VDB

GCVE-110-MAGEIA-2026-139

GCVE-110-MAGEIA-2026-139
Advisory Published
Vulnetix · Advisory published May 15, 2026
Unbounded read in WebDAV LOCK and PROPFIND handling. (CVE-2026-41284) HTTP/2 request headers not validated. (CVE-2026-41293) WebSocket authentication header exposure. (CVE-2026-42498) Digest authenticator will authenticate any unknown user. (CVE-2026-43512) LockOutRealm treats user names as case-sensitive. (CVE-2026-43513) AJP secret compared in non-constant time. (CVE-2026-43514) Security constraints not correctly applied. (CVE-2026-43515)

Affected Products

VendorProductVersionsPlatforms
Mageiatomcat0 (affected), 9.0.118-1.mga9 (unaffected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›