Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15561

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 8undertow-coreAffected
Red Hat JBoss Enterprise Application Platform Expansion Packundertow-coreNot affected
Red Hat JBoss Enterprise Application Platform 7.4.25undertow-coreFixedRHSA-2026:5380611.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-activemq-artemisFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-glassfish-jsfFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-ironjacamarFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-jackson-annotationsFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-jackson-coreFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-jackson-databindFixedRHSA-2026:5364411.08.2026
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7eap7-jackson-jaxrs-providersFixedRHSA-2026:5364411.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2483133undertow-core: OOM via missing limits in chunked trailer in EAP's Undertow

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 дней назад

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

CVSS3: 7.5
nvd
7 дней назад

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

CVSS3: 7.5
debian
7 дней назад

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. ...

CVSS3: 7.5
github
7 дней назад

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

7.5 High

CVSS3