- Issued:
- 2026-07-20
- Updated:
- 2026-07-20
RHSA-2026:41951 - Security Advisory
Synopsis
Important: Red Hat Data Grid 8.6.2 security update
Type/Severity
Security Advisory: Important
Topic
An update for Red Hat Data Grid 8 is now available.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
Red Hat Data Grid is an in-memory, distributed, NoSQL datastore solution. It increases application response times and allows for dramatically improving performance while providing availability, reliability, and elastic scale.
Data Grid 8.6.2 replaces Data Grid 8.6.1 and includes bug fixes and enhancements. Find out more about Data Grid 8.6.2 in the Release Notes[3].
Security Fix(es):
- CVE-2026-54513 jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution [jdg-8.6] (CVE-2026-54513)
- CVE-2026-42211 react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode [jdg-8.6] (CVE-2026-42211)
- CVE-2026-42264 axios: Axios: Prototype pollution allows information disclosure and request manipulation [jdg-8.6] (CVE-2026-42264)
- CVE-2026-50193 jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing [jdg-8.6] (CVE-2026-50193)
- CVE-2026-54512 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass [jdg-8.6] (CVE-2026-54512)
- CVE-2026-40983 micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests [jdg-8.6] (CVE-2026-40983)
- CVE-2026-40984 micrometer-core: Micrometer: Denial of Service via specially crafted HTTP requests [jdg-8.6] (CVE-2026-40984)
- CVE-2026-12143 form-data: form-data: Form field override via CRLF injection [jdg-8.6] (CVE-2026-12143)
- CVE-2026-9595 webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration [jdg-8.6] (CVE-2026-9595)
- CVE-2026-50011 netty-codec-redis: Netty: Denial of Service via malicious Redis array header [jdg-8.6] (CVE-2026-50011)
- CVE-2026-45416 netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake [jdg-8.6] (CVE-2026-45416)
- CVE-2026-44890 netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads [jdg-8.6] (CVE-2026-44890)
- CVE-2026-44250 netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays [jdg-8.6] (CVE-2026-44250)
- CVE-2026-46340 netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments [jdg-8.6] (CVE-2026-46340)
- CVE-2026-45674 netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation [jdg-8.6] (CVE-2026-45674)
- CVE-2026-50010 netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass [jdg-8.6] (CVE-2026-50010)
- CVE-2026-48006 netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator [jdg-8.6] (CVE-2026-48006)
- CVE-2026-47691 netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records [jdg-8.6] (CVE-2026-47691)
- CVE-2026-48059 netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers [jdg-8.6] (CVE-2026-48059)
- CVE-2026-48043 netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak [jdg-8.6] (CVE-2026-48043)
- CVE-2026-44893 netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message [jdg-8.6] (CVE-2026-44893)
- CVE-2026-44249 netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation [jdg-8.6] (CVE-2026-44249)
- CVE-2026-44492 axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization [jdg-8.6] (CVE-2026-44492)
- CVE-2026-44494 axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution [jdg-8.6] (CVE-2026-44494)
- CVE-2026-44496 axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name [jdg-8.6] (CVE-2026-44496)
- CVE-2026-44486 axios: Axios: Information disclosure of proxy credentials via HTTP redirects [jdg-8.6] (CVE-2026-44486)
- CVE-2026-44487 axios: Axios: Information disclosure of proxy credentials via redirect flows [jdg-8.6] (CVE-2026-44487)
- CVE-2026-44488 axios: Axios: Denial of Service due to unenforced request and response size limits [jdg-8.6] (CVE-2026-44488)
- CVE-2026-44495 axios: Axios: Information disclosure due to prototype pollution vulnerability [jdg-8.6] (CVE-2026-44495)
- CVE-2026-6322 fast-uri: fast-uri: URI authority bypass due to improper delimiter handling [jdg-8.6] (CVE-2026-6322)
- CVE-2026-45292 opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage [jdg-8.6] (CVE-2026-45292)
- CVE-2026-42583 netty-codec-compression: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder [jdg-8.6] (CVE-2026-42583)
- CVE-2026-44248 netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header [jdg-8.6] (CVE-2026-44248)
- CVE-2026-42587 netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression [jdg-8.6] (CVE-2026-42587)
- CVE-2026-42586 netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder [jdg-8.6] (CVE-2026-42586)
- CVE-2026-42342 react-router: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint [jdg-8.6] (CVE-2026-42342)
- CVE-2026-33245 react-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirects [jdg-8.6] (CVE-2026-33245)
- CVE-2026-34077 react-router: React Router: Denial of Service via client-side Cross-Site Scripting in RSC redirect handling [jdg-8.6] (CVE-2026-34077)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
Affected Products
- Red Hat JBoss Data Grid Text-Only Advisories x86_64
Fixes
- BZ - 2466684 - CVE-2026-6322 fast-uri: fast-uri: URI authority bypass due to improper delimiter handling
- BZ - 2467927 - CVE-2026-42264 axios: Axios: Prototype pollution allows information disclosure and request manipulation
- BZ - 2477213 - CVE-2026-42586 netty-codec-redis: Netty: Command injection via CRLF characters in Redis codec encoder
- BZ - 2477219 - CVE-2026-42583 netty: io.netty/netty-codec-compression: io.netty/netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder
- BZ - 2477220 - CVE-2026-42587 netty: io.netty/netty-codec-http: io.netty/netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression
- BZ - 2477231 - CVE-2026-44248 netty: io.netty/netty-codec-mqtt: Netty: Denial of Service due to excessive resource consumption from crafted MQTT 5 header
- BZ - 2482785 - CVE-2026-45292 opentelemetry-java: opentelemetry-api: opentelemetry-extension-trace-propagators: OpenTelemetry Java: Denial of Service due to unbounded memory allocation when parsing oversized baggage
- BZ - 2484115 - CVE-2026-42211 react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode
- BZ - 2484116 - CVE-2026-42342 react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint
- BZ - 2484123 - CVE-2026-34077 react-router: React Router: Denial of Service via client-side Cross-Site Scripting in RSC redirect handling
- BZ - 2484124 - CVE-2026-33245 react-router: React Router: Cross-Site Scripting vulnerability via untrusted React Server Component redirects
- BZ - 2486697 - CVE-2026-40983 micrometer: micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests
- BZ - 2486716 - CVE-2026-40984 micrometer-core: micrometer-jetty11: micrometer-jetty12: Micrometer: Denial of Service via specially crafted HTTP requests
- BZ - 2487937 - CVE-2026-44495 axios: Axios: Information disclosure due to prototype pollution vulnerability
- BZ - 2487938 - CVE-2026-44492 axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization
- BZ - 2487942 - CVE-2026-44494 axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution
- BZ - 2487943 - CVE-2026-44496 axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name
- BZ - 2487947 - CVE-2026-44486 axios: Axios: Information disclosure of proxy credentials via HTTP redirects
- BZ - 2487948 - CVE-2026-44487 axios: Axios: Information disclosure of proxy credentials via redirect flows
- BZ - 2487949 - CVE-2026-44488 axios: Axios: Denial of Service due to unenforced request and response size limits
- BZ - 2488053 - CVE-2026-44890 netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payloads
- BZ - 2488062 - CVE-2026-44250 netty-codec-redis: netty-codec-redis: Denial of Service via crafted Redis payload with deeply nested arrays
- BZ - 2488081 - CVE-2026-44249 netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation
- BZ - 2488383 - CVE-2026-44893 netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message
- BZ - 2488388 - CVE-2026-46340 netty-transport-sctp: Netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments
- BZ - 2488391 - CVE-2026-45416 netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake
- BZ - 2488400 - CVE-2026-45674 netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation
- BZ - 2488413 - CVE-2026-50011 netty-codec-redis: Netty: Denial of Service via malicious Redis array header
- BZ - 2488429 - CVE-2026-50010 netty-handler: Netty: Improper trust manager handling leads to hostname verification bypass
- BZ - 2488433 - CVE-2026-48006 netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
- BZ - 2488437 - CVE-2026-48059 netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers
- BZ - 2488439 - CVE-2026-47691 io.netty/netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records
- BZ - 2488442 - CVE-2026-48043 netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak
- BZ - 2488480 - CVE-2026-12143 form-data: form-data: Form field override via CRLF injection
- BZ - 2488934 - CVE-2026-9595 webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration
- BZ - 2491999 - CVE-2026-50193 jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing
- BZ - 2492010 - CVE-2026-54513 jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution
- BZ - 2492015 - CVE-2026-54512 jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass
CVEs
- CVE-2026-6322
- CVE-2026-9595
- CVE-2026-12143
- CVE-2026-33245
- CVE-2026-34077
- CVE-2026-40983
- CVE-2026-40984
- CVE-2026-42211
- CVE-2026-42264
- CVE-2026-42342
- CVE-2026-42583
- CVE-2026-42586
- CVE-2026-42587
- CVE-2026-44248
- CVE-2026-44249
- CVE-2026-44250
- CVE-2026-44486
- CVE-2026-44487
- CVE-2026-44488
- CVE-2026-44492
- CVE-2026-44494
- CVE-2026-44495
- CVE-2026-44496
- CVE-2026-44890
- CVE-2026-44893
- CVE-2026-45292
- CVE-2026-45416
- CVE-2026-45674
- CVE-2026-46340
- CVE-2026-47691
- CVE-2026-48006
- CVE-2026-48043
- CVE-2026-48059
- CVE-2026-50010
- CVE-2026-50011
- CVE-2026-50193
- CVE-2026-54512
- CVE-2026-54513
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.