Skip to main content

Vendor/product archive

redhat / fuse CVEs

Beta · best-effort

26 CVEs tagged to redhat / fuse4 Critical, 11 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2026-28369

Published Mar 27, 2026

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping…

CVSS 8.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-28368

Published Mar 27, 2026

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to…

CVSS 8.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-28367

Published Mar 27, 2026

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certai…

CVSS 8.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2025-57849

Published Mar 13, 2026

A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time.…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-12543

Published Jan 7, 2026

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host heade…

CVSS 9.6 · Critical
evidence mentions
16
Buzz score
39.8

CVE-2025-9784

Published Sep 2, 2025

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset"…

CVSS 7.5 · High
evidence mentions
20
Buzz score
50.0

CVE-2024-1635

Published Feb 19, 2024

A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection…

CVSS 7.5 · High

CVE-2021-4178

Published Aug 24, 2022

A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allo…

CVSS 6.7 · Medium

CVE-2021-3690

Published Aug 23, 2022

A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The hi…

CVSS 7.5 · High

CVE-2021-3597

Published May 24, 2022

A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulner…

CVSS 5.9 · Medium

CVE-2020-25689

Published Nov 2, 2020

A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly c…

CVSS 5.3 · Medium

CVE-2019-14900

Published Jul 6, 2020

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals…

CVSS 6.5 · Medium

CVE-2020-10719

Published May 26, 2020

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advanta…

CVSS 6.5 · Medium

CVE-2019-10174

Published Nov 25, 2019

A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any cl…

CVSS 8.8 · High

CVE-2019-14860

Published Nov 8, 2019

It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing atta…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0201

Published May 23, 2019

An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the req…

CVSS 5.9 · Medium

CVE-2019-0204

Published Mar 25, 2019

A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2