CVE-2026-54513
Red Hat Security Advisory: Streams for Apache Kafka 3.2.1 release and security update
Description
A flaw was found in jackson-databind, a library used for processing data. This vulnerability allows an attacker to bypass security controls designed to validate data types. By sending specially crafted input, an attacker can force the system to process untrusted data, which may lead to the execution of malicious code. This could result in a complete compromise of the affected system, impacting its confidentiality, integrity, and availability.
Metrics
Weakness classes (CWE)
CWE-184Base
Incomplete List of Disallowed Inputs
The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-08-06 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:50846
- Reference: https://access.redhat.com/errata/RHSA-2026:50847
- Reference: https://access.redhat.com/errata/RHSA-2026:50848
- Reference: https://access.redhat.com/errata/RHSA-2026:50849
- CVE Modified2026-07-30 12:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:48095
- Reference: https://access.redhat.com/errata/RHSA-2026:48151
- CVE Modified2026-07-23 12:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:43400
- Reference: https://access.redhat.com/errata/RHSA-2026:44061
- Reference: https://access.redhat.com/errata/RHSA-2026:44062
- Reference: https://access.redhat.com/errata/RHSA-2026:44063
- CVE Modified2026-07-22 12:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:43218
- Affected: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33, Red Hat Data Grid 8.6.2, Red Hat Enterprise Linux 9 (+85) → Red Hat Build of Apache Camel 4.18 for Quarkus 3.33, Red Hat Data Grid 8.6.2, Red Hat Enterprise Linux 8 (+85)
- CVE Modified2026-07-21 12:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:41951
- Affected: Red Hat Build of Apache Camel 4.18 for Quarkus 3.33, Red Hat Enterprise Linux 9, Cryostat 4 (+85) → Red Hat Build of Apache Camel 4.18 for Quarkus 3.33, Red Hat Data Grid 8.6.2, Red Hat Enterprise Linux 9 (+85)
Affected operating systems
linux
ubuntu / nettynoble
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
apache
kafka2.8.0 – 3.9.2
apache
kafka4.0.0 – 4.0.2
apache
kafka4.1.0 – 4.1.2
Atlassian
BambooData Center LTS 10.2.22
Atlassian
BambooData Center LTS 12.1.10
Atlassian
BitbucketData Center 10.4.2
Atlassian
BitbucketData Center LTS 10.2.6
Atlassian
BitbucketData Center LTS 9.4.23
Atlassian
ConfluenceData Center LTS 10.2.15
Atlassian
ConfluenceData Center LTS 9.2.23
Atlassian
Crucible4.9.13
Atlassian
Fisheye4.9.13
Atlassian
JiraData Center LTS 10.3.24
Atlassian
JiraData Center LTS 11.3.10
bitnami
golang1.26.0-0
eclipse
vert.x4.0.0 – 4.5.29
eclipse
vert.x5.0.0 – 5.1.4
go
stdlib1.26.0-0
golang
go1.26.0 – 1.26.2
golang
go1.26.0 – 1.26.3
golang
go1.25.10
golang
go1.25.9
golang
net0.55.0
IBM
QRadar SIEM<7.5.0 UP15 IF06
References & sources
- https://github.com/netty/netty/security/advisories/GHSA-93wv-jw9v-4972web
- https://nvd.nist.gov/vuln/detail/CVE-2026-56819advisory
- https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003bweb
- https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6web
- https://github.com/netty/nettypackage
- https://github.com/netty/netty/releases/tag/netty-4.1.136.Finalweb
- https://github.com/netty/netty/releases/tag/netty-4.2.16.Finalweb
- https://github.com/vercel/next.js/security/advisories/GHSA-89xv-2m56-2m9xx_refsource_CONFIRM
- https://github.com/vercel/next.js/commit/b51206321854193208c0805ba42acc49287f942bx_refsource_MISC
- https://github.com/vercel/next.js/commit/e3e5666ccead3a15162793d697af5e48b7cc0498x_refsource_MISC
- https://github.com/vercel/next.js/releases/tag/v15.5.21x_refsource_MISC
- https://github.com/vercel/next.js/releases/tag/v16.2.11x_refsource_MISC
- https://github.com/netty/netty/security/advisories/GHSA-cc37-9q2j-3hfvweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-44893advisory
- https://github.com/netty/netty/releases/tag/netty-4.1.135.Finalweb
- https://github.com/netty/netty/releases/tag/netty-4.2.15.Finalweb
- https://access.redhat.com/security/cve/CVE-2026-44893vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2488383issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44893.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:53644vendor-advisoryx_refsource_REDHAT
Linked CVEs
- CVE-2026-69153
A flaw was found in PostCSS.
mediumCVSSv3 5.3 - CVE-2026-6860
A flaw was found in eclipse-vertx/vert.x.
medium - CVE-2026-64649
A flaw was found in Next.js, a framework for building web applications.
highCVSSv3 6.5 - CVE-2026-64648
A flaw was found in Next.js.
mediumCVSSv3 5.4 - CVE-2026-64646
A flaw was found in Next.js.
mediumCVSSv3 5.3 - CVE-2026-64645
A flaw was found in Next.js, a React framework for building web applications.
highCVSSv3 6.1 - CVE-2026-64644
A flaw was found in Next.js, a React framework.
mediumCVSSv3 5.3 - CVE-2026-64641
A flaw was found in Next.js, a React framework for building web applications.
highCVSSv3 7.5 - CVE-2026-59901
A flaw was found in the netty-codec-compression component of Netty.
highCVSSv3 7.5 - CVE-2026-59899
A flaw was found in the Netty netty-codec-http component.
highCVSSv3 7.5 - CVE-2026-59869
A flaw was found in js-yaml, a JavaScript YAML parser and dumper.
highCVSSv3 7.5 - CVE-2026-56819
A flaw was found in Netty, a network application framework.
highCVSSv3 7.5 - CVE-2026-56746
A flaw was found in Netty, a network application framework.
mediumCVSSv3 6.5 - CVE-2026-56745
A flaw was found in Netty.
highCVSSv3 7.5 - CVE-2026-55833
A flaw was found in Netty, a network application framework.
highCVSSv3 7.5 - CVE-2026-55831
A flaw was found in Netty, a network application framework.
highCVSSv3 7.5 - CVE-2026-55225
When the Strimzi cluster operator is deployed with watchAnyNamespace=true (or a multi-namespace list), any namespace editor can set Kafka…
— - CVE-2026-54512
A flaw was found in jackson-databind.
highCVSSv3 8.1 - CVE-2026-50559
A flaw was found in Quarkus.
highCVSSv3 7.5 - CVE-2026-50193
A flaw was found in jackson-databind, a general-purpose data-binding library for Jackson Data Processor.
medium - CVE-2026-49978
A flaw was found in DOMPurify, a tool designed to sanitize HTML, MathML, and SVG to prevent cross-site scripting (XSS) attacks.
mediumCVSSv3 6.1 - CVE-2026-48059
A flaw was found in the Netty HAProxy PROXY protocol v2 codec.
highCVSSv3 7.5 - CVE-2026-48043
A flaw was found in netty-codec-http2.
highCVSSv3 7.5 - CVE-2026-47691
A flaw was found in Netty's `DnsResolveContext`.
criticalCVSSv3 10.0
Show 33 more CVEs
- CVE-2026-45674
A flaw was found in Netty's DnsResolveContext.
criticalCVSSv3 10.0 - CVE-2026-45416
A flaw was found in Netty, a network application framework.
highCVSSv3 7.5 - CVE-2026-45109
A flaw was found in Next.js.
highCVSSv3 7.5 - CVE-2026-44893
A flaw was found in netty-codec-haproxy, a component of the Netty network application framework.
highCVSSv3 7.5 - CVE-2026-44579
A flaw was found in Next.js.
highCVSSv3 7.5 - CVE-2026-44578
A flaw was found in Next.js.
highCVSSv3 8.6 - CVE-2026-44577
A flaw was found in Next.js.
mediumCVSSv3 5.9 - CVE-2026-44575
A flaw was found in Next.js.
highCVSSv3 7.5 - CVE-2026-44574
A flaw was found in Next.js.
highCVSSv3 8.1 - CVE-2026-44573
A flaw was found in Next.js.
highCVSSv3 7.5 - CVE-2026-44249
A flaw was found in netty-handler, a component of the Netty network application framework.
highCVSSv3 8.1 - CVE-2026-42587
A flaw was found in Netty.
highCVSSv3 7.5 - CVE-2026-42584
A flaw was found in Netty, an asynchronous, event-driven network application framework.
criticalCVSSv3 9.1 - CVE-2026-42583
A flaw was found in Netty, an asynchronous, event-driven network application framework.
highCVSSv3 7.5 - CVE-2026-42581
A flaw was found in Netty's HttpObjectDecoder.
criticalCVSSv3 9.8 - CVE-2026-42579
A flaw was found in Netty.
criticalCVSSv3 9.1 - CVE-2026-42578
A flaw was found in Netty.
highCVSSv3 7.5 - CVE-2026-42504
A flaw was found in the Golang MIME (Multipurpose Internet Mail Extensions) package.
highCVSSv3 7.5 - CVE-2026-40984
A flaw was found in Micrometer.
highCVSSv3 7.5 - CVE-2026-40983
A flaw was found in Micrometer.
highCVSSv3 7.5 - CVE-2026-39852
A flaw was found in io.quarkus:quarkus-vertx-http.
highCVSSv3 8.2 - CVE-2026-39821
A flaw was found in golang.org/x/net/idna.
criticalCVSSv3 9.6 - CVE-2026-35554
A flaw was found in the Apache Kafka Java producer client.
highCVSSv3 8.7 - CVE-2026-34481
A flaw was found in Apache Log4j's JsonTemplateLayout.
highCVSSv3 7.5 - CVE-2026-34480
A flaw was found in Apache Log4j Core.
medium - CVE-2026-34478
A flaw was found in Apache Log4j Core.
medium - CVE-2026-33811
A flaw was found in the `net` package of Go (golang), specifically when using the `LookupCNAME` function with the `cgo` DNS resolver.
highCVSSv3 7.5 - CVE-2026-32283
A flaw was found in the `crypto/tls` package within the Go (golang) standard library, specifically affecting TLS 1.3 connections.
highCVSSv3 7.5 - CVE-2026-27145
A flaw was found in the `crypto/x509` package of `golang`.
mediumCVSSv3 6.5 - CVE-2026-16308
A flaw was found in Quarkus REST.
highCVSSv3 7.5 - CVE-2026-15076
A flaw was found in Eclipse Vert.x Web Client.
highCVSSv3 7.5 - CVE-2026-15075
A flaw was found in Eclipse Vert.x.
highCVSSv3 7.5 - CVE-2026-10051
A flaw was found in Eclipse Jetty.
highCVSSv3 7.5