Skip to main content

Vendor/product archive

redhat / data_grid CVEs

Beta · best-effort

20 CVEs tagged to redhat / data_grid3 Critical, 9 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2026-28369

Published Mar 27, 2026

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping…

CVSS 8.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-28368

Published Mar 27, 2026

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to…

CVSS 8.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-28367

Published Mar 27, 2026

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certai…

CVSS 8.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2025-12543

Published Jan 7, 2026

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host heade…

CVSS 9.6 · Critical
evidence mentions
16
Buzz score
39.8

CVE-2024-7885

Published Aug 21, 2024

A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyPro…

CVSS 7.5 · High

CVE-2023-4586

Published Oct 4, 2023

A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-i…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3536

Published May 20, 2021

A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, lead…

CVSS 4.8 · Medium

CVE-2020-25644

Published Oct 6, 2020

A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of s…

CVSS 7.5 · High
Showing 1-20 of 20 CVEsPage 1 of 1