VDB

GCVE-110-NCSC-2026-258

GCVE-110-NCSC-2026-258
Advisory PublishedCVSS 9.8/10
Vulnetix · Advisory published July 22, 2026
Apache Avro versions prior to 1.11.4 contain schema parsing vulnerabilities that enable remote code execution, data disclosure, modification, and denial of service across multiple enterprise products including Red Hat JBoss, NetApp, Oracle BPM, SOA Suite, Hyperion, and HPE solutions.

Weaknesses (CWE)

CWE-502Deserialization of Untrusted DataCWE-94Improper Control of Generation of Code ('Code Injection')CWE-289Authentication Bypass by Alternate NameCWE-863Incorrect AuthorizationCWE-908Use of Uninitialized ResourceCWE-226Sensitive Information in Resource Not Removed Before ReuseCWE-409Improper Handling of Highly Compressed Data (Data Amplification)CWE-425Direct Request ('Forced Browsing')CWE-297Improper Validation of Certificate with Host MismatchCWE-532Insertion of Sensitive Information into Log FileCWE-1285Improper Validation of Specified Index, Position, or Offset in InputCWE-116Improper Encoding or Escaping of OutputCWE-862Missing AuthorizationCWE-770Allocation of Resources Without Limits or Throttling

Risk Scores

CVSS 3.1
9.8/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Oracle Corporationvers:unknown/*
Oraclevers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

68,083 records in the GCVE database · Updated August 18, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›