Skip to content
Threat Feed

Tag

Middleware

9 briefs RSS
high advisory

IBM MQ Improper Validation Vulnerability (CVE-2026-11381)

IBM MQ contains a vulnerability in the validation of message distribution list structures that allows an authenticated attacker to trigger a denial of service or potentially execute arbitrary code.

MQ vulnerability cve middleware
1c
high advisory

XML External Entity Injection in IBM MQ Classes for Java

An XML external entity injection vulnerability (CVE-2026-12666) in IBM MQ Classes for Java allows authenticated attackers to perform denial-of-service attacks or disclose sensitive host information by manipulating MQRFH2 headers.

IBM MQ +1 vulnerability java middleware cve-2026-12666 rce dos
1t 1c updated
critical advisory

CVE-2026-85440: Heap Overflow in MOOS core-moos

A pre-authentication heap overflow vulnerability in the MOOSCommPkt packet handling of MOOS core-moos versions up to 10.4.0 allows remote unauthenticated attackers to perform arbitrary memory writes via crafted packets.

core-moos cve authentication-bypass middleware denial-of-service network-vulnerability vulnerability network-security remote-access
5t 1c
critical advisory

Buffer Overflow Vulnerabilities in MOOS-IvP

Multiple buffer overflow vulnerabilities in MOOS-IvP versions up to 24.8.1 allow for remote code execution via malformed IvP function strings.

MOOS-IvP +1 vulnerability cve rce memory-corruption buffer-overflow research-robotics cve-2026-85438 remote-code-execution +4
4t 1c
high advisory

Credential Guessing Vulnerability via WildFly Elytron Unicode Normalization

A vulnerability in WildFly Elytron's password normalization logic allows attackers to bypass intended password character entropy, facilitating unauthorized access through dictionary-based credential guessing.

Red Hat build of Apache Camel 4 for Quarkus 3 +5 credential-access vulnerability middleware
1t 1c
medium advisory

IBM WebSphere Application Server Security Bypass Vulnerability

IBM WebSphere Application Server and Liberty are vulnerable to a security bypass flaw that permits remote, unauthenticated attackers to circumvent established security controls.

WebSphere Application Server +1 vulnerability websphere middleware
1t
high advisory

Next.js Middleware Authorization Bypass via Dynamic Route Parameter Injection (CVE-2026-44574)

A vulnerability in Next.js (CVE-2026-44574) allows for authorization bypass in applications that use middleware to protect dynamic routes, enabling attackers to render protected content without proper authorization by crafting specific query parameters.

next +1 nextjs middleware authorization bypass CVE-2026-44574 cloud
2r 1t
high advisory

@fastify/middie Middleware Bypass Vulnerability (CVE-2026-33804)

A middleware bypass vulnerability (CVE-2026-33804) exists in @fastify/middie versions 9.3.1 and earlier when the deprecated Fastify ignoreDuplicateSlashes option is enabled, potentially allowing unauthorized access.

fastify middie middleware bypass cve-2026-33804 defense-evasion
2r 1t 1c
critical advisory

Fastify/Express Middleware Path Doubling Authentication Bypass

A path handling bug in `@fastify/express` v4.0.4 `onRegister` function causes middleware paths to be doubled when inherited by child plugins, resulting in complete bypass of Express middleware security controls for all routes defined within child plugin scopes that share a prefix with parent-scoped middleware.

@fastify/express fastify express authentication-bypass middleware path-traversal
2r 1t