Red Hat Data Grid
Red Hat Data Grid is an in-memory, distributed, elastic NoSQL key-value datastore. Built from the Infinispan open-source software project, it's available to deploy as an embedded library, as a standalone server, or as a containerized application on Red Hat OpenShift Container Platform.
Browse the latest documentation
Red Hat Data Grid 8.6 Release NotesRelease Information
Data Grid Operator GuideData Grid Operator
Building and deploying Data Grid clusters with HelmData Grid Helm Chart
Data Grid Server GuideData Grid Server
Hot Rod Java Client GuideHot Rod Clients
Data Grid Performance and Sizing GuideDeployment Planning
Upgrading Data GridUpgrading
Latest security advisories
| Severity | Advisory/CVE | Synopsis | Date |
|---|---|---|---|
| Severity Moderate | Advisory/CVECVE-2026-59296 | Synopsis A flaw was found in Micrometer's StatsD and Logging meter registries. This vulnerability allows a remote attacker to inject line terminators into metric data, such as names or tag values, due to insufficient sanitization of untrusted input. Exploitation can lead to the spoofing of arbitrary metrics, including critical system or business metrics, and the injection of false log entries, potentially impacting monitoring and auditing systems. | Date |
| Severity Important | Advisory/CVECVE-2026-67214 | Synopsis A flaw was found in nanoid (Nano ID), a JavaScript library used for generating unique identifiers. This vulnerability allows an attacker to cause a Denial of Service (DoS) by providing a negative size input to the customAlphabet or nanoid functions within the library's non-secure module. When a negative size is provided, these functions enter an infinite loop, causing the application to hang indefinitely and disrupting service availability. | Date |
| Severity Moderate | Advisory/CVECVE-2026-65902 | Synopsis A flaw was found in DOMPurify. An attacker can exploit a vulnerability in how DOMPurify handles its sanitization hooks when default configurations are used. By manipulating the uponSanitizeElement or uponSanitizeAttribute hooks, an attacker can permanently alter the allowed HTML tags and attributes. This allows malicious content to bypass sanitization, potentially leading to cross-site scripting (XSS) attacks and compromising the integrity of web applications. | Date |
| Severity Moderate | Advisory/CVECVE-2026-65899 | Synopsis A flaw was found in DOMPurify where the clearConfig() function does not properly reset the retained Trusted Types policy. This can lead to a DOMPurify instance, when reused across different security contexts, remaining bound to a previously supplied and potentially unsafe policy. An attacker could leverage this to execute malicious scripts, resulting in client-side arbitrary code execution. | Date |
| Severity Important | Advisory/CVECVE-2026-41292 | Synopsis A flaw was found in Unbound. A remote attacker can exploit this vulnerability by sending queries with an excessive number of EDNS (Extension Mechanisms for DNS) options. This can cause Unbound threads to be held hostage while parsing and creating internal data structures for these options. Coordinated attacks can lead to resource exhaustion, resulting in a degradation of service or a denial of service (DoS) for legitimate users. | Date |
Top resources
Get support
Support cases
Get answers quickly by opening a support case with us.
Live chat
Directly access our support engineers during weekday business hours.
Call or email
Speak directly with a Red Hat Support expert by phone or through email.