Threats Tagged 'cve-2026-76844'
View all threats tagged with 'cve-2026-76844'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-76844'
Click on any threat for detailed analysis and mitigation recommendations
Red Hat Data Grid 8.6.3 addresses multiple security vulnerabilities including denial of service, information disclosure, cross-site scripting, and security bypass issues primarily in Netty components and related libraries. These vulnerabilities affect the in-memory distributed NoSQL datastore solution and could impact availability, confidentiality, and integrity. The update replaces version 8.6.2 and includes fixes for a range of CVEs such as CVE-2026-44891 (Netty STOMP decoder DoS) and CVE-2026-49978 (DOMPurify XSS). Join the discussion | GCVE Database | 09/21/2026, 12:19:52 UTC Added: 08/14/2026, 16:36:47 UTC |
Red Hat Data Grid is an in-memory, distributed, NoSQL datastore solution. It increases application response times and allows for dramatically improving performance while providing availability, reliability, and elastic scale. Data Grid 8.6.3 replaces Data Grid 8.6.2 and includes bug fixes and enhancements. Find out more about Data Grid 8.6.3 in the Release Notes[3]. Security Fix(es): * CVE-2026-68494 jackson-core: jackson-core: Denial of Service via incomplete fix in async JSON parser [jdg-8.6] (CVE-2026-68494) * CVE-2026-56745 datagrid-8/datagrid-8: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec [jdg-8.6] (CVE-2026-56745) * CVE-2026-62243 netty-handler: Netty: TLS hostname verification bypass via OpenSSL client path misconfiguration [jdg-8.6] (CVE-2026-62243) * CVE-2026-73508 netty-codec-dns: Netty: Denial of Service via Memory Leak in DNS Record Decoder with Malformed Domain Names [jdg-8.6] (CVE-2026-73508) * CVE-2026-49978 dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution [jdg-8.6] (CVE-2026-49978) * CVE-2026-76844 redhat-datagrid-maven-repository.zip: webpack-dev-middleware: Information Disclosure via Path Traversal [jdg-8.6] (CVE-2026-76844) * CVE-2026-59901 netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) [jdg-8.6] (CVE-2026-59901) * CVE-2026-59899 netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) [jdg-8.6] (CVE-2026-59899) * CVE-2026-56820 netty-handler-ssl-ocsp: Netty: Certificate revocation bypass via OCSP response replay attack [jdg-8.6] (CVE-2026-56820) * CVE-2026-56819 netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak [jdg-8.6] (CVE-2026-56819) * CVE-2026-56817 netty-codec-xml: Netty: Information disclosure via XML External Entity (XXE) vulnerability [jdg-8.6] (CVE-2026-56817) * CVE-2026-56746 netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header [jdg-8.6] (CVE-2026-56746) * CVE-2026-55851 netty-codec-haproxy: Netty codec-haproxy: Denial of Service via crafted PROXY protocol v2 message [jdg-8.6] (CVE-2026-55851) * CVE-2026-55831 netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing [jdg-8.6] (CVE-2026-55831) * CVE-2026-55833 netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification [jdg-8.6] (CVE-2026-55833) * CVE-2026-44891 netty-codec-stomp: Netty: Denial of Service vulnerability in STOMP decoder [jdg-8.6] (CVE-2026-44891) * CVE-2026-59296 micrometer-core: Micrometer: Line-protocol and log injection via unsanitized input allows metric and log spoofing [jdg-8.6] (CVE-2026-59296) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/21/2026, 12:19:52 UTC Added: 08/14/2026, 16:36:44 UTC |
0 Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network. Join the discussion | GCVE Database | 08/31/2026, 21:39:55 UTC Added: 06/02/2026, 21:44:02 UTC |
0 Red Hat Discovery, also known as Discovery, is an inspection and reporting tool that finds, identifies, and reports environment data, or facts, such as the number of physical and virtual systems on a network, their operating systems, and relevant configuration data stored within them. Discovery also identifies and reports more detailed facts for some versions of key Red Hat packages and products that it finds in the network. Join the discussion | GCVE Database | 08/31/2026, 21:39:55 UTC Added: 06/02/2026, 21:44:02 UTC |
0 CVE-2026-76844 is a high-severity path traversal vulnerability in webpack-dev-middleware. It arises from improper pathname validation when the configured publicPath lacks a trailing slash, allowing crafted requests to bypass traversal guards and access files outside the intended directory. This vulnerability affects versions starting from 5.3.4, 6.1.2, 7.1.0, and later up to 8.1.1. The issue is a partial regression of a previous vulnerability (CVE-2024-29180) and requires the middleware to be backed by a physical filesystem to be exploitable. No official patch or remediation guidance is currently provided. Join the discussion | CVE Database V5 | 08/24/2026, 13:12:01 UTC Added: 08/24/2026, 13:22:59 UTC |
Showing 1 to 5 of 5 results