Wildfly是Wildfly基金会开源的一款应用服务器中间件。 Wildfly存在输入验证错误漏洞,该漏洞源于密码哈希和验证使用Unicode NFKC规范化输入,可能将全角字符折叠为ASCII等效字符,导致远程攻击者更容易通过纯ASCII字典猜出受影响密码,从而未授权访问。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat build of Apache Camel 4 for Quarkus 3 | any |
affected |
| Red Hat | Red Hat build of Debezium 3 | any |
affected |
| Red Hat | Red Hat Build of Keycloak | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Data Grid 8 | any |
affected |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | any |
affected |
any |
affected | ||
any |
affected | ||
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | any |
affected |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | any |
unaffected |
| Red Hat | Red Hat Single Sign-On 7 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67567 | 9.9 CRITICAL | Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart ap |
| CVE-2026-11861 | 9.6 CRITICAL | Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relations |
| CVE-2026-13097 | 8.7 HIGH | Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniquenes |
| CVE-2026-77176 | 8.1 HIGH | Kata-containers: insufficient validation of createcontainer mount and storage rules in gen |
| CVE-2026-18917 | 7.8 HIGH | Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow |
| CVE-2026-73137 | 7.7 HIGH | Multicloud-operators-subscription: multicloud-operators-subscription: cross-namespace secr |
| CVE-2026-73197 | 7.5 HIGH | Ipa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request b |
| CVE-2026-73198 | 7.5 HIGH | Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read |
| CVE-2026-73199 | 6.5 MEDIUM | Ipa: freeipa: null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) |
| CVE-2026-66787 | 5.4 MEDIUM | Lighthouse: go pprof profiling endpoint enabled unconditionally on lighthouse-agent :8082 |
| CVE-2026-77014 | 5.3 MEDIUM | Libsoup: libsoup: integer truncation in sort_ranges() comparator causes silent omission of |
| CVE-2026-73196 | 4.3 MEDIUM | Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encodi |
| CVE-2026-66788 | 3.7 LOW | Lighthouse: dockerfile build stages use end-of-life fedora 40 referenced by mutable tag |
| CVE-2026-66785 | 2.5 LOW | Submariner: ipsec psk secrets file created with default world-readable permissions |
No comments yet