Migration Toolkit for Applications
The Migration Toolkit for Applications (MTA) is an assembly of tools that support large-scale Java application modernization and migration projects across a broad range of transformations and use cases.
Browse the latest documentation
Release NotesWhat's New
Configuring and using rules for an MTA analysisRules Development
Latest security advisories
| Severity | Advisory/CVE | Synopsis | Date |
|---|---|---|---|
| Severity Important | Advisory/CVECVE-2026-73620 | Synopsis A flaw was found in GitPython. This vulnerability arises from insufficient guarding of git option forwarding within the `IndexFile.checkout()` and `TagReference.create()` functions. An authenticated attacker can exploit this by passing unsafe options through keyword arguments, leading to the ability to overwrite arbitrary files with repository content or read sensitive files. This could result in significant data integrity and confidentiality impacts. | Date |
| Severity Important | Advisory/CVECVE-2026-71235 | Synopsis A flaw was found in Magistrala's Rules Engine. An authenticated low-privileged user can exploit this vulnerability by creating rules with embedded Go or Lua scripts. These scripts are executed server-side without sufficient validation, allowing for arbitrary file read and write operations, access to internal databases, and Server-Side Request Forgery (SSRF) against internal microservices. This could lead to significant data compromise and unauthorized system access. | Date |
| Severity Important | Advisory/CVE(RHSA-2026:50300) Migration Toolkit for Applications | Synopsis Migration Toolkit for Applications | Date |
| Severity Important | Advisory/CVECVE-2026-67324 | Synopsis A flaw was found in GitPython. A remote attacker can exploit a vulnerability where the software fails to properly recognize joined short-option forms (e.g., -u<value>) when enforcing its default unsafe-option gate. This allows the attacker to bypass security checks and execute arbitrary commands during a Git clone operation. This can lead to a complete compromise of the affected system. | Date |
| Severity Critical | Advisory/CVE(RHSA-2026:43038) Migration Toolkit for Applications | Synopsis Migration Toolkit for Applications | Date |
Top resources
Lifecycle
View the various levels of maintenance for each release of a product over a period from initial release to the end of maintenance.
Troubleshooting
Connect to the right information to self-solve issues quickly and efficiently.
Go to Toolkit
This toolkit is included with a Red Hat OpenShift subscription.
Documentation
Find more technical content about how to use your products or services.
Get support
Support cases
Get answers quickly by opening a support case with us.
Live chat
Directly access our support engineers during weekday business hours.
Call or email
Speak directly with a Red Hat Support expert by phone or through email.