Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5680

Опубликовано: 04 июл. 2026
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.

Меры по смягчению последствий

To mitigate this issue, configure the PerMessageDeflateHandshake to limit the maximum decompressed buffer size. This can be achieved by setting the maxDecompressedBufferSize parameter to a reasonable value (e.g., 10 MB) in the PerMessageDeflateHandshake constructor. This action may require a restart of the affected application or service to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4undertow-coreAffected
Red Hat build of Apache Camel - HawtIO 4undertow-coreNot affected
Red Hat Data Grid 8undertow-coreAffected
Red Hat Enterprise Linux 10moditectNot affected
Red Hat Enterprise Linux 8pki-core:10.6/resteasyAffected
Red Hat Enterprise Linux 8pki-deps:10.6/resteasyNot affected
Red Hat Enterprise Linux 9resteasyAffected
Red Hat Fuse 7undertow-coreAffected
Red Hat JBoss Enterprise Application Platform 7undertow-coreWill not fix
Red Hat JBoss Enterprise Application Platform 8undertow-coreAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2455350undertow-core: Undertow: Denial of Service via WebSocket permessage-deflate processing

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
9 дней назад

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.

CVSS3: 7.5
nvd
9 дней назад

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.

CVSS3: 7.5
debian
9 дней назад

A flaw was found in Undertow. A remote attacker could exploit this vul ...

CVSS3: 7.5
github
9 дней назад

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.

7.5 High

CVSS3