Red Hat released Red Hat Data Grid 8.6.1 and later 8.6.2 to remediate multiple Important security issues in bundled components affecting Red Hat JBoss Data Grid. The advisories cite vulnerabilities in Netty, Axios, Spring Boot, lodash, DOMPurify, Apache Log4j, jackson-databind, React Router, Micrometer, OpenTelemetry Java, form-data, fast-uri, and webpack-dev-server, with impacts including remote or arbitrary code execution, denial of service, request smuggling, authentication bypass, information disclosure, prototype pollution, hostname verification bypass, command injection, log injection, and cross-site scripting.
One of the disclosed flaws, CVE-2026-9595 in webpack-dev-server, could let an overly broad proxy configuration with ws: true intercept Hot Module Replacement WebSocket traffic, exposing browser cookies and the Origin header to a proxy backend while also bypassing Host and Origin checks and disrupting the HMR socket. Red Hat said the issue was fixed in Data Grid 8.6.2, and advised customers to update from earlier releases, while mitigations for affected development environments include limiting proxy contexts to specific paths instead of / and avoiding WebSocket forwarding where it is not required.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-20, Red Hat Bugzilla documented CVE-2026-9595 in webpack-dev-server, describing information disclosure and denial-of-service risks when a broadly scoped proxy with `ws: true` intercepts HMR WebSocket traffic. The entry states the issue was fixed in webpack-dev-server version 5 and addressed in Red Hat Data Grid 8.6.2 via RHSA-2026:41951.
On 2026-07-20, Red Hat published advisory RHSA-2026:41951, rated Important, announcing Red Hat Data Grid 8.6.2 as a replacement for 8.6.1. The update included bug fixes, enhancements, and remediation for numerous vulnerabilities across bundled components including jackson-databind, React Router, Axios, Netty, Micrometer, OpenTelemetry Java, form-data, webpack-dev-server, and fast-uri.
On 2026-06-02, Red Hat published advisory RHSA-2026:22619, rated Important, announcing Red Hat Data Grid 8.6.1 as a replacement for 8.6.0. The update included bug fixes, enhancements, and fixes for multiple bundled-component vulnerabilities affecting Netty, Axios, Spring Boot, lodash, DOMPurify, and Apache Log4j.
On 2026-08-20, Red Hat published advisory RHSA-2026:57590. Related Bugzilla content states this advisory addresses CVE-2026-9595 in Red Hat Enterprise Linux 10.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.