« Back to list

Redhat

Redhat Migration Toolkit FOR Applications: vulnerabilities and CVEs

Redhat Migration Toolkit FOR Applications has 5 published vulnerabilities, 1 of them in the last 12 months. 0 are rated critical and 2 are listed by CISA as actively exploited.

CVEs5
Last 12 months1
Critical0
Actively exploited2

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-48710Medium (6.5)7.1%⚠ Active exploitationMay 26, 2026
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw…
CVE-2023-44487High (7.5)100%⚠ Active exploitationOct 10, 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-48710Medium (6.5)7.1%⚠ Active exploitationMay 26, 2026
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw…
CVE-2024-1132High (8.1)1.6%—Apr 17, 2024
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive…
CVE-2023-6291High (7.1)0.95%—Jan 26, 2024
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible…
CVE-2023-44487High (7.5)100%⚠ Active exploitationOct 10, 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2022-4492High (7.5)0.60%—Feb 23, 2023
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application2
  2. T1499.004 Application or System Exploitation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Redhat