WebSocket Connection Flaw in Undertow Affects JBoss EAP and WildFly
CVE-2026-81624
7.5HIGH
What is CVE-2026-81624?
A significant flaw has been identified in Undertow, a versatile web server component utilized in JBoss EAP and WildFly, concerning the management of WebSocket connections. The vulnerability arises from default configuration limits that do not constrain message buffer sizes and session timeouts, which remain set to unlimited. As a result, an attacker can exploit this weakness by sending excessive data or maintaining persistent connections, which may lead to server instability, resource exhaustion, and ultimately, a system crash.