Threats Tagged 'cve-2026-68494'
View all threats tagged with 'cve-2026-68494'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-68494'
Click on any threat for detailed analysis and mitigation recommendations
An update is now available for the Red Hat build of Cryostat 4 on RHEL 9. Security Fix(es): * Apache HttpComponents Core: Denial of Service via excessive HTTP headers (CVE-2026-54399) * Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks (CVE-2026-54428) * Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects (CVE-2026-15075) * Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation (CVE-2026-15076) * SeaweedFS: Information disclosure via S3 API gateway path traversal (CVE-2026-55874) * SeaweedFS: Unauthorized data deletion via path traversal in S3 gateway (CVE-2026-58372) * protobufjs: Denial of Service via crafted .proto schema (CVE-2026-59877) * Quarkus REST: Unbounded multipart MIME part-header accumulation allows remote OOM denial of service (CVE-2026-16308) * Netty: Denial of Service via SPDY header decompression amplification (CVE-2026-55833) * Netty: Denial of Service via SPDY SETTINGS frame processing (CVE-2026-55831) * Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message (CVE-2026-55851) * Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec (CVE-2026-56745) * Netty: Security control bypass allows unauthorized requests via null origin header (CVE-2026-56746) * Netty: Denial of Service via HTTP/2 DATA frame memory leak (CVE-2026-56819) * Netty: Memory exhaustion in netty-codec-http (decompression bomb) (CVE-2026-59899) * Apache Thrift: Denial of Service via integer overflow or wraparound (CVE-2026-55969) * Apache Thrift: Denial of Service via improper handling of highly compressed data (CVE-2026-48586) * Apache Thrift: Denial of Service due to uncontrolled resource allocation (CVE-2026-45112) * brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152) * ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192) * jackson-core: Denial of Service via incomplete fix in async JSON parser (CVE-2026-68494) * DOMPurify: Cross-site scripting vulnerability allows code execution (CVE-2026-49978) * OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178) * Go net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * Go encoding/xml: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) * Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * Go crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * js-yaml: Denial of Service via crafted YAML documents (CVE-2026-59869) * golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions (CVE-2026-56854) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/16/2026, 17:16:26 UTC Added: 07/30/2026, 05:46:42 UTC |
0 Red Hat Satellite 6.16 prior to 6.16.13 contains multiple security vulnerabilities including arbitrary code execution, authentication bypass, denial of service, HTTP request smuggling, and information disclosure. These issues affect components such as jackson-databind, ruby-jwt, python-aiohttp, Eclipse Jetty, and jackson-core. The vulnerabilities are addressed in the Red Hat Satellite 6.16.13 update. Join the discussion | GCVE Database | 09/03/2026, 23:02:57 UTC Added: 09/04/2026, 14:25:19 UTC |
0 Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security Fix(es): * ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution (CVE-2026-11332) * ansible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for CVE-2026-11332) (CVE-2026-16493) * openvox-server: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) * puppetserver: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) * rubygem-jwt: ruby-jwt: Authentication bypass due to empty key in HMAC verification (CVE-2026-45363) * python-aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses (CVE-2026-69244) * python-aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade (CVE-2026-69243) * python-aiohttp: AIOHTTP: Arbitrary code execution via untrusted input to CookieJar.load() (CVE-2026-34993) * openvox-server: jackson-core: Denial of Service via incomplete fix in async JSON parser (CVE-2026-68494) * openvox-server: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections (CVE-2026-10051) * python-gitpython: GitPython: Arbitrary File Overwrite via improper git option validation (CVE-2026-73624) * python-gitpython: GitPython: Remote Code Execution via kwarg value smuggling (CVE-2026-73625) * python-gitpython: GitPython: Information disclosure via environment variable expansion in URL handling (CVE-2026-73622) * python-gitpython: GitPython: Remote Code Execution via malicious Git template (CVE-2026-73623) * python-gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding (CVE-2026-73620) * python-gitpython: GitPython: Arbitrary code execution via improper validation of clone options (CVE-2026-42284) * python3.12-gitpython: GitPython: Arbitrary code execution via improper validation of clone options (CVE-2026-42284) * python-gitpython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks (CVE-2026-42215) * python3.12-gitpython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks (CVE-2026-42215) * python-gitpython: GitPython: Arbitrary code execution via injected newlines in Git configuration (CVE-2026-44244) * python3.12-gitpython: GitPython: Arbitrary code execution via injected newlines in Git configuration (CVE-2026-44244) * python-gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names (CVE-2026-76222) * python3.12-gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names (CVE-2026-76222) * python-gitpython: GitPython: Remote Code Execution via malicious Git hooks (CVE-2026-76218) * python3.12-gitpython: GitPython: Remote Code Execution via malicious Git hooks (CVE-2026-76218) * python-gitpython: GitPython: Arbitrary command execution via crafted kwargs (CVE-2026-76220) * python3.12-gitpython: GitPython: Arbitrary command execution via crafted kwargs (CVE-2026-76220) * python-gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection (CVE-2026-76219) * python3.12-gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection (CVE-2026-76219) * python-gitpython: GitPython: Arbitrary code execution via config-name injection (CVE-2026-76221) * python3.12-gitpython: GitPython: Arbitrary code execution via config-name injection (CVE-2026-76221) Join the discussion | GCVE Database | 09/03/2026, 23:00:57 UTC Added: 09/04/2026, 14:25:19 UTC |
0 Red Hat Satellite 6.17.11 update addresses multiple security vulnerabilities including arbitrary code execution, denial of service, authentication bypass, HTTP request smuggling, and information disclosure. These issues affect components such as jackson-databind, jackson-core, AIOHTTP, ruby-jwt, Eclipse Jetty, and ansible-core. The update fixes argument injection flaws leading to code execution and other critical security issues. The advisory rates the update as important and recommends applying it after ensuring all previous errata are applied. Join the discussion | GCVE Database | 09/03/2026, 23:00:42 UTC Added: 09/04/2026, 14:25:19 UTC |
0 Red Hat Satellite 6.18 prior to 6.18.9 contains multiple security vulnerabilities affecting components such as aiohttp, Eclipse Jetty, jackson-core, ansible-core, puppetserver, and ruby-jwt. These include HTTP request smuggling, denial of service, information disclosure, arbitrary code execution, and authentication bypass issues. The update to version 6.18.9 addresses these vulnerabilities along with several bug fixes. Users are advised to apply this update after ensuring all previous errata are installed. Join the discussion | GCVE Database | 09/03/2026, 22:05:12 UTC Added: 09/04/2026, 14:25:19 UTC |
0 CVE-2026-18401 is a medium severity vulnerability in FasterXML jackson-core affecting the asynchronous JSON parser. The async parser does not enforce the maxNumberLength constraint, allowing an attacker to submit JSON with arbitrarily long number tokens. This leads to excessive memory allocation and potential CPU exhaustion, causing denial of service. The synchronous parser is not affected as it enforces this limit correctly. No privileges or user interaction beyond submitting JSON data are required. The issue affects jackson-core versions 2.15.0 through 2.18.5, 2.19.0 through 2.21.0, and 3.0.0 through 3.0.x. Patch status is not confirmed; no official fix or remediation level is stated in the vendor advisory. Join the discussion | CVE Database V5 | 08/29/2026, 00:00:00 UTC Added: 08/04/2026, 14:56:53 UTC |
0 Red Hat has released security updates for its build of Quarkus, addressing multiple vulnerabilities including authentication downgrades, a heap buffer overflow causing denial of service, man-in-the-middle protection bypass, and unauthorized command execution due to improper certificate validation. These issues affect versions prior to 3.27.5. The update is rated as having an important security impact and includes fixes for CVE-2026-8484 among others. Users are advised to apply the 3.27.5 update to mitigate these vulnerabilities. Join the discussion | GCVE Database | 08/13/2026, 14:51:19 UTC Added: 08/13/2026, 17:48:30 UTC |
0 An update is now available for Red Hat Lightspeed (formerly Insights) for Runtimes on RHEL 9. Security fix(es): * jackson-core: Denial of Service via incomplete fix in async JSON parser (CVE-2026-68494) * jackson-databind: @JsonIgnore bypass in Java Records (CVE-2026-59888) * jackson-databind: Denial of Service via deeply nested JSON processing (CVE-2026-50193) * jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/12/2026, 22:01:08 UTC Added: 08/13/2026, 17:47:48 UTC |
0 CVE-2026-68494 is a high-severity vulnerability in FasterXML jackson-core affecting versions from 2.15.0 through 2.18.7, 2.19.0 through 2.21.3, and 3.0.0 through 3.1.3. It involves improper resource allocation without limits in the non-blocking JSON parser, allowing an attacker to cause excessive memory consumption by streaming JSON numbers in many small chunks without terminators. This can lead to JVM heap exhaustion in reactive frameworks using the async parser. The issue does not affect synchronous parsers or async parsers operating on complete input. Exploitation requires only the ability to stream data to a parsing endpoint and no privileges. Join the discussion | CVE Database V5 | 08/04/2026, 14:39:14 UTC Added: 08/04/2026, 14:56:55 UTC |
Showing 1 to 9 of 9 results