CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0254 [1.00] [M/H] Vulnerabilities fixed in Oracle database products

unknownCVE-2026-3381CVE-2026-27171
Oracle has fixed 158 vulnerabilities in Oracle Database Server, APEX, Autonomous Health Framework, Essbase, Global Lifecycle Management, GoldenGate, NoSQL Database, Spatial Studio, SQL Developer, and TimesTen In-Memory Database. Of these vulnerabilities, 91 are from third-party products for which updates have previously been released and are now processed by Oracle, or concern vulnerabilities that cannot lead to exploitation because they are in parts of the products that are not accessible. The six most severe vulnerabilities have received a CVSS score of 9 or higher. The vulnerability in Eclipse Jetty's HTTP/1.1 parser, used in Oracle REST Data Services versions 24.2.0 to 26.1.0, concerns incorrect parsing of chunked transfer encoding extensions with unclosed quoted strings, allowing HTTP request smuggling. This can lead to cache poisoning, bypass of access control, session hijacking, and unauthorized access to endpoints. Perl versions from 5.9.4 to 5.43.9 contain a vulnerable Compress::Raw::Zlib module due to an outdated zlib library with multiple security issues, including CVE-2026-3381 and CVE-2026-27171. This vulnerability is relevant for Perl distributions often deployed in Red Hat Enterprise Linux and OpenShift Container Platform environments. Apache Kafka versions 4.1.0 and 4.1.1 contain a vulnerability in JWT token validation where the default validator accepts any JWT token without proper validation, potentially allowing unauthorized access. This is resolved by explicitly setting the validator or upgrading to version 4.1.2 or higher. Oracle Communications Unified Assurance Message Bus components versions 6.1.1 to 7.0.0, which use Apache Kafka, contain a vulnerability that allows unauthenticated network attackers to gain unauthorized access and modify critical data. Oracle Net Services versions 19.3 to 19.31, 21.3.

CSIRTS triage

What
Multiple vulnerabilities have been fixed, including one that allows HTTP request smuggling.
Who is affected
Users of various Oracle Database products, including Oracle REST Data Services versions 24.2.0 to 26.1.0.
Urgency
Remediation is necessary due to the potential for exploitation of the vulnerabilities.
Action
Apply the latest updates from Oracle.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Oracle Database

Get an email when a new Oracle Database advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-07-22
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0254

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-3381coverage & exploitation statusNVD · CVE.org
CVE-2026-27171coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Oracle database products

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories