CVE-2026-4867

Red Hat Security Advisory: Cluster Observability Operator 1.5.0

Description

A flaw was found in path-to-regexp. A remote attacker could exploit this vulnerability by crafting a malicious URL with three or more parameters in a single segment, separated by non-period characters. This causes the component to generate a bad regular expression, leading to catastrophic backtracking. The overlapping capture groups can consume excessive processing resources, resulting in a Denial of Service (DoS) for the affected application.

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
41.0 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.5 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-01 14:36 UTC
CWE-1333

Weakness classes (CWE)

  • CWE-1333Base

    Inefficient Regular Expression Complexity

    The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

    cwe.mitre.org →

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • digitalbazaar

    forge1.3.3

  • digitalbazaar

    forge1.4.0

  • go

    golang.org/x/net

  • go

    golang.org/x/oauth2

  • go

    stdlib1.24.0-0

  • golang

    go1.26.0 – 1.26.3

  • golang

    go1.25.10

  • golang

    http20.53.0

  • golang

    net0.55.0

  • handlebarsjs

    handlebars4.0.0 – 4.7.9

  • immutable-js

    immutable3.0.0 – 3.8.3

  • immutable-js

    immutable4.0.0 – 4.3.7

  • immutable-js

    immutable5.0.0 – 5.1.5

References & sources

Linked CVEs

Show 16 more CVEs
IDCVE-2026-4867