在 中发现一个安全漏洞。该漏洞允许远程攻击者通过单条连接以比应用程序处理速度更快的速率连续发送消息,从而触发拒绝服务(Denial of Service,DoS)攻击。由于存在无限制的消息缓冲机制以及缺乏读取背压(backpressure)控制,系统会迅速耗尽堆内存空间,最终导致抛出 异常,进而使 Java 虚拟机(JVM)崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Exploit Intelligence | - |
cpe:/a:redhat:exploit_intelligence:0
|
|
| Red Hat | Red Hat build of Quarkus | - |
cpe:/a:redhat:quarkus:3
|
|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86320 | 7.8 HIGH | Flatpak-builder: host code execution via `git am` hook execution in patch source extractio |
| CVE-2026-92925 | 7.1 HIGH | Redis: redis: out-of-bounds read via crafted cluster bus packets |
| CVE-2026-76781 | 5.5 MEDIUM | Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute |
| CVE-2026-81829 | 5.3 MEDIUM | Smallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: unauthenticated same-origin ssrf via uns |
| CVE-2026-92904 | 4.3 MEDIUM | Rubygem-foreman_remote_execution: job output readable without object-level view_job_invoca |
| CVE-2026-92893 | 4.3 MEDIUM | Rubygem-foreman_ansible: ansible inventory api ignores view_hosts permission filters, expo |
| CVE-2026-92894 | 4.3 MEDIUM | Rubygem-foreman_ansible: unscoped lookupvalue deletion allows cross-model override value d |
No comments yet