A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-orig
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | - | 0 ~ 6.2.19.Final | - |
|
| Red Hat | Red Hat build of Apache Camel 4 for Quarkus 3 | - |
cpe:/a:redhat:camel_quarkus:3
|
|
| Red Hat | Red Hat build of Apicurio Registry 3 | - |
cpe:/a:redhat:apicurio_registry:3
|
|
| Red Hat | Red Hat build of Debezium 3 | - |
cpe:/a:redhat:debezium:3
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat build of Quarkus | - |
cpe:/a:redhat:quarkus:3
|
|
| Red Hat | Red Hat Certificate System 10 | - |
cpe:/a:redhat:certificate_system:10
|
|
| Red Hat | Red Hat Certificate System 11 | - |
cpe:/a:redhat:certificate_system:11
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Fuse 7 | - |
cpe:/a:redhat:jboss_fuse:7
|
|
| Red Hat | Red Hat Fuse 7 | - |
cpe:/a:redhat:jboss_fuse:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | - |
cpe:/a:redhat:jbosseapxp
|
|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93569 | 8.2 HIGH | Io.netty/netty-codec-http2: http/1 absolute-form host mismatch is translated to http/2 :au |
| CVE-2026-93565 | 7.5 HIGH | Io.netty/netty-codec-http: netty rtspdecoder method-token smuggling via trailing control b |
| CVE-2026-89059 | 7.5 HIGH | Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos) |
| CVE-2026-93494 | 7.5 HIGH | Io.netty/netty-codec-stomp: netty: bytebuf leak in stompsubframedecoder when a frame body |
| CVE-2026-87743 | 7.5 HIGH | Quarkus-vertx-http: authorization bypass via path normalization discrepancy in quarkus htt |
| CVE-2026-93575 | 7.5 HIGH | Io.netty/netty-codec-mqtt: netty: resource exhaustion in mqttdecoder |
| CVE-2026-93572 | 7.5 HIGH | Io.netty/netty-codec-redis: netty: redisarrayaggregator nested resp headers multiply patch |
| CVE-2026-93563 | 7.5 HIGH | Io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation in smtprespon |
| CVE-2026-93488 | 7.5 HIGH | Io.netty/netty-codec-http: netty: denial of service via unbounded concurrent spdy streams |
| CVE-2026-93491 | 7.5 HIGH | Io.netty/netty-codec-http: netty: denial of service via unbounded httpservercodec http/1.1 |
| CVE-2026-93560 | 7.5 HIGH | Io.netty/netty-codec-stomp: netty: stomp codec content-length long-to-int truncation cause |
| CVE-2026-93558 | 7.5 HIGH | Io.netty/netty-codec-http: netty: unbounded per-connection queue growth in websocketserver |
| CVE-2026-93564 | 7.5 HIGH | Io.netty/netty-codec-haproxy: netty: haproxy proxy-v2 nested-tlv grandchild bytebuf refere |
| CVE-2026-93567 | 7.5 HIGH | Io.netty/netty-codec-http2: http/1 authority-form connect is translated to malformed http/ |
| CVE-2026-91149 | 7.5 HIGH | Cockpit: cockpit: denial of service via unbounded connection thread spawning |
| CVE-2026-93576 | 7.5 HIGH | Io.netty/netty-codec-smtp: netty netty-codec-smtp — smtp command-name field is not crlf-va |
| CVE-2026-93568 | 7.5 HIGH | Io.netty/netty-codec-http2: io.netty/netty-codec-http3: netty: http/2 and http/3 extended |
| CVE-2026-81627 | 6.7 MEDIUM | Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smra |
| CVE-2026-93566 | 6.5 MEDIUM | Io.netty/netty-codec-http: netty: http request smuggling due to control characters in the |
| CVE-2026-93579 | 6.5 MEDIUM | Io.netty/netty-codec-http2: netty: http/2 header field values are not validated by default |
Showing top 20 of 37 CVEs. View all on vendor page → →
No comments yet