Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-15561

Опубликовано: 11 авг. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
undertowunfixedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2483133

EPSS

Процентиль: 28%
0.0035
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 дней назад

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

CVSS3: 7.5
redhat
7 дней назад

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

CVSS3: 7.5
nvd
7 дней назад

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

CVSS3: 7.5
github
7 дней назад

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

EPSS

Процентиль: 28%
0.0035
Низкий