Red Hat Security Advisory: Streams for Apache Kafka 3.2.0 release and security update
🔗 CVE IDs covered (13)
📋 Description
CVE-2024-29371 — jose4j: jose4j: Denial of Service via malicious JSON Web Encryption (JWE) token compression CVE-2024-34351 — next: Next.js Server-Side Request Forgery in Server Actions CVE-2025-61726 — golang: net/url: Memory exhaustion in query parameter parsing in net/url CVE-2025-61729 — crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate CVE-2025-62718 — axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization CVE-2025-68121 — crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption CVE-2026-1002 — io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-23864 — react-server-dom-webpack: react-server-dom-parcel: reactreact-server-dom-turbopack: React Server Components: Denial of Service via specially crafted HTTP requests CVE-2026-27980 — next.js: Next.js: Unbounded next/image disk cache growth can exhaust storage CVE-2026-33870 — io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values CVE-2026-33871 — netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood CVE-2026-40175 — axios: Axios: Remote Code Execution via Prototype Pollution escalation
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2026:13571
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2418462
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2423194
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2430180
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2433059
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2434432
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2437111
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448509
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2452453
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2452456
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2453496
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2454387
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2456913
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457432
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_13571.json