RHSA-2026:8159HighCVSS 7.5
Red Hat Security Advisory: Red Hat Build of Apache Camel 4.14 for Quarkus 3.27 update is now available (RHBQ 3.27.3.GA)
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-1002 — io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files CVE-2026-33870 — io.netty/netty-codec-http: Netty: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values CVE-2026-33871 — netty: Netty: Denial of Service via HTTP/2 CONTINUATION frame flood
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:8159
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2430180
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2452453
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2452456
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_8159.json