Denial of Service Vulnerability in EAP's Undertow HTTP Decoder
CVE-2026-15561

7.5HIGH

What is CVE-2026-15561?

A security flaw has been identified in EAP's Undertow HTTP/1.1 chunked-transfer decoder, where inadequate limits on size and count can be exploited by an attacker. This vulnerability allows an unauthenticated connection to overwhelm the Java Virtual Machine (JVM), potentially causing an OutOfMemory error. Such an error can result in all deployments on the listener being halted, leading to a significant disruption of service.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.