Skip to main content

Threats Tagged 'cwe-606'

View all threats tagged with 'cwe-606'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-606

Threats Tagged 'cwe-606'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the RPM packages for Red Hat OpenShift Container Platform 4.21.35. See the following advisory for the container images for this release: https://access.redhat.com/errata/RHSA-2026:71453 Security Fix(es): * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.21 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.21/html-single/updating_clusters/index#updating-cluster-cli.

Join the discussion

Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service

Join the discussion

Temporal Server did not bound the work performed while searching for a Schedule's next action time. An authenticated caller with namespace write permission could create or update a Schedule that combines a fine-grained cadence with an exclusion calendar that rejects every candidate time, causing the server to evaluate excluded candidates without a per-search work budget. This can consume excessive CPU in Frontend and Schedule worker components. A persisted specification can also cause its backing Schedule Workflow to repeatedly fail and retry, allowing CPU consumption to continue without additional requests until the Schedule is deleted or its backing Workflow is terminated. Repeated or parallel exploitation can deny service. The issue affects availability only; it does not expose or modify Workflow data.

Join the discussion

Red Hat Lightspeed in Satellite analyzes system health and configuration by applying predefined rules to a small set of local data, such as installed packages, running services, and configuration settings.

Join the discussion

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.18.55. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:66385 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ Security Fix(es): * bind: BIND: Denial of Service via maliciously crafted DNSSEC-validated zone (CVE-2026-1519) * samba: group policy certificate enrollment uses http:// without validation (CVE-2026-3012) * bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (CVE-2026-3039) * bind: BIND: Denial of Service via specially crafted DNS messages (CVE-2026-5946) * dracut: dracut: Root code execution via DHCP options command injection (CVE-2026-6893) * bind9: bind: Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331) * sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data (CVE-2026-11822) * sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 (CVE-2026-11824) * bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321) * dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die() (CVE-2026-15816) * sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export (CVE-2026-16313) * golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * kernel: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (CVE-2026-43112) * samba: vfs_worm does not block directory modification (CVE-2026-2340) * gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison (CVE-2026-3833) * bind: bind9: Incorrect acceptance of NSEC3 records (CVE-2026-10723) * libarchive: Double-Free Vulnerability in RAR5 Decompression Logic via dangling filtered_buf pointer in init_unpack() (CVE-2026-14164) * systemd: systemd: Arbitrary code execution or Denial of Service via spurious IPC API call data (CVE-2026-29111) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli.

Join the discussion

Red Hat Edge Manager (RHEM) provides simple, scalable, and security-focused management of edge devices and applications. It supports image-mode RHEL and container workloads that run on Podman/Docker or Kubernetes. RHEM is now available as a standalone feature, providing greater flexibility for edge deployments. In addition to the standalone version, RHEM continues to be offered as a plugin for the following platforms: Red Hat Advanced Cluster Management (RHACM): Extends fleet management to edge devices. Red Hat Ansible Automation Platform (AAP): Integrates edge management with Ansible automation. This integration enables organizations to optimize the management and orchestration of their fleets of edge devices; whether its thousands of dispersed retail point-of-sale systems or industrial machinery on remote factory floors. Value for customers and partners: * This solution not only helps customers manage thousands of devices but helps scale operations. * To manage large-scale deployments, customers need to be able to integrate with their existing management systems, support remote configuration and over-the-air updates, and collect telemetry data for advanced analytics. * Red Hat Edge Manager offers a simple and security-focused lifecycle management, from onboarding to decommissioning of edge devices. This complete end-to-end solution empowers organizations to gain the most value from the fleets of devices that generate data, all from a centralized location. Security Fixes: * flightctl: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) * flightctl: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * flightctl: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178) * flightctl: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740) * flightctl: Arc: Information disclosure and Denial of Service via unauthenticated debug endpoints (CVE-2026-48050) * flightctl: golang.org/x/text: Denial of Service via invalid UTF-8 input (CVE-2026-56852) * flightctl: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * flightctl: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * flightctl: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) * flightctl: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * flightctl: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * flightctl: go-git: Arbitrary file read/write via symbolic link resolution (CVE-2026-71556)

Join the discussion

smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infinite loop when a value inside an array or inline table is followed by a comment with no trailing newline. In src/util.ts, skipUntil() calls indexOfNewline(), receives -1 at the end of input, and resets the cursor to the beginning of the string instead of leaving the structure scan. The parser then hangs indefinitely and can consume a service's processing capacity when an application parses attacker-controlled TOML. This issue is fixed in version 1.7.1.

Join the discussion

Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Join the discussion

GNU wget contains a denial of service vulnerability in its FTP OPIE/S-KEY authentication. The vulnerability arises because the server-supplied sequence number used as a loop iteration count for MD5 key derivation is unchecked and can be extremely large. This can cause wget to perform excessive CPU-intensive computations, suspending the process for a significant time. The --timeout option does not mitigate this issue as it only applies to network I/O, not CPU usage. The issue was fixed in a specific commit.

Join the discussion

Pega Infinity versions 7.1.0 through 25.1.2 contain a vulnerability due to improper validation of inputs used as loop conditions. This flaw can cause excessive looping, potentially resulting in denial of service or other adverse effects. The vulnerability is identified as CWE-606 and has a high severity score of 8.8. No official patch or remediation guidance has been provided yet, and there are no known exploits in the wild.

Join the discussion

Showing 1 to 10 of 34 results

Filters:Tag: cwe-606
Page 1 of 4
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses