在 Redis 社区版中,集群总线的 PING/PONG/MEET 数据包解析器虽然验证了扩展字段的填充和总长度,但并未检查携带字符串的扩展字段是否正确以空字符(null)结尾。这可能导致攻击者构造特定的数据包,在后续以 C 字符串形式消费负载时触发越界读取。该漏洞可能导致信息泄露或远程拒绝服务(DoS)。Redis 商业版(Redis Software / Redis Enterprise)不受此问题影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Confidential Compute Attestation | - |
cpe:/a:redhat:confidential_compute_attestation:1
|
|
| Red Hat | Logging Subsystem for Red Hat OpenShift | - |
cpe:/a:redhat:logging:6
|
|
| Red Hat | Pen Drive Powered by Red Hat Lightspeed | - |
cpe:/a:redhat:pdrive_lightspeed:1
|
|
| Red Hat | Red Hat 3scale API Management Platform 2 | - |
cpe:/a:redhat:red_hat_3scale_amp:2
|
|
| Red Hat | Red Hat 3scale API Management Platform 2 | - |
cpe:/a:redhat:red_hat_3scale_amp:2
|
|
| Red Hat | Red Hat 3scale API Management Platform 2 | - |
cpe:/a:redhat:red_hat_3scale_amp:2
|
|
| Red Hat | Red Hat AI Inference Server | - |
cpe:/a:redhat:ai_inference_server:3
|
|
| Red Hat | Red Hat AI Inference Server | - |
cpe:/a:redhat:ai_inference_server:3
|
|
| Red Hat | Red Hat AI Inference Server | - |
cpe:/a:redhat:ai_inference_server:3
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Ansible Automation Platform 2 | - |
cpe:/a:redhat:ansible_automation_platform:2
|
|
| Red Hat | Red Hat Connectivity Link 1 | - |
cpe:/a:redhat:connectivity_link:1
|
|
| Red Hat | Red Hat Developer Hub | - |
cpe:/a:redhat:rhdh:1
|
|
| Red Hat | Red Hat Developer Hub | - |
cpe:/a:redhat:rhdh:1
|
|
| Red Hat | Red Hat Developer Hub | - |
cpe:/a:redhat:rhdh:1
|
|
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | - |
cpe:/a:redhat:enterprise_linux_ai:3
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86320 | 7.8 HIGH | Flatpak-builder: host code execution via `git am` hook execution in patch source extractio |
| CVE-2026-87742 | 7.5 HIGH | Quarkus-websockets-next: denial of service (oom) in quarkus-websockets-next via unbounded |
| CVE-2026-76781 | 5.5 MEDIUM | Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute |
| CVE-2026-81829 | 5.3 MEDIUM | Smallrye-jwt: quarkus-smallrye-jwt: smallrye-jwt: unauthenticated same-origin ssrf via uns |
| CVE-2026-92904 | 4.3 MEDIUM | Rubygem-foreman_remote_execution: job output readable without object-level view_job_invoca |
| CVE-2026-92893 | 4.3 MEDIUM | Rubygem-foreman_ansible: ansible inventory api ignores view_hosts permission filters, expo |
| CVE-2026-92894 | 4.3 MEDIUM | Rubygem-foreman_ansible: unscoped lookupvalue deletion allows cross-model override value d |
No comments yet