Red Hat released RHSA-2026:48151 to patch Cryostat 4 on RHEL 9, rating the update Important and warning that the product bundled numerous vulnerable dependencies. The advisory covers a broad range of issues across components including Netty, Quarkus, Jackson Databind, Vert.x, several Go libraries, undici, ws, protobufjs, form-data, js-cookie, brace-expansion, and Avro decoders. Red Hat said the flaws could enable denial of service, information disclosure, data manipulation, authorization bypass, hostname verification bypass, man-in-the-middle attacks, cross-site scripting, integer overflow, prototype pollution, and arbitrary code execution.
One of the tracked issues, CVE-2026-42504, affected Go's MIME handling and could cause excessive CPU consumption when decoding a maliciously crafted MIME header with many invalid encoded words, resulting in a denial-of-service condition. Red Hat linked that bug directly to Cryostat 4 on RHEL 9 and said it was remediated through the same advisory, instructing customers to apply the update after confirming any prerequisite errata are already installed.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Red Hat's Bugzilla entry for CVE-2026-42504 describes a denial-of-service issue in Golang MIME header decoding caused by maliciously crafted headers with many invalid encoded-words. The notice says Cryostat 4 on RHEL 9 is affected and that the issue was addressed through advisory RHSA-2026:48151.
Red Hat published security advisory RHSA-2026:48151, rated Important, for the Red Hat build of Cryostat 4 on RHEL 9. The update addresses numerous bundled dependency vulnerabilities affecting components including Netty, Quarkus, Jackson Databind, Vert.x, Go libraries, undici, ws, protobufjs, form-data, js-cookie, brace-expansion, and Avro decoders.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.