CVEs (24)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 10Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+7 moreJul 22, 2026 Mar 27, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, whic...Show more |
1Redhat 10Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+7 moreJun 29, 2026 Mar 27, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in he...Show more |
1Redhat 9Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+6 moreJun 29, 2026 Mar 27, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions o...Show more |
1Redhat 10Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+7 moreJul 7, 2026 Mar 24, 2026 N/A· v4 N/A· v3 N/A· v2 Rejected reason: The Undertow web server enforces a default maximum HTTP request entity size limit. Any request (including GET or HEAD) containing a body that exceeds this configurable limit is safely dropped by the serv...Show more |
1Redhat 8Build Of Apache Camel Data GridFuse+5 moreJul 24, 2026 Jan 7, 2026 N/A· v4 9.6 CRITICAL· v3 N/A· v2 A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result,...Show more |
1Redhat 8Build Of Apache Camel For Spring Boot Enterprise LinuxFuse+5 moreJul 24, 2026 Sep 2, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to indu...Show more |
1Redhat 9Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootBuild Of Keycloak+6 moreJun 17, 2026 Aug 21, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple request...Show more |
33Akka AmazonApache+30 more165.net 3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+162 moreJun 17, 2026 Oct 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
2Netapp Redhat16Build Of Quarkus Decision ManagerFuse+13 moreJun 17, 2026 Sep 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. |
1Redhat 4Decision Manager DroolsJboss Middleware Text Only Advisories+1 moreJun 17, 2026 Sep 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadge...Show more |
1Redhat 2Decision Manager Process AutomationJun 17, 2026 Oct 17, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console. |
1Redhat 9A Mq Streams Build Of QuarkusDescision Manager+6 moreJun 17, 2026 Aug 24, 2022 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supp...Show more |
1Redhat 3Business Central Descision ManagerProcess AutomationJun 17, 2026 Apr 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc. |
1Redhat 5Descision Manager Jboss Enterprise Application PlatformJboss Enterprise Application Platform Expansion Pack+2 moreJun 17, 2026 Mar 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability. |
4Apache FedoraprojectOracle+1 more46Advanced Supply Chain Planning Business IntelligenceBusiness Process Management Suite+43 moreJun 17, 2026 Dec 14, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName c...Show more |
2Quarkus Redhat13Build Of Quarkus Codeready StudioData Grid+10 moreJun 17, 2026 Aug 5, 2021 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnera...Show more |
1Redhat 3Descision Manager JbpmProcess AutomationJun 17, 2026 Jun 1, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the name of Ruleflow Groups from other projects, despite the user not having access to those projects. The...Show more |
1Redhat 9A Mq Online Build Of QuarkusCodeready Studio+6 moreJun 17, 2026 Mar 16, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside t...Show more |
2Netapp Redhat6Codeready Studio Descision ManagerJboss Fuse+3 moreJun 17, 2026 Sep 23, 2020 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat fr...Show more |
1Redhat 3Decision Manager Process AutomationWildfly ElytronJun 17, 2026 Sep 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorizatio...Show more |