text can exploit this bypass to take control of the server by executing unauthorized commands. Join the discussion | GCVE Database | 08/31/2026, 15:34:43 UTC Added: 08/31/2026, 17:51:01 UTC |
0 HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue affects Apache HttpComponents Client: from 5.0-alpha1 through 5.6.2. Join the discussion | CVE Database V5 | 07/31/2026, 10:12:18 UTC Added: 07/31/2026, 10:22:52 UTC |
Showing 1 to 4 of 4 results