jwcrypto 中发现了缺陷。远程攻击者可以发送一个经过特殊构造的 JSON Web 加密(JWE)令牌,其中包含大量的周期分隔符。这个格式错误的令牌可以强制 JWE.deserialize() 函数分配过多的内存,从而导致 MemoryError(内存错误)。这会导致处理不受信任的 JWE 值的服务发生拒绝服务(DoS)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2 | any |
affected |
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
| … +5 more rows | |||
| Red Hat | Red Hat Enterprise Linux 10 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 9 | any |
unknown |
| Red Hat | Red Hat OpenShift AI (RHOAI) | any |
affected |
any |
affected | ||
| Red Hat | Red Hat OpenStack Platform 16.2 | any |
affected |
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenShift AI (RHOAI) | - |
cpe:/a:redhat:openshift_ai
|
|
| Red Hat | Red Hat OpenStack Platform 16.2 | - |
cpe:/a:redhat:openstack:16.2
|
|
| Red Hat | Red Hat OpenStack Platform 16.2 | - |
cpe:/a:redhat:openstack:16.2
|
|
| Red Hat | Red Hat OpenStack Platform 16.2 | - |
cpe:/a:redhat:openstack:16.2
|
|
| Red Hat | Red Hat OpenStack Platform 16.2 | - |
cpe:/a:redhat:openstack:16.2
|
|
| Red Hat | Red Hat OpenStack Platform 16.2 | - |
cpe:/a:redhat:openstack:16.2
|
|
| Red Hat | Red Hat OpenStack Platform 16.2 | - |
cpe:/a:redhat:openstack:16.2
|
|
| Red Hat | Red Hat OpenStack Platform 16.2 | - |
cpe:/a:redhat:openstack:16.2
|
|
| Red Hat | Red Hat OpenStack Platform 16.2 | - |
cpe:/a:redhat:openstack:16.2
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78002 | 7.5 HIGH | Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() fun |
| CVE-2026-5680 | 7.5 HIGH | Undertow-core: undertow: denial of service via websocket permessage-deflate processing |
| CVE-2026-81658 | 6.5 MEDIUM | Foreman: cross-tenant disclosure of template revisions via unauthorized audit lookup |
| CVE-2026-81668 | 5.4 MEDIUM | Rubygem-katello: cross-tenant content view filter rule access and modification via unautho |
| CVE-2026-81893 | 4.7 MEDIUM | Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recovery |
No comments yet