Jboss Fuse
101 CVEs tracked. 5 of them are in CISA KEV.
This hub aggregates every CVE we track for Jboss Fuse, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Jboss Fuse CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 101 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical26
- High37
- Medium31
- Low7
Latest CVEs
The 15 most recently published vulnerabilities affecting Jboss Fuse.
- CVE-2024-7885Undertow: improper state management in proxy protocol parsing causes information leakage7.5
- CVE-2023-6717Keycloak: xss via assertion consumer service url in saml post-binding flow6.0
- CVE-2023-26159Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error, ...7.3
- CVE-2023-45648Apache Tomcat: Trailer header parsing too lenient5.3
- CVE-2023-44487The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.7.5
- CVE-2023-35116jackson-databind through 2.15.2 allows attackers to cause a denial of service or other unspecified impact via a crafted object that uses cyclic dependencies. NOTE: the vendor's perspective is that ...4.7
- CVE-2023-26464Apache Log4j 1.x (EOL) allows DoS in Chainsaw and SocketAppender7.5
- CVE-2022-4492The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and...7.5
- CVE-2022-41966XStream Denial of Service via stack overflow 8.2
- CVE-2022-41854Stack Overflow in Snakeyaml5.8
- CVE-2022-42920Apache Commons BCEL prior to 6.6.0 allows producing arbitrary bytecode via out-of-bounds writing9.8
- CVE-2022-37865Apache Ivy allows creating/overwriting any file on the system9.1
- CVE-2022-3647Redis Crash Report debug.c sigsegvHandler denial of service3.1
- CVE-2022-38749DoS in SnakeYAML6.5
- CVE-2022-2764A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.4.9
Product grouping is registry-driven, with AI assist and human review. How it works