Red Hat / Fuse
29 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-41731 | In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization | HIGH | 8.1 | Jun 9, 2026 |
| CVE-2026-28369 | Undertow: undertow: request smuggling via malformed http request headers | CRITICAL | 9.1 | Mar 27, 2026 |
| CVE-2026-28367 | Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator | CRITICAL | 9.1 | Mar 27, 2026 |
| CVE-2026-28368 | Undertow: undertow: request smuggling via inconsistent header parsing | CRITICAL | 9.1 | Mar 27, 2026 |
| CVE-2025-57849 | Fuse: privilege escalation via excessive /etc/passwd permissions | MEDIUM | 6.4 | Mar 13, 2026 |
| CVE-2025-12543 | Undertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrf | CRITICAL | 9.6 | Jan 7, 2026 |
| CVE-2025-9784 | Undertow: undertow madeyoureset http/2 ddos vulnerability | HIGH | 7.5 | Sep 2, 2025 |
| CVE-2024-1635 | Undertow: out-of-memory error after several closed connections with wildfly-http-client protocol | HIGH | 8.7 | Feb 19, 2024 |
| CVE-2023-1108 | Undertow: infinite loop in sslconduit during close | HIGH | 7.5 | Sep 14, 2023 |
| CVE-2021-4178 | kubernetes-client: Insecure deserialization in unmarshalYaml method | MEDIUM | 6.7 | Aug 24, 2022 |
| CVE-2021-3690 | undertow: buffer leak on incoming websocket PONG message may lead to DoS | HIGH | 7.5 | Aug 23, 2022 |
| CVE-2021-3597 | undertow: HTTP2SourceChannel fails to write final frame under some circumstances may lead to DoS | MEDIUM | 5.9 | May 24, 2022 |
| CVE-2020-10688 | RESTEasy: RESTEASY003870 exception in RESTEasy can lead to a reflected XSS attack | MEDIUM | 6.1 | May 27, 2021 |
| CVE-2020-25689 | wildfly-core: memory leak in WildFly host-controller in domain mode while not able to reconnect to domain-controller | MEDIUM | 6.5 | Oct 30, 2020 |
| CVE-2019-14900 | hibernate: SQL injection issue in Hibernate ORM | MEDIUM | 6.5 | Jul 6, 2020 |
| CVE-2020-10719 | undertow: invalid HTTP request with large chunk size | MEDIUM | 6.5 | May 26, 2020 |
| CVE-2019-10174 | infinispan: invokeAccessibly method from ReflectionUtil class allows to invoke private methods | HIGH | 8.8 | Nov 25, 2019 |
| CVE-2019-10219 | hibernate-validator: safeHTML validator allows XSS | MEDIUM | 6.1 | Nov 8, 2019 |
| CVE-2019-14860 | syndesis: default CORS configuration is allow all | MEDIUM | 6.5 | Nov 8, 2019 |
| CVE-2019-0201 | zookeeper: Information disclosure in Apache ZooKeeper | MEDIUM | 5.9 | May 23, 2019 |
| CVE-2019-0204 | mesos: docker image code execution | HIGH | 7.8 | Mar 25, 2019 |
| CVE-2016-8653 | Fuse-6: JMX endpoint deserializes untrusted credentials. | MEDIUM | 5.3 | Aug 1, 2018 |
| CVE-2018-1258 | spring-security-core: Unauthorized Access with Spring Security Method Security | HIGH | 8.8 | May 11, 2018 |
| CVE-2018-1270 | spring-framework: Possible RCE via spring messaging | CRITICAL | 9.8 | Apr 6, 2018 |
| CVE-2018-1199 | spring-framework: Improper URL path validation allows for bypassing of security checks on static resources | MEDIUM | 5.3 | Mar 16, 2018 |
Showing 1 to 25 of 29 CVEs