Common Vulnerabilities and Exposures (CVE)

CVE-2026-93573

Sep 22, 2026 22:26:40 UTC

A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a n...

CVE-2026-18176

Sep 22, 2026 22:21:06 UTC

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

CVE-2026-18173

Sep 22, 2026 22:20:21 UTC

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication.

CVE-2026-18172

Sep 22, 2026 22:16:27 UTC

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references.

CVE-2026-18169

Sep 22, 2026 22:13:39 UTC

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.

CVE-2026-93558

Sep 22, 2026 22:13:19 UTC

A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. This leads to an unbounded...

CVE-2026-18170

Sep 22, 2026 22:13:08 UTC

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without limits or throttling.

CVE-2026-93488

Sep 22, 2026 22:13:08 UTC

A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote peer can op...

CVE-2026-18163

Sep 22, 2026 22:11:59 UTC

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.

CVE-2026-18162

Sep 22, 2026 22:10:47 UTC

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.

CVE-2026-18161

Sep 22, 2026 22:10:20 UTC

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to falsify transaction audit logs due to improper validation of a client-supplied HTTP header.

CVE-2026-18156

Sep 22, 2026 22:09:15 UTC

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper authorization.

CVE-2026-18154

Sep 22, 2026 22:07:40 UTC

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or predictable cryptographic key.

CVE-2026-18153

Sep 22, 2026 22:07:12 UTC

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and initialization vector...

CVE-2026-18152

Sep 22, 2026 22:06:11 UTC

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-signed messages due to improper verification of cryptographic signatures.