CVE-2026-93565
- EPSS 0.37%
- Veröffentlicht 18.09.2026 14:18:11
- Zuletzt bearbeitet 22.09.2026 17:17:30
A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens in Real-Time Streaming Protocol (RTSP) requests. A remote attacker can exploit this by sending a specially crafte...
CVE-2026-93564
- EPSS 0.43%
- Veröffentlicht 18.09.2026 14:13:32
- Zuletzt bearbeitet 22.09.2026 17:17:30
A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to send specially crafted PROXY-protocol v2 headers. This can lead to memory exhaustion, resulting in a Denial of Serv...
CVE-2026-93558
- EPSS 0.53%
- Veröffentlicht 18.09.2026 14:09:01
- Zuletzt bearbeitet 22.09.2026 23:17:08
A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. This leads to an unbounded growth of...
CVE-2026-93492
- EPSS 0.3%
- Veröffentlicht 18.09.2026 12:49:03
- Zuletzt bearbeitet 29.09.2026 21:19:38
A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This causes the HpackEncoder to store an excessive number of unique headers, leading to inc...
CVE-2026-93491
- EPSS 0.44%
- Veröffentlicht 18.09.2026 12:43:26
- Zuletzt bearbeitet 22.09.2026 19:16:57
A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without li...
CVE-2026-93488
- EPSS 0.46%
- Veröffentlicht 18.09.2026 11:47:52
- Zuletzt bearbeitet 22.09.2026 23:17:07
A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote peer can open a SPDY ...
CVE-2026-89059
- EPSS 0.56%
- Veröffentlicht 18.09.2026 07:13:39
- Zuletzt bearbeitet 18.09.2026 19:06:08
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image decla...
CVE-2026-90997
- EPSS 0.4%
- Veröffentlicht 17.09.2026 18:47:34
- Zuletzt bearbeitet 22.09.2026 19:16:56
A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. This vulnerability ena...
CVE-2026-19607
- EPSS 0.51%
- Veröffentlicht 16.09.2026 15:46:43
- Zuletzt bearbeitet 16.09.2026 19:42:43
A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker to register ...
CVE-2026-17526
- EPSS 0.45%
- Veröffentlicht 16.09.2026 15:46:13
- Zuletzt bearbeitet 16.09.2026 19:42:43
Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the r...