Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-81624

Опубликовано: 27 авг. 2026
Источник: redhat
CVSS3: 7.5

Описание

Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being unlimited. This allows a remote attacker to send large amounts of data or maintain connections indefinitely, potentially crashing the server by exhausting its memory or other resources.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Important, given that the default configuration allows for unlimited resource consumption. Successful exploitation allows an attacker to cause a denial of service via resource exhaustion. The vulnerability's root cause is the lack of configuration options for WebSocket buffer sizes and timeouts in the container boot process.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4undertow-coreAffected
Red Hat Enterprise Linux 10moditectNot affected
Red Hat Enterprise Linux 8pki-core:10.6/resteasyNot affected
Red Hat Enterprise Linux 8pki-deps:10.6/resteasyNot affected
Red Hat Enterprise Linux 9resteasyNot affected
Red Hat Fuse 7undertow-coreWill not fix
Red Hat JBoss Enterprise Application Platform 7jboss-eap-7/eap74-els-openjdk11-openshift-rhel8Will not fix
Red Hat JBoss Enterprise Application Platform 7jboss-eap-7/eap74-els-openjdk17-openshift-rhel8Will not fix
Red Hat JBoss Enterprise Application Platform 7jboss-eap-7/eap74-els-openjdk8-openshift-rhel8Will not fix
Red Hat JBoss Enterprise Application Platform 7undertow-coreWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2524868undertow-core: undertow: WebSocketContainer defaults for buffers and timeouts are infinite

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
16 дней назад

Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being unlimited. This allows a remote attacker to send large amounts of data or maintain connections indefinitely, potentially crashing the server by exhausting its memory or other resources.

CVSS3: 7.5
nvd
16 дней назад

Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being unlimited. This allows a remote attacker to send large amounts of data or maintain connections indefinitely, potentially crashing the server by exhausting its memory or other resources.

CVSS3: 7.5
debian
16 дней назад

Undertow is a flexible performant web server used in JBoss EAP and Wil ...

CVSS3: 7.5
github
16 дней назад

Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being unlimited. This allows a remote attacker to send large amounts of data or maintain connections indefinitely, potentially crashing the server by exhausting its memory or other resources.

7.5 High

CVSS3