Out of Memory Flaw in Undertow Affects WebSocket Endpoints
CVE-2026-15565

7.5HIGH

What is CVE-2026-15565?

A vulnerability has been identified in Undertow, where a remote attacker can exploit WebSocket endpoints associated with any @ServerEndpoint class that implements an @OnMessage method. This allows attackers to initiate a Denial of Service (DoS) by causing an out-of-memory condition using standard WebSocket handshake procedures without requiring any form of authentication. Consequently, such attacks can disrupt service availability and negatively impact users.

Affected Version(s)

Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:2.16.0-22.redhat_00057.1.el7eap

Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:2.3.14-11.SP11_redhat_00001.1.el7eap

Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 0:1.5.26-2.Final_redhat_00001.1.el7eap

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.