Описание
A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack without authentication and using only a standard WebSocket handshake.
Меры по смягчению последствий
Option 1 — Server-wide configuration to disable websockets handshake:
isWebsocketsEnabled() returns false → no WebSocket upgrade accepted for any deployment. Option 2 — Per-application configuration to disable websockets handshake: false Only that specific WAR's @ServerEndpoint classes are not registered.Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel for Spring Boot 4 | undertow-websockets-jsr | Affected | ||
| Red Hat Data Grid 8 | undertow-websockets-jsr | Affected | ||
| Red Hat Fuse 7 | undertow-websockets-jsr | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 8 | undertow-websockets-jsr | Affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | undertow-websockets-jsr | Not affected | ||
| Red Hat Single Sign-On 7 | undertow-websockets-jsr | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7.4.25 | undertow-websockets-jsr | Fixed | RHSA-2026:53806 | 11.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack without authentication and using only a standard WebSocket handshake.
A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack without authentication and using only a standard WebSocket handshake.
A flaw was found in Undertow. A remote attacker can cause Out of Memor ...
A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack without authentication and using only a standard WebSocket handshake.
EPSS
7.5 High
CVSS3