Skip to content

CVE update for 26.0.0.10 #8563

Description

@Faizi-AdnanFahad

This issue is opened for updating the CVE list for 26.0.0.10 to include the following. @ayoho @cluk fyi

|https://www.cve.org/CVERecord?id=CVE-2026-11713[CVE-2026-11713]
|5.4
|Information Disclosure
|17.0.0.3-26.0.0.9
|26.0.0.10
|Affects the feature:restConnector-2.0 feature

|https://www.cve.org/CVERecord?id=CVE-2026-14909[CVE-2026-14909]
|6.5
|SQL Injection
|17.0.0.3-26.0.0.9
|26.0.0.10
|Affects the feature:restConnector-2.0 feature

|https://www.cve.org/CVERecord?id=CVE-2026-49875[CVE-2026-49875]
|9.8
|Server-Side Request Forgery
|17.0.0.3-26.0.0.9
|26.0.0.10
|Affects the feature:jaxrs-2.0, feature:jaxrs-2.1, feature:jaxws-2.2, feature:xmlWS-3.0, feature:xmlWS-4.0, and feature:wsAtomicTransaction-1.2 features

|https://www.cve.org/CVERecord?id=CVE-2026-65432[CVE-2026-65432]
|7.5
|Cross-Site Scripting
|17.0.0.3-26.0.0.9
|26.0.0.10
|Affects the feature:jaxws-2.2, feature:xmlWS-3.0, feature:xmlWS-4.0, feature:wsSecurity-1.1, and feature:wsAtomicTransaction-1.2 features

|https://www.cve.org/CVERecord?id=CVE-2026-66142[CVE-2026-66142]
|7.5
|Denial of Service
|17.0.0.3-26.0.0.9
|26.0.0.10
|Affects the feature:jaxws-2.2, feature:xmlWS-3.0, and feature:xmlWS-4.0 features

|https://www.cve.org/CVERecord?id=CVE-2026-66143[CVE-2026-66143]
|7.5
|Denial of Service
|17.0.0.3-26.0.0.9
|26.0.0.10
|Affects the feature:jaxws-2.2, feature:xmlWS-3.0, and feature:xmlWS-4.0 features

|https://www.cve.org/CVERecord?id=CVE-2026-66144[CVE-2026-66144]
|7.5
|Denial of Service
|17.0.0.3-26.0.0.9
|26.0.0.10
|Affects the feature:jaxws-2.2, feature:xmlWS-3.0, and feature:xmlWS-4.0 features

|https://www.cve.org/CVERecord?id=CVE-2026-77816[CVE-2026-77816]
|6.5
|Path Traversal
|17.0.0.3-26.0.0.9
|26.0.0.10
|

|https://www.cve.org/CVERecord?id=CVE-2026-79715[CVE-2026-79715]
|5.5
|Path Traversal
|17.0.0.3-26.0.0.9
|26.0.0.10
|

Activity

  1. added a commit that references this issue on Oct 1, 2026
  2. ramkumar-k-9286 commented on Oct 1, 2026

    @ramkumar-k-9286
    Contributor

    Hi @Faizi-AdnanFahad

    Suggested updates have been incorporated to the Security vulnerability (CVE) list page.

    Draft site Link: https://docs-draft-openlibertyio.mqj6zf7jocq.us-south.codeengine.appdomain.cloud/docs/latest/security-vulnerabilities.html

    When you have it, please share the pending information to update in the page.

    Regards,
    Ramkumar.

  3. ramkumar-k-9286 commented on Oct 2, 2026

    @ramkumar-k-9286
    Contributor

    Hi @Faizi-AdnanFahad

    Suggested updates have been incorporated to the Security vulnerability (CVE) list page.

    Draft site Link: https://docs-draft-openlibertyio.mqj6zf7jocq.us-south.codeengine.appdomain.cloud/docs/latest/security-vulnerabilities.html

    Please share the information to be added to notes for the first two CVE

    Regards,
    Ramkumar.

  4. Faizi-AdnanFahad commented on Oct 2, 2026

    @Faizi-AdnanFahad
    Author

    Regarding the notes missing field in the first two entries, since the SB has not been published, I can't get those until the SB is published on Tuesday. Talking to Ram, the doc building and publishing is a multistage process and can take quite a bit of time which can't be done quickly on Tuesday, we can go ahead and publish this as is and come back and update it on Wednesday.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions