Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being unlimited. This allows a remote attacker to send large amounts of data or maintain connections indefinitely, potentially crashing the server by exhausting its memory or other resources.
Metrics
Affected Vendors & Products
References
History
Mon, 31 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat build Of Apache Camel For Spring Boot
Redhat jboss Enterprise Application Platform Expansion Pack Redhat quay 3 |
|
| Vendors & Products |
Redhat build Of Apache Camel For Spring Boot
Redhat jboss Enterprise Application Platform Expansion Pack Redhat quay 3 |
Mon, 31 Aug 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 31 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being unlimited. This allows a remote attacker to send large amounts of data or maintain connections indefinitely, potentially crashing the server by exhausting its memory or other resources. | |
| Title | Undertow-core: undertow: websocketcontainer defaults for buffers and timeouts are infinite | |
| First Time appeared |
Redhat
Redhat camel Spring Boot Redhat enterprise Linux Redhat jboss Enterprise Application Platform Redhat jboss Fuse Redhat jbosseapxp Redhat red Hat Single Sign On |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:/a:redhat:camel_spring_boot:4 cpe:/a:redhat:jboss_enterprise_application_platform:7 cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jboss_fuse:7 cpe:/a:redhat:jbosseapxp cpe:/a:redhat:red_hat_single_sign_on:7 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat camel Spring Boot Redhat enterprise Linux Redhat jboss Enterprise Application Platform Redhat jboss Fuse Redhat jbosseapxp Redhat red Hat Single Sign On |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2026-08-31T08:47:51.752Z
Updated: 2026-08-31T08:47:51.752Z
Reserved: 2026-08-27T08:40:49.997Z
Link: CVE-2026-81624
No data.
Status : Received
Published: 2026-08-31T09:17:03.453
Modified: 2026-08-31T09:17:03.453
Link: CVE-2026-81624