Undertow是美国Undertow组织开源的个灵活高效的 Java Web 服务器。 Undertow存在数字错误漏洞,该漏洞源于writeString()方法在写入HTTP响应头时将16位Unicode字符静默转换为8位字节,导致字符截断为ASCII控制字符或特殊符号,可能造成有限完整性影响或信息泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | any |
affected |
any |
affected | ||
any |
affected | ||
any |
affected | ||
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | any |
affected |
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | any |
affected |
any |
affected | ||
any |
affected | ||
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | any |
affected |
any |
affected | ||
any |
affected | ||
| Red Hat | Red Hat Single Sign-On 7 | any |
affected |
any |
affected | ||
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58224 | 6.5 MEDIUM | Samba: ctdb fails to do integrity checking of received packets |
| CVE-2026-74243 | 6.5 MEDIUM | Quay: unauthenticated secscan notification endpoint in quay when psk is unset |
| CVE-2026-74244 | 5.9 MEDIUM | Quay: stripe webhook accepts forged events without signature verification in quay |
| CVE-2026-74245 | 5.9 MEDIUM | Quay: unauthenticated exported logs download in quay |
| CVE-2026-19617 | 5.5 MEDIUM | Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser |
| CVE-2026-74240 | 5.4 MEDIUM | Quay: jwt claim validation bypasses in quay federated robot and sso authentication |
| CVE-2026-74242 | 5.3 MEDIUM | Quay: repository notification uuid idor in quay api |
| CVE-2026-74241 | 4.8 MEDIUM | Quay: ldap referral filter injection in quay external ldap authentication |
| CVE-2026-13002 | 4.4 MEDIUM | Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing |
| CVE-2026-74247 | 4.2 MEDIUM | Quay: ssrf via build archive_url in quay build api |
No comments yet