Denial of Service Vulnerability in EAP's Undertow HTTP Decoder
CVE-2026-15561
7.5HIGH
Key Information:
What is CVE-2026-15561?
A security flaw has been identified in EAP's Undertow HTTP/1.1 chunked-transfer decoder, where inadequate limits on size and count can be exploited by an attacker. This vulnerability allows an unauthenticated connection to overwhelm the Java Virtual Machine (JVM), potentially causing an OutOfMemory error. Such an error can result in all deployments on the listener being halted, leading to a significant disruption of service.
Affected Version(s)
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:2.16.0-22.redhat_00057.1.el7eap
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:2.3.14-11.SP11_redhat_00001.1.el7eap
Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:1.5.26-2.Final_redhat_00001.1.el7eap