Threats Tagged 'cve-2026-69244'
View all threats tagged with 'cve-2026-69244'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-69244'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat Satellite 6.16 prior to 6.16.13 contains multiple security vulnerabilities including arbitrary code execution, authentication bypass, denial of service, HTTP request smuggling, and information disclosure. These issues affect components such as jackson-databind, ruby-jwt, python-aiohttp, Eclipse Jetty, and jackson-core. The vulnerabilities are addressed in the Red Hat Satellite 6.16.13 update. Join the discussion | GCVE Database | 09/03/2026, 23:02:57 UTC Added: 09/04/2026, 14:25:19 UTC |
0 Red Hat Satellite 6.19.0 through 6.19.4 for RHEL 9 contains multiple security vulnerabilities affecting components such as ansible-core, openvox-server, puppetserver, rubygem-jwt, python-aiohttp, and python-gitpython. These vulnerabilities include arbitrary code execution, authentication bypass, denial of service, HTTP request smuggling, information disclosure, and arbitrary file overwrite. Red Hat has released an update (6.19.4 Async Update) addressing these issues. Join the discussion | GCVE Database | 09/03/2026, 23:00:57 UTC Added: 09/04/2026, 14:25:19 UTC |
0 Red Hat Satellite 6.17.11 update addresses multiple security vulnerabilities including arbitrary code execution, denial of service, authentication bypass, HTTP request smuggling, and information disclosure. These issues affect components such as jackson-databind, jackson-core, AIOHTTP, ruby-jwt, Eclipse Jetty, and ansible-core. The update fixes argument injection flaws leading to code execution and other critical security issues. The advisory rates the update as important and recommends applying it after ensuring all previous errata are applied. Join the discussion | GCVE Database | 09/03/2026, 23:00:42 UTC Added: 09/04/2026, 14:25:19 UTC |
0 Red Hat Satellite 6.18 prior to 6.18.9 contains multiple security vulnerabilities affecting components such as aiohttp, Eclipse Jetty, jackson-core, ansible-core, puppetserver, and ruby-jwt. These include HTTP request smuggling, denial of service, information disclosure, arbitrary code execution, and authentication bypass issues. The update to version 6.18.9 addresses these vulnerabilities along with several bug fixes. Users are advised to apply this update after ensuring all previous errata are installed. Join the discussion | GCVE Database | 09/03/2026, 22:05:12 UTC Added: 09/04/2026, 14:25:19 UTC |
0 Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network. Join the discussion | GCVE Database | 08/13/2026, 19:46:27 UTC Added: 07/11/2026, 09:36:49 UTC |
0 Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network. Join the discussion | GCVE Database | 08/13/2026, 19:46:27 UTC Added: 07/11/2026, 09:36:49 UTC |
0 ### Summary The client accepts and decompresses frames with the RSV1 bit set even when the `permessage-deflate` extension was not negotiated. ### Impact A client may unexpectedly decompress WebSocket frames when explicitly opted out. This could lead to additional CPU/memory consumption, but is unlikely to be a significant issue unless a zip bomb vulnerability or similar is also present. --- Patch: https://github.com/aio-libs/aiohttp/commit/47fb6ae354d4fa22048f4dbe7dbf82b625f0a2f6 Join the discussion | GCVE Database | 08/13/2026, 17:46:47 UTC Added: 09/17/2026, 01:58:54 UTC |
0 An out-of-bounds heap read vulnerability exists in the C HTTP response parser of vdirsyncer when handling malformed chunked responses. This flaw can cause a denial of service (DoS) if an attacker-controlled server or an accidental malformed response triggers the error path. A patch is available to fix this issue. As a workaround, users can disable the C parser by setting the environment variable AIOHTTP_NO_EXTENSIONS=1 to use the unaffected Python parser. Join the discussion | GCVE Database | 08/13/2026, 17:46:47 UTC Added: 08/14/2026, 16:37:04 UTC |
### Summary When assert statements are bypassed, an infinite loop can occur, resulting in a DoS attack when processing a POST body. ### Impact If optimisations are enabled (`-O` or `PYTHONOPTIMIZE=1`), and the application includes a handler that uses the `Request.post()` method, then an attacker may be able to execute a DoS attack with a specially crafted message. ------ Patch: https://github.com/aio-libs/aiohttp/commit/bc1319ec3cbff9438a758951a30907b072561259 Join the discussion | GCVE Database | 08/13/2026, 17:46:47 UTC Added: 05/26/2026, 20:58:21 UTC |
0 ### Summary A zip bomb can be used to execute a DoS against the aiohttp server. ### Impact An attacker may be able to send a compressed request that when decompressed by aiohttp could exhaust the host's memory. ------ Patch: https://github.com/aio-libs/aiohttp/commit/2b920c39002cee0ec5b402581779bbaaf7c9138a Join the discussion | GCVE Database | 08/13/2026, 17:46:47 UTC Added: 05/26/2026, 20:58:16 UTC |
Showing 1 to 10 of 15 results