CVE-2026-0603
- EPSS 0.08%
- Veröffentlicht 23.01.2026 06:31:38
- Zuletzt bearbeitet 26.01.2026 15:03:51
A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClauseBuilder i...
CVE-2025-9784
- EPSS 0.05%
- Veröffentlicht 02.09.2025 13:37:59
- Zuletzt bearbeitet 08.01.2026 23:15:43
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload b...
CVE-2025-23368
- EPSS 0.23%
- Veröffentlicht 04.03.2025 16:15:39
- Zuletzt bearbeitet 14.10.2025 16:56:41
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.
CVE-2025-23367
- EPSS 0.19%
- Veröffentlicht 30.01.2025 15:15:18
- Zuletzt bearbeitet 06.12.2025 01:15:48
A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resum...
CVE-2024-45497
- EPSS 0.58%
- Veröffentlicht 31.12.2024 03:15:05
- Zuletzt bearbeitet 21.10.2025 05:15:54
A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary...
CVE-2024-1635
- EPSS 1.06%
- Veröffentlicht 19.02.2024 22:15:48
- Zuletzt bearbeitet 07.05.2025 12:27:53
A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immedia...
CVE-2023-1108
- EPSS 0.55%
- Veröffentlicht 14.09.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:38:28
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
CVE-2021-4178
- EPSS 0.1%
- Veröffentlicht 24.08.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:37:04
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.
CVE-2021-3690
- EPSS 0.28%
- Veröffentlicht 23.08.2022 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:09
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
CVE-2021-3597
- EPSS 0.21%
- Veröffentlicht 24.05.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:21:56
A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2...