Red Hat Data Grid
Red Hat Data Grid is an in-memory, distributed, elastic NoSQL key-value datastore. Built from the Infinispan open-source software project, it's available to deploy as an embedded library, as a standalone server, or as a containerized application on Red Hat OpenShift Container Platform.
browse_doc
Red Hat Data Grid 8.6 Release NotesRelease Information
Data Grid Operator GuideData Grid Operator
Building and deploying Data Grid clusters with HelmData Grid Helm Chart
Data Grid Server GuideData Grid Server
Hot Rod Java Client GuideHot Rod Clients
Data Grid Performance and Sizing GuideDeployment Planning
Upgrading Data GridUpgrading
latest_security
| severity | advisory_cve | synopsis | date |
|---|---|---|---|
| severity Important | advisory_cveCVE-2026-73643 | synopsis A flaw was found in js-yaml, a JavaScript YAML parser. A remote attacker could exploit this vulnerability by providing specially crafted YAML input containing nested flow collections. This can lead to exponential parsing time when the application processes untrusted input, consuming excessive CPU resources. This resource exhaustion can block the Node.js event loop and cause a Denial of Service (DoS) for the affected process. | date |
| severity Important | advisory_cveCVE-2026-45819 | synopsis A flaw was found in baseline-browser-mapping. This vulnerability allows an attacker to cause a denial of service by providing invalid or conflicting input parameters. The affected component improperly terminates the process instead of handling the input error gracefully, leading to immediate service disruption. | date |
| severity Important | advisory_cveCVE-2026-44495 | synopsis A flaw was found in Axios, a promise-based HTTP client. This vulnerability involves prototype pollution gadgets in the request configuration processing. If another vulnerability has already polluted the Object.prototype.transformResponse, affected Axios versions may incorrectly interpret this inherited value as part of the request configuration or as an option validator. Axios does not itself create the prototype pollution. Exploitability requires a separate prototype-pollution vulnerability or equivalent attacker control over Object.prototype before Axios creates a request. | date |
| severity Moderate | advisory_cveCVE-2026-8723 | synopsis A flaw was found in the `qs` library. When the `qs.stringify` function processes arrays containing `null` or `undefined` elements, and is configured with both `arrayFormat: 'comma'` and `encodeValuesOnly: true`, it can trigger a `TypeError`. This error causes the application to crash or return a 500 error, leading to a Denial of Service (DoS) for affected requests. | date |
| severity Moderate | advisory_cveCVE-2026-33349 | synopsis A flaw was found in fast-xml-parser. A remote attacker can exploit this vulnerability by providing specially crafted XML input to an application using the affected library. The DocTypeReader component incorrectly processes configuration limits for entity counts and sizes when these limits are explicitly set to zero, bypassing intended restrictions. This oversight allows for unbounded entity expansion, consuming excessive memory and leading to a Denial of Service (DoS) condition, which makes the application unavailable to legitimate users. | date |
top_resources
Knowledgebase
Access articles and solutions to find answers to your questions.
Supported configurations
See your Red Hat-provided production or development support for supported configurations.
Troubleshooting
Connect to the right information to self-solve issues quickly and efficiently.
Lifecycle
View the various levels of maintenance for each release of a product over a period from initial release to the end of maintenance.