Skip to main content

Threats Tagged 'cve-2026-76844'

View all threats tagged with 'cve-2026-76844'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-76844

Threats Tagged 'cve-2026-76844'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat Data Grid 8.6.3 addresses multiple security vulnerabilities including denial of service, information disclosure, cross-site scripting, and security bypass issues primarily in Netty components and related libraries. These vulnerabilities affect the in-memory distributed NoSQL datastore solution and could impact availability, confidentiality, and integrity. The update replaces version 8.6.2 and includes fixes for a range of CVEs such as CVE-2026-44891 (Netty STOMP decoder DoS) and CVE-2026-49978 (DOMPurify XSS).

Join the discussion

Red Hat Data Grid is an in-memory, distributed, NoSQL datastore solution. It increases application response times and allows for dramatically improving performance while providing availability, reliability, and elastic scale. Data Grid 8.6.3 replaces Data Grid 8.6.2 and includes bug fixes and enhancements. Find out more about Data Grid 8.6.3 in the Release Notes[3]. Security Fix(es): * CVE-2026-68494 jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser [jdg-8.6] (CVE-2026-68494) * CVE-2026-56745 datagrid-8/datagrid-8: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec [jdg-8.6] (CVE-2026-56745) * CVE-2026-62243 netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration [jdg-8.6] (CVE-2026-62243) * CVE-2026-73508 netty-codec-dns: Netty: Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names [jdg-8.6] (CVE-2026-73508) * CVE-2026-49978 dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution [jdg-8.6] (CVE-2026-49978) * CVE-2026-76844 redhat-datagrid-maven-repository.zip: webpack-dev-middleware: Information Disclosure via Path Traversal [jdg-8.6] (CVE-2026-76844) * CVE-2026-59901 netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) [jdg-8.6] (CVE-2026-59901) * CVE-2026-59899 netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) [jdg-8.6] (CVE-2026-59899) * CVE-2026-56820 netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack [jdg-8.6] (CVE-2026-56820) * CVE-2026-56819 netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak [jdg-8.6] (CVE-2026-56819) * CVE-2026-56817 netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability [jdg-8.6] (CVE-2026-56817) * CVE-2026-56746 netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header [jdg-8.6] (CVE-2026-56746) * CVE-2026-55851 netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message [jdg-8.6] (CVE-2026-55851) * CVE-2026-55831 netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing [jdg-8.6] (CVE-2026-55831) * CVE-2026-55833 netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification [jdg-8.6] (CVE-2026-55833) * CVE-2026-44891 netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder [jdg-8.6] (CVE-2026-44891) * CVE-2026-59296 micrometer-core: Micrometer: Line-protocol and log injection via unsanitized input allows metric and log spoofing [jdg-8.6] (CVE-2026-59296) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network.

Join the discussion

Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network.

Join the discussion

CVE-2026-76844 is a high-severity path traversal vulnerability in webpack-dev-middleware. It arises from improper pathname validation when the configured publicPath lacks a trailing slash, allowing crafted requests to bypass traversal guards and access files outside the intended directory. This vulnerability affects versions starting from 5.3.4, 6.1.2, 7.1.0, and later up to 8.1.1. The issue is a partial regression of a previous vulnerability (CVE-2024-29180) and requires the middleware to be backed by a physical filesystem to be exploitable. No official patch or remediation guidance is currently provided.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: cve-2026-76844
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses