Redhat

Fuse

37 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Veröffentlicht 11.08.2026 15:32:00
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chu...

  • EPSS 0.44%
  • Veröffentlicht 11.08.2026 09:17:13
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size.

  • EPSS 0.48%
  • Veröffentlicht 11.08.2026 09:17:13
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack without authe...

  • EPSS 0.34%
  • Veröffentlicht 11.08.2026 02:35:22
  • Zuletzt bearbeitet 14.08.2026 19:07:46

A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload into the Inet Address field through the Management Model. This injection causes the server to crash and become unrecoverable, as th...

  • EPSS 0.51%
  • Veröffentlicht 09.06.2026 23:49:26
  • Zuletzt bearbeitet 05.08.2026 13:22:14

JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean de...

  • EPSS 0.68%
  • Veröffentlicht 27.03.2026 16:13:05
  • Zuletzt bearbeitet 22.07.2026 06:16:33

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can...

  • EPSS 0.71%
  • Veröffentlicht 27.03.2026 16:13:05
  • Zuletzt bearbeitet 29.06.2026 10:16:30

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Go...

  • EPSS 0.7%
  • Veröffentlicht 27.03.2026 16:13:03
  • Zuletzt bearbeitet 29.06.2026 10:16:31

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exp...

  • EPSS 0.21%
  • Veröffentlicht 13.03.2026 03:08:32
  • Zuletzt bearbeitet 05.06.2026 19:57:46

A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an ...

  • EPSS 0.78%
  • Veröffentlicht 23.01.2026 06:31:38
  • Zuletzt bearbeitet 19.08.2026 12:17:14

A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClauseBuilder i...