CVEs (28)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 10Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+7 moreMar 31, 2026 Mar 27, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, whic...Show more |
1Redhat 10Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+7 moreMar 31, 2026 Mar 27, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in he...Show more |
1Redhat 9Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+6 moreApr 10, 2026 Mar 27, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions o...Show more |
1Redhat 10Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+7 moreApr 8, 2026 Mar 24, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes parameters using methods lik...Show more |
1Redhat 8Build Of Apache Camel Data GridFuse+5 moreMar 18, 2026 Jan 7, 2026 N/A· v4 9.6 CRITICAL· v3 N/A· v2 A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result,...Show more |
1Redhat 8Build Of Apache Camel For Spring Boot Enterprise LinuxFuse+5 moreMar 18, 2026 Sep 2, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to indu...Show more |
2Netapp Redhat9Active Iq Unified Manager FuseIntegration Camel For Spring Boot+6 moreJun 25, 2025 Feb 19, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then...Show more |
2Netapp Redhat16Build Of Quarkus Decision ManagerFuse+13 moreNov 21, 2024 Sep 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. |
1Redhat 9A Mq Streams Build Of QuarkusDescision Manager+6 moreNov 21, 2024 Aug 24, 2022 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supp...Show more |
1Redhat 7Fuse Integration Camel KIntegration Camel Quarkus+4 moreNov 21, 2024 Aug 23, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is a...Show more |
2Netapp Redhat8Active Iq Unified Manager FuseJboss Enterprise Application Platform+5 moreNov 21, 2024 May 24, 2022 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affect...Show more |
1Redhat 4Fuse Jboss Enterprise Application PlatformOpenshift Application Runtimes+1 moreNov 21, 2024 May 27, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could us...Show more |
2Netapp Redhat10Active Iq Unified Manager FuseJboss Data Grid+7 moreNov 21, 2024 Nov 2, 2020 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain...Show more |
3Hibernate QuarkusRedhat10Build Of Quarkus Decision ManagerFuse+7 moreNov 21, 2024 Jul 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or G...Show more |
2Netapp Redhat8Active Iq Unified Manager FuseJboss Enterprise Application Platform+5 moreNov 21, 2024 May 26, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling. |
3Infinispan NetappRedhat7Active Iq Unified Manager FuseInfinispan+4 moreNov 21, 2024 Nov 25, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The att...Show more |
It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized infor...Show more |
3Netapp OracleRedhat188Access Manager Active Iq Unified ManagerAgile Engineering Data Management+185 moreJul 7, 2025 Nov 8, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can r...Show more |
5Apache DebianNetapp+2 more10Activemq Debian LinuxDrill+7 moreNov 21, 2024 May 23, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information c...Show more |
A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2...Show more |