Red Hat Security Advisory: Red Hat Data Grid 8.6.1 security update
🔗 CVE IDs covered (12)
📋 Description
CVE-2026-4800 — lodash: lodash: Arbitrary code execution via untrusted input in template imports CVE-2026-33870 — io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values CVE-2026-33871 — netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood CVE-2026-34478 — org.apache.logging.log4j/log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames CVE-2026-34480 — org.apache.logging.log4j/log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging CVE-2026-34481 — org.apache.logging.log4j: Apache Log4j JsonTemplateLayout: Denial of Service via invalid JSON output CVE-2026-40975 — Spring Boot: Spring Boot: Weak pseudo-random number generation can lead to information disclosure. CVE-2026-41240 — DOMPurify: DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization CVE-2026-42033 — axios: Axios: HTTP Transport Hijacking via Prototype Pollution CVE-2026-42039 — axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data CVE-2026-42041 — axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling CVE-2026-42043 — axios: Axios: NO_PROXY bypass via crafted URL
🎯 Affected products1
- Red Hat Data Grid 8.6.1
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Applications utilizing Spring Boot should avoid using the `${random.value}` property for generating cryptographic secrets or other security-sensitive data. Developers should review their application configurations and code to ensure that only cryptographically strong random number generators are used for such purposes. For UUID generation, `${random.uuid}` is not affected and can be used. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2026:22619
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_data_grid/8.6
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2452453
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2452456
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2453496
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457321
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457323
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457328
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2461147
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2461607
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2461626
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2461629
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2461630
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2463331
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_22619.json