REDHAT-BUG-2429926: XSS
Published Jan 15, 2026
·Updated
There is a CRLF injection vulnerability in HttpServer in JDK which may lead to potential XSS.
Affected Software
1 affected component
Oracle JDK
Event History
Jan 15, 2026
Data Sourced
via Red Hat·12:06 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2429926?
The severity of REDHAT-BUG-2429926 is categorized as moderate due to its potential for leading to XSS attacks.
2
How do I fix REDHAT-BUG-2429926?
To fix REDHAT-BUG-2429926, update to the latest version of Oracle JDK that addresses the CRLF injection vulnerability.
3
What causes REDHAT-BUG-2429926 vulnerability?
REDHAT-BUG-2429926 is caused by improper handling of newline characters in the HttpServer component of the JDK.
4
Who is affected by REDHAT-BUG-2429926?
Users of Oracle JDK are affected by REDHAT-BUG-2429926, particularly those using vulnerable versions.
5
Can REDHAT-BUG-2429926 be exploited remotely?
Yes, REDHAT-BUG-2429926 can potentially be exploited remotely if an attacker can send crafted requests to the HttpServer.