VDB
GCVE-110-NCSC-2026-258
GCVE-110-NCSC-2026-258
Advisory PublishedCVSS 9.8/10
Apache Avro versions prior to 1.11.4 contain schema parsing vulnerabilities that enable remote code execution, data disclosure, modification, and denial of service across multiple enterprise products including Red Hat JBoss, NetApp, Oracle BPM, SOA Suite, Hyperion, and HPE solutions.
Weaknesses (CWE)
CWE-502Deserialization of Untrusted DataCWE-94Improper Control of Generation of Code ('Code Injection')CWE-289Authentication Bypass by Alternate NameCWE-863Incorrect AuthorizationCWE-908Use of Uninitialized ResourceCWE-226Sensitive Information in Resource Not Removed Before ReuseCWE-409Improper Handling of Highly Compressed Data (Data Amplification)CWE-425Direct Request ('Forced Browsing')CWE-297Improper Validation of Certificate with Host MismatchCWE-532Insertion of Sensitive Information into Log FileCWE-1285Improper Validation of Specified Index, Position, or Offset in InputCWE-116Improper Encoding or Escaping of OutputCWE-862Missing AuthorizationCWE-770Allocation of Resources Without Limits or Throttling
Risk Scores
CVSS 3.1
9.8/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Oracle Corporation | vers:unknown/* | — | — |
| Oracle | vers:unknown/* | — | — |
Browse GCVE Records
68,083 records in the GCVE database · Updated August 18, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.