Threats Tagged 'cve-2026-69152'
View all threats tagged with 'cve-2026-69152'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-69152'
Click on any threat for detailed analysis and mitigation recommendations
Collector with the supported components for a Red Hat build of OpenTelemetry Security Fix(es): * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820) * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/17/2026, 07:06:12 UTC Added: 08/17/2026, 00:57:04 UTC |
Collector with the supported components for a Red Hat build of OpenTelemetry Security Fix(es): * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820) * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * github.com/open-telemetry/opentelemetry-go: go.opentelemetry.io/otel/baggage: go.opentelemetry.io/otel/propagation: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/17/2026, 07:06:12 UTC Added: 08/17/2026, 00:57:04 UTC |
An update is now available for the Red Hat build of Cryostat 4 on RHEL 9. Security Fix(es): * Apache HttpComponents Core: Denial of Service via excessive HTTP headers (CVE-2026-54399) * Apache HttpComponents Core: Denial of Service via oversized HTTP/2 HPACK header blocks (CVE-2026-54428) * Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects (CVE-2026-15075) * Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation (CVE-2026-15076) * SeaweedFS: Information disclosure via S3 API gateway path traversal (CVE-2026-55874) * SeaweedFS: Unauthorized data deletion via path traversal in S3 gateway (CVE-2026-58372) * protobufjs: Denial of Service via crafted .proto schema (CVE-2026-59877) * Quarkus REST: Unbounded multipart MIME part-header accumulation allows remote OOM denial of service (CVE-2026-16308) * Netty: Denial of Service via SPDY header decompression amplification (CVE-2026-55833) * Netty: Denial of Service via SPDY SETTINGS frame processing (CVE-2026-55831) * Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message (CVE-2026-55851) * Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec (CVE-2026-56745) * Netty: Security control bypass allows unauthorized requests via null origin header (CVE-2026-56746) * Netty: Denial of Service via HTTP/2 DATA frame memory leak (CVE-2026-56819) * Netty: Memory exhaustion in netty-codec-http (decompression bomb) (CVE-2026-59899) * Apache Thrift: Denial of Service via integer overflow or wraparound (CVE-2026-55969) * Apache Thrift: Denial of Service via improper handling of highly compressed data (CVE-2026-48586) * Apache Thrift: Denial of Service due to uncontrolled resource allocation (CVE-2026-45112) * brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152) * ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192) * jackson-core: Denial of Service via incomplete fix in async JSON parser (CVE-2026-68494) * DOMPurify: Cross-site scripting vulnerability allows code execution (CVE-2026-49978) * OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178) * Go net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * Go encoding/xml: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) * Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * Go crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * js-yaml: Denial of Service via crafted YAML documents (CVE-2026-59869) * golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions (CVE-2026-56854) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/16/2026, 17:16:26 UTC Added: 07/30/2026, 05:46:42 UTC |
Red Hat OpenShift Logging 6.6.1 is a cluster-wide logging solution for OpenShift that collects and manages applications, infrastructure, and audit logs. Join the discussion | GCVE Database | 09/10/2026, 16:42:04 UTC Added: 09/09/2026, 13:28:58 UTC |
0 Red Hat Ansible Automation Platform 2.1 delivers an Ansible-first Red Hat Developer Hub user experience that simplifies the automation experience for Ansible users of all skill levels. The Ansible plug-ins provide curated content and features to accelerate Ansible learner onboarding and streamline Ansible use case adoption across your organization. Join the discussion | GCVE Database | 09/08/2026, 07:34:17 UTC Added: 09/09/2026, 13:30:16 UTC |
0 Red Hat Quay 3.15.8 contains a Server-Side Request Forgery (SSRF) vulnerability in its repository-level mirror configuration feature. An authenticated repository administrator can exploit this flaw by providing a crafted hostname, causing the Quay mirror worker to make unauthorized requests to internal network services or cloud metadata endpoints. This could expose sensitive internal resources. The vulnerability requires administrator privileges and network egress restrictions or disabling the feature can mitigate the risk. Join the discussion | GCVE Database | 09/03/2026, 18:45:09 UTC Added: 08/06/2026, 18:17:21 UTC |
GCVE Database | 08/31/2026, 15:37:13 UTC Added: 08/05/2026, 15:30:56 UTC | |
This release of the Red Hat build of OpenTelemetry provides new features, security improvements, and bug fixes. Breaking changes: * None Deprecations: * None Technology Preview features: * None Enhancements: * None Bug fixes: * None Known issues: * None Join the discussion | GCVE Database | 08/13/2026, 20:33:45 UTC Added: 07/16/2026, 10:39:02 UTC |
This release of the Red Hat build of OpenTelemetry provides new features, security improvements, and bug fixes. Breaking changes: * None Deprecations: * None Technology Preview features: * None Enhancements: * None Bug fixes: * None Known issues: * None Join the discussion | GCVE Database | 08/13/2026, 20:33:45 UTC Added: 07/13/2026, 09:20:42 UTC |
0 Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network. Join the discussion | GCVE Database | 08/13/2026, 19:46:27 UTC Added: 07/11/2026, 09:36:49 UTC |
Showing 1 to 10 of 18 results