cbcvebase.

Redhat Fuse vulnerabilities

40 known vulnerabilities affecting redhat/fuse.

Total CVEs
40
CISA KEV
3
actively exploited
Public exploits
8
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH13MEDIUM11LOW8

Vulnerabilities

Page 2 of 2
CVE-2026-3260P3HIGHCVSS 7.5v7.0.02026-03-24
CVE-2026-3260 [HIGH] CWE-770 CVE-2026-3260: A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes parameters using methods like `getParameterMap()`, the server prematurely parses and stores this content to disk. This could lead to resource exhaustion, potentiall
nvd
CVE-2023-1108P3HIGHCVSS 7.5v1.0.02023-09-14
CVE-2023-1108 [HIGH] CWE-835 CVE-2023-1108: A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unex A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
nvd
CVE-2016-1233P3HIGHCVSS 7.8≥ 0, < 2.9.5-12016-01-26
CVE-2016-1233 [HIGH] CVE-2016-1233: An unspecified udev rule in the Debian fuse package in jessie before 2 An unspecified udev rule in the Debian fuse package in jessie before 2.9.3-15+deb8u2, in stretch before 2.9.5-1, and in sid before 2.9.5-1 sets world-writable permissions for the /dev/cuse character device, which allows local users to gain privileges via a character device in /dev, related to an ioctl.
osv
CVE-2017-7957P3HIGHCVSS 7.5v1.02017-04-29
CVE-2017-7957 [HIGH] CWE-20 CVE-2017-7957: XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to creat XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("") call.
nvd
CVE-2025-57849P3MEDIUMCVSS 6.4v7.0.02026-03-13
CVE-2025-57849 [MEDIUM] CWE-276 CVE-2025-57849: A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /e A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modif
nvd
CVE-2021-3690P3HIGHCVSS 7.5v1.02022-08-23
CVE-2021-3690 [HIGH] CWE-400 CVE-2021-3690: A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memor A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
nvd
CVE-2020-10719P4MEDIUMCVSS 6.5v1.02020-05-26
CVE-2020-10719 [MEDIUM] CWE-444 CVE-2020-10719: A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTT A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.
nvd
CVE-2020-25689P4MEDIUMCVSS 6.5v6.0.02020-11-02
CVE-2020-25689 [MEDIUM] CWE-401 CVE-2020-25689: A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tr A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat
nvd
CVE-2021-4178P4MEDIUMCVSS 6.7v7.112022-08-24
CVE-2021-4178 [MEDIUM] CWE-502 CVE-2021-4178: A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0 A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.
nvd
CVE-2018-1199P4MEDIUMCVSS 5.3v1.02018-03-16
CVE-2018-1199 [MEDIUM] CWE-20 CVE-2018-1199: Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint. The
nvd
CVE-2019-14860P4MEDIUMCVSS 6.5fixed in 7.5.02019-11-08
CVE-2019-14860 [MEDIUM] CWE-942 CVE-2019-14860: It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1v1.02019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2005-1858P4LOWCVSS 2.1PoC≥ 0, < 2.3.0-12005-06-03
CVE-2005-1858 [LOW] CVE-2005-1858: FUSE 2 FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local users to obtain sensitive information.
osv
CVE-2021-3597P4MEDIUMCVSS 5.9v1.02022-05-24
CVE-2021-3597 [MEDIUM] CWE-362 CVE-2021-3597: A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circu A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior
nvd
CVE-2020-10688P4MEDIUMCVSS 6.1v1.02021-05-27
CVE-2020-10688 [MEDIUM] CWE-79 CVE-2020-10688: A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4 A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.
nvd
CVE-2011-0543P4LOWCVSS 3.3≥ 0, < 2.8.5-12011-09-02
CVE-2011-0543 [LOW] CVE-2011-0543: Certain legacy functionality in fusermount in fuse 2 Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.
osv
CVE-2011-0542P4LOWCVSS 3.3≥ 0, < 2.8.5-12011-09-02
CVE-2011-0542 [LOW] CVE-2011-0542: fusermount in fuse 2 fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified vectors.
osv
CVE-2011-0541P4LOWCVSS 3.3≥ 0, < 2.8.5-12011-09-02
CVE-2011-0541 [LOW] CVE-2011-0541: fuse 2 fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.
osv
CVE-2010-0789P4LOWCVSS 3.3≥ 0, < 2.8.1-1.22010-03-02
CVE-2010-0789 [LOW] CVE-2010-0789: fusermount in FUSE before 2 fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint.
osv
CVE-2005-3531P4LOWCVSS 2.1≥ 0, < 2.4.1-0.12005-11-23
CVE-2005-3531 [LOW] CVE-2005-3531: fusermount in FUSE before 2 fusermount in FUSE before 2.4.1, if installed setuid root, allows local users to corrupt /etc/mtab and possibly modify mount options by performing a mount over a directory whose name contains certain special characters.
osv
Redhat Fuse vulnerabilities | cvebase