VendorsRed Hatdata_grid8.0
Vulnerabilities

Red Hat Data Grid 8.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2025-12543
Undertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrf
Published 2026-01-07 · Modified
9.6EPSS 0.014
CVE-2026-28367
Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator
Published 2026-03-27 · Modified
9.1EPSS 0.009
CVE-2026-28368
Undertow: undertow: request smuggling via inconsistent header parsing
Published 2026-03-27 · Modified
9.1EPSS 0.009
CVE-2026-28369
Undertow: undertow: request smuggling via malformed http request headers
Published 2026-03-27 · Modified
9.1EPSS 0.009
CVE-2025-23368
Org.wildfly.core:wildfly-elytron-integration: wildfly elytron brute force attack via cli
Published 2025-03-04 · Modified
8.1EPSS 0.009
CVE-2026-15573
Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher
Published 2026-08-05 · Modified
8.1EPSS 0.005
CVE-2026-16102
Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers
Published 2026-08-05 · Modified
8.1EPSS 0.005
CVE-2020-25644
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
Published 2020-10-06 · Modified
7.5EPSS 0.024
CVE-2020-10771
A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) attack.
Published 2021-06-02 · Modified
7.1EPSS 0.004
CVE-2020-25711
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When authz is enabled, any user with authentication can perform operations like shutting down the server without the ADMIN role.
Published 2020-12-03 · Modified
6.5EPSS 0.011
CVE-2026-16093
Keycloak-services: keycloak-services: required signed-jwt assertion policy can be bypassed with unsigned assertion headers
Published 2026-07-17 · Modified
5.4EPSS 0.004
CVE-2021-3642
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
Published 2021-08-05 · Modified
5.3EPSS 0.008
CVE-2021-3536
A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.
Published 2021-05-20 · Modified
4.8EPSS 0.005
CVE-2026-15945
Keycloak-services: keycloak-services: group hierarchy search discloses hidden parent groups under fgap v2
Published 2026-07-16 · Modified
4.3EPSS 0.003