{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/security-flaw/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redhat:quarkus:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-87742"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Quarkus (quarkus-websockets-next)","Quarkus"],"_cs_severities":["high"],"_cs_tags":["denial-of-service","java","application-security","web-application","security-flaw","authorization-bypass"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA vulnerability exists in the quarkus-websockets-next component of the Red Hat Quarkus framework, identified as CVE-2026-87742. This issue stems from the lack of read backpressure and the implementation of unbounded message buffering within the WebSocket handling logic. A remote, unauthenticated attacker can exploit this flaw by flooding a single WebSocket connection with high-frequency messages. Because the application fails to regulate the data ingress rate, the incoming messages accumulate in the system's memory heap. This rapid, uncontrolled allocation of memory leads to a java.lang.OutOfMemoryError, ultimately forcing the JVM to crash and resulting in a complete Denial of Service for the affected service.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the immediate unavailability of the application due to a JVM crash. This Denial of Service vulnerability impacts any service utilizing the vulnerable quarkus-websockets-next extension. Depending on the service architecture, this may lead to significant operational disruption for organizations relying on the affected Quarkus-based applications.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIdentify all applications currently utilizing the quarkus-websockets-next extension within the environment.\u003c/li\u003e\n\u003cli\u003eMonitor application logs and system resource telemetry for sudden, high-frequency WebSocket traffic volume and recurring JVM heap usage spikes.\u003c/li\u003e\n\u003cli\u003eConsult Red Hat security advisories for the specific patched version of Quarkus and prioritize applying updates to all vulnerable nodes.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-18T12:05:16Z","date_published":"2026-09-17T15:59:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-quarkus-websockets-dos/","summary":"A vulnerability in quarkus-websockets-next allows a remote attacker to cause a Denial of Service via heap exhaustion by streaming WebSocket messages faster than the application can process them.","title":"Denial of Service Vulnerability in Quarkus WebSockets Next","url":"https://feed.craftedsignal.io/briefs/2026-09-quarkus-websockets-dos/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:opennhp:opennhp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-92792"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenNHP (\u003c= 1.0.2)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","attestation","security-flaw"],"_cs_type":"advisory","_cs_vendors":["OpenNHP"],"content_html":"\u003cp\u003eOpenNHP versions up to 1.0.2 are susceptible to an authentication bypass vulnerability involving the trusted-execution attestation process. The application insecurely selects its attestation verifier based on user-supplied evidence. Specifically, by injecting a 'test_purpose' key into the evidence payload, an attacker can force the application to default to the 'FallbackVerifier' regardless of the actual attestation context. By further providing enrolled measurement values and corresponding serial numbers - which may be obtained from existing allowlists - an attacker can satisfy the conditions required by the fallback logic. This flaw allows unauthorized entities to masquerade as valid devices or services, effectively bypassing the security controls intended to verify the integrity and identity of trusted execution environments. This vulnerability presents a high risk to environments relying on OpenNHP for identity and trust verification.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the complete bypass of attestation-based authentication mechanisms within the OpenNHP framework. This grants unauthorized actors the ability to gain access to restricted network segments or services that rely on these verification checks, potentially leading to unauthorized data access, system manipulation, or further lateral movement within the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch OpenNHP to the latest version available that addresses CVE-2026-92792 immediately.\u003c/li\u003e\n\u003cli\u003eIf patching is not immediately feasible, restrict access to the attestation endpoints by implementing strict ingress filtering at the network level to limit the exposure of the management interface.\u003c/li\u003e\n\u003cli\u003eAudit application logs for anomalous attestation requests that include unusual keys such as 'test_purpose' in the payload.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-16T21:57:18Z","date_published":"2026-09-16T21:57:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-opennhp-attestation-bypass/","summary":"OpenNHP versions up to 1.0.2 contain an authentication bypass vulnerability allowing attackers to force the use of a fallback attestation verifier via malicious input.","title":"Authentication Bypass in OpenNHP via Attestation Verification Manipulation","url":"https://feed.craftedsignal.io/briefs/2026-09-opennhp-attestation-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Security-Flaw","version":"https://jsonfeed.org/version/1.1"}