A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enorm
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Red Hat | - | 0 ~ 6.2.19.Final | - |
|
| Red Hat | Red Hat build of Apache Camel 4 for Quarkus 3 | - |
cpe:/a:redhat:camel_quarkus:3
|
|
| Red Hat | Red Hat build of Apicurio Registry 3 | - |
cpe:/a:redhat:apicurio_registry:3
|
|
| Red Hat | Red Hat build of Debezium 3 | - |
cpe:/a:redhat:debezium:3
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat Build of Keycloak | - |
cpe:/a:redhat:build_keycloak:
|
|
| Red Hat | Red Hat build of Quarkus | - |
cpe:/a:redhat:quarkus:3
|
|
| Red Hat | Red Hat Certificate System 10 | - |
cpe:/a:redhat:certificate_system:10
|
|
| Red Hat | Red Hat Certificate System 11 | - |
cpe:/a:redhat:certificate_system:11
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Fuse 7 | - |
cpe:/a:redhat:jboss_fuse:7
|
|
| Red Hat | Red Hat Fuse 7 | - |
cpe:/a:redhat:jboss_fuse:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:7
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | - |
cpe:/a:redhat:jboss_enterprise_application_platform:8
|
|
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | - |
cpe:/a:redhat:jbosseapxp
|
|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| Red Hat | Red Hat Single Sign-On 7 | - |
cpe:/a:redhat:red_hat_single_sign_on:7
|
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-93569 | 8.2 HIGH | Netty http2 代理主机头覆盖漏洞 |
| CVE-2026-93563 | 7.5 HIGH | Netty-codec-smtp SMTP解码器内存耗尽DoS |
| CVE-2026-93564 | 7.5 HIGH | Netty haproxy模块嵌套TLV引用计数泄漏 |
| CVE-2026-93558 | 7.5 HIGH | Netty WebSocket扩展处理器未界队列拒绝服务 |
| CVE-2026-93565 | 7.5 HIGH | Netty RTSP解码器方法令牌走私漏洞 |
| CVE-2026-93560 | 7.5 HIGH | Netty STOMP编解码器无限循环拒绝服务漏洞 |
| CVE-2026-93491 | 7.5 HIGH | Netty HTTPServerCodec 拒绝服务漏洞 |
| CVE-2026-93488 | 7.5 HIGH | Netty 远程拒绝服务漏洞 |
| CVE-2026-93567 | 7.5 HIGH | Netty HTTP2 authority 连接转换缺陷 |
| CVE-2026-93576 | 7.5 HIGH | Netty SMTP命令名CRLF校验不完整漏洞 |
| CVE-2026-93568 | 7.5 HIGH | Netty HTTP/2与HTTP/3 CONNECT请求降级漏洞 |
| CVE-2026-93572 | 7.5 HIGH | Netty redisarrayaggregator 预分配限制漏洞 |
| CVE-2026-93575 | 7.5 HIGH | Netty MQTT解码器资源耗尽漏洞 |
| CVE-2026-87743 | 7.5 HIGH | Quarkus vertx-http 路径规范化授权绕过漏洞 |
| CVE-2026-91149 | 7.5 HIGH | Cockpit: cockpit: denial of service via unbounded connection thread spawning |
| CVE-2026-93494 | 7.5 HIGH | Netty Stomp子帧解码器字节缓冲区泄漏漏洞 |
| CVE-2026-89058 | 7.4 HIGH | Resteasy CORSFilter 任意源凭据反射漏洞 |
| CVE-2026-81627 | 6.7 MEDIUM | Qemu-kvm 远程代码执行漏洞 |
| CVE-2026-93566 | 6.5 MEDIUM | Netty Http 请求走私漏洞 |
| CVE-2026-93573 | 6.5 MEDIUM | Netty 分块传输编码绕过致请求走私漏洞 |
显示前 20 条,共 33 条。 查看全部 → →
暂无评论