CVE-2026-4867
Red Hat Security Advisory: Cluster Observability Operator 1.5.0
Description
A flaw was found in path-to-regexp. A remote attacker could exploit this vulnerability by crafting a malicious URL with three or more parameters in a single segment, separated by non-period characters. This causes the component to generate a bad regular expression, leading to catastrophic backtracking. The overlapping capture groups can consume excessive processing resources, resulting in a Denial of Service (DoS) for the affected application.
Metrics
Weakness classes (CWE)
CWE-1333Base
Inefficient Regular Expression Complexity
The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.
cwe.mitre.org →
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
Atlassian
BambooData Center LTS 10.2.22
Atlassian
BambooData Center LTS 12.1.10
Atlassian
BitbucketData Center 10.4.2
Atlassian
BitbucketData Center LTS 10.2.6
Atlassian
BitbucketData Center LTS 9.4.23
Atlassian
ConfluenceData Center LTS 10.2.15
Atlassian
ConfluenceData Center LTS 9.2.23
Atlassian
Crucible4.9.13
Atlassian
Fisheye4.9.13
Atlassian
JiraData Center LTS 10.3.24
Atlassian
JiraData Center LTS 11.3.10
digitalbazaar
forge1.3.3
digitalbazaar
forge1.4.0
go
golang.org/x/net
go
golang.org/x/oauth2
go
stdlib1.24.0-0
golang
go1.26.0 – 1.26.3
golang
go1.25.10
golang
http20.53.0
golang
net0.55.0
handlebarsjs
handlebars4.0.0 – 4.7.9
immutable-js
immutable3.0.0 – 3.8.3
immutable-js
immutable4.0.0 – 4.3.7
immutable-js
immutable5.0.0 – 5.1.5
References & sources
- https://github.com/digitalbazaar/forge/security/advisories/GHSA-cfm4-qjh2-4765web
- https://github.com/digitalbazaar/forge/security/advisories/GHSA-ppp5-5v6c-4jwpweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-33894advisory
- https://datatracker.ietf.org/doc/html/rfc2313#section-8web
- https://github.com/digitalbazaar/forgepackage
- https://mailarchive.ietf.org/arch/msg/openpgp/5rnE9ZRN1AokBVj3VqblGlP63QEweb
- https://www.rfc-editor.org/rfc/rfc8017.htmlweb
- https://access.redhat.com/security/cve/CVE-2026-33894vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2452464issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33894.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:24761vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:34342vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:9742vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:13826vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:22629vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:21017vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:24853vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:19375vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:22465vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:22840vendor-advisoryx_refsource_REDHAT
Linked CVEs
- CVE-2026-9697
A flaw was found in undici.
highCVSSv3 7.4 - CVE-2026-9277
A flaw was found in the shell-quote component.
criticalCVSSv3 8.1 - CVE-2026-6734
A flaw was found in undici.
highCVSSv3 8.8 - CVE-2026-6322
A flaw was found in fast-uri.
highCVSSv3 7.5 - CVE-2026-6321
A flaw was found in fast-uri.
highCVSSv3 7.5 - CVE-2026-48779
A flaw was found in ws, an open source WebSocket client and server.
highCVSSv3 7.5 - CVE-2026-4800
A flaw was found in lodash.
criticalCVSSv3 9.8 - CVE-2026-42506
A flaw was found in golang.org/x/net/html.
mediumCVSSv3 6.1 - CVE-2026-39821
A flaw was found in golang.org/x/net/idna.
criticalCVSSv3 9.6 - CVE-2026-33941
A flaw was found in Handlebars.
highCVSSv3 8.3 - CVE-2026-33940
A flaw was found in Handlebars.js.
highCVSSv3 8.1 - CVE-2026-33939
A flaw was found in Handlebars.js.
highCVSSv3 7.5 - CVE-2026-33938
A flaw was found in Handlebars.
highCVSSv3 8.1 - CVE-2026-33937
A flaw was found in Handlebars.
criticalCVSSv3 9.8 - CVE-2026-33896
A flaw was found in Forge (also known as node-forge), a JavaScript implementation of Transport Layer Security (TLS).
criticalCVSSv3 9.1 - CVE-2026-33895
A flaw was found in Forge (also called `node-forge`), a JavaScript library used for Transport Layer Security (TLS).
highCVSSv3 7.5 - CVE-2026-33894
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript.
highCVSSv3 7.5 - CVE-2026-33891
A flaw was found in the node-forge library, a JavaScript implementation of Transport Layer Security.
highCVSSv3 7.5 - CVE-2026-33814
A flaw was found in the HTTP/2 protocol implementation within the Go standard library (golang.org/x/net and net/http/internal/http2).
highCVSSv3 7.5 - CVE-2026-33671
A flaw was found in Picomatch, a JavaScript glob matcher.
highCVSSv3 7.5 - CVE-2026-33228
A flaw was found in flatted, a JavaScript Object Notation (JSON) parser designed for handling circular data structures.
criticalCVSSv3 9.8 - CVE-2026-32141
A denial of service flaw has been discovered in the flatted npm library.
highCVSSv3 7.5 - CVE-2026-29063
A flaw was found in Immutable.js, a library for persistent immutable data structures.
criticalCVSSv3 9.8 - CVE-2026-25681
A flaw was found in golang.org/x/net/html.
mediumCVSSv3 6.1
Show 16 more CVEs
- CVE-2026-25680
A flaw was found in golang.org/x/net/html.
mediumCVSSv3 6.5 - CVE-2026-2229
A flaw was found in the undici WebSocket client.
highCVSSv3 7.5 - CVE-2026-1528
A flaw was found in undici.
highCVSSv3 7.5 - CVE-2026-1526
A flaw was found in undici.
highCVSSv3 7.5 - CVE-2026-12151
A flaw was found in undici.
highCVSSv3 7.5 - CVE-2026-12143
A flaw was found in form-data, a library for creating readable multipart/form-data streams.
highCVSSv3 7.5 - CVE-2025-58190
The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of…
— - CVE-2025-47911
The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denia…
— - CVE-2025-22872
A flaw was found in the HTML tokenizer component.
— - CVE-2025-22870
A flaw was found in proxy host matching.
— - CVE-2025-22868
A flaw was found in the `golang.org/x/oauth2/jws` package in the token parsing component.
— - CVE-2024-52011
A flaw was found in launch-editor, a tool that allows users to open files with line numbers in an editor from Node.js.
highCVSSv3 8.3 - CVE-2024-45338
A flaw was found in golang.org/x/net/html.
— - CVE-2024-4068
A flaw was found in the NPM package `braces.` It fails to limit the number of characters it can handle, which could lead to memory exhaus…
highCVSSv3 7.5 - CVE-2021-33623
A flaw was found in nodejs-trim-newlines.
— - CVE-2020-7753
A flaw was found in the npm library trim where a specifically crafted input can cause a regular expression to take an abnormal amount of…
highCVSSv3 7.5