Data grid
This hub aggregates every CVE we track for Data grid, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
35
CVEs tracked
5
Critical
16
High
3
In CISA KEV
Severity distribution
HIGH16MEDIUM13CRITICAL5LOW1
Monthly trend
0
1
0
0
0
0
0
0
1
0
1
1
0
0
0
0
0
0
0
1
4
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Data grid.
- CVE-2026-28369Undertow: undertow: request smuggling via malformed http request headers8.7
- CVE-2026-28367Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator8.7
- CVE-2026-28368Undertow: undertow: request smuggling via inconsistent header parsing8.7
- CVE-2026-3260Undertow: undertow: denial of service due to premature multipart/form-data parsing in get requests5.9
- CVE-2026-27903minimatch has a ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments7.5
- CVE-2025-5731Infinispan: credential leakage in infinispan cli5.5
- CVE-2025-48734Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default8.8
- CVE-2025-23368Org.wildfly.core:wildfly-elytron-integration: wildfly elytron brute force attack via cli8.1
- CVE-2024-7885Undertow: improper state management in proxy protocol parsing causes information leakage7.5
- CVE-2023-6717Keycloak: xss via assertion consumer service url in saml post-binding flow6.0
- CVE-2023-5384Infinispan: credentials returned from configuration as clear text7.2
- CVE-2023-5236Infinispan: circular reference on marshalling leads to dos4.4
- CVE-2023-3629Infinispan: non-admins should not be able to get cache config via rest api4.3
- CVE-2023-3628Infispan: rest bulk ops don't check permissions6.5
- CVE-2023-4586Hotrod-client: hot rod client does not enable hostname validation when using tls that lead to a mitm attack7.4
Product normalization is registry-driven with AI assist and human review. How it works