CVE-2026-94000
- EPSS 0.24%
- Veröffentlicht 19.09.2026 14:09:17
- Zuletzt bearbeitet 22.09.2026 19:37:36
A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges before allowing...
CVE-2026-93999
- EPSS 0.15%
- Veröffentlicht 19.09.2026 14:09:11
- Zuletzt bearbeitet 22.09.2026 19:37:36
A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores requested audiences from stored client IDs. Keycloak ...
CVE-2026-93562
- EPSS 0.28%
- Veröffentlicht 18.09.2026 20:12:51
- Zuletzt bearbeitet 22.09.2026 21:17:33
A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending specially crafted HTTP requests, an attacker can inject arbitrary HTTP req...
CVE-2026-93574
- EPSS 0.36%
- Veröffentlicht 18.09.2026 20:12:43
- Zuletzt bearbeitet 24.09.2026 11:17:01
A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size token that includes post-digit whitespace. This incorrect parsing of the chunk size can le...
CVE-2026-93573
- EPSS 0.23%
- Veröffentlicht 18.09.2026 14:44:00
- Zuletzt bearbeitet 24.09.2026 11:17:00
A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final t...
CVE-2026-93568
- EPSS 0.47%
- Veröffentlicht 18.09.2026 14:34:04
- Zuletzt bearbeitet 22.09.2026 19:16:58
A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty's HTTP-object conversion path incorrectly processes these requests as regular HTTP/1.1 CONNEC...
CVE-2026-93569
- EPSS 0.37%
- Veröffentlicht 18.09.2026 14:27:54
- Zuletzt bearbeitet 22.09.2026 19:16:58
A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, Netty incorre...
CVE-2026-93567
- EPSS 0.4%
- Veröffentlicht 18.09.2026 14:23:27
- Zuletzt bearbeitet 22.09.2026 19:16:58
A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority. A remote attacker can exploit t...
CVE-2026-10832
- EPSS 0.28%
- Veröffentlicht 18.09.2026 14:19:29
- Zuletzt bearbeitet 29.09.2026 12:17:10
A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER (Distinguished Encoding Rules) payload. The decoder attempts to allocate exc...
CVE-2026-93566
- EPSS 0.38%
- Veröffentlicht 18.09.2026 14:19:29
- Zuletzt bearbeitet 24.09.2026 11:16:59
A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arb...