Red Hat released Important security updates for Red Hat AMQ Broker 7.12.7 and 7.13.5, addressing multiple vulnerabilities in bundled components including Bouncy Castle, Netty, and Apache ZooKeeper. The advisories cover issues such as LDAP injection in BC-JAVA (CVE-2026-0636), HTTP request smuggling and HTTP/2 denial of service in Netty, and ZooKeeper flaws that could enable information disclosure and reverse-DNS-spoofing-based impersonation. Red Hat told customers to back up existing installations before applying the fixed releases from the Customer Portal.
The updates also remediate a Bouncy Castle cryptographic flaw, CVE-2025-14813, in the GOSTCTR implementation, where keystream reuse after more than 255 blocks under the same key and IV can allow plaintext recovery from captured ciphertext. Red Hat rated that issue Important with a CVSS 7.5 score and advised limiting encrypted payloads to 255 blocks per key/IV pair or moving to a stronger authenticated encryption mode until patched. The underlying weakness aligns with CWE-327, which covers the use of broken or risky cryptographic algorithms that can expose sensitive data and undermine system trust.

See real exploitation activity before you spend the cycle.
13 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-06, Red Hat issued RHSA-2026:14272 for Red Hat AMQ Broker 7.13.5, rated Important, addressing multiple vulnerabilities including LDAP injection, request smuggling, denial of service, and cryptographic validation flaws.
On 2026-05-06, Red Hat issued RHSA-2026:14276 for Red Hat AMQ Broker 7.12.7, rated Important, with fixes for vulnerabilities in Bouncy Castle, Apache ZooKeeper, and Netty.
Red Hat published its CVE-2026-0636 record on April 15, 2026, describing an LDAP injection flaw in Bouncy Castle's LDAPStoreHelper implementation.
Red Hat published its CVE-2025-14813 record on April 15, 2026, describing a Bouncy Castle GOSTCTR flaw that can cause keystream reuse after more than 255 blocks under the same key and IV.
The CWE-327 entry lists CVE-2022-30320 as an observed example where a PLC protocol uses a cryptographically insecure hashing algorithm for passwords.
The CWE-327 entry lists CVE-2022-30273 as an observed example involving use of TEA in ECB mode in a SCADA-based protocol.
The CWE-327 entry references the 2022 OT:ICEFALL study, which examined products from 10 OT vendors and reported 56 vulnerabilities, including weak cryptography in multiple OT products.
The CWE-327 entry states that SHA-1 was practically broken in 2017 at a cost of about $110K, reinforcing the risks of relying on obsolete cryptography.
CVE-2008-3775 is cited in the CWE-327 entry as an observed example of a product using ROT-25 to obfuscate a password in the registry.
The CWE-327 entry notes that SHA-1 was theoretically broken in 2005, illustrating how cryptographic algorithms can become unsafe over time.
Red Hat's CVE records state that Red Hat JBoss Enterprise Application Platform 7.4.25 with bcprov-jdk12 was listed as fixed for CVE-2025-14813 and CVE-2026-0636 on August 11, 2026.
Red Hat last modified its CVE-2026-0636 entry on June 30, 2026, including mitigation guidance and references to upstream and downstream fixes.
Red Hat last modified its CVE-2025-14813 entry on June 30, 2026, after publishing mitigation guidance and affected-product fix information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.