← All Advisories

CVE-2026-15561

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-15561

Key Details

CVECVE-2026-15561
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productssee table below
Classified asCWE-770 (Allocation of Resources Without Limits or Throttling)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat JBoss Enterprise Application Platform 7.4.25
Red HatRed Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7
Red HatRed Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8
Red HatRed Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9
Red HatRed Hat JBoss Enterprise Application Platform 7
Red HatRed Hat JBoss Enterprise Application Platform 8.1 for RHEL 10
Red HatRed Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
Red HatRed Hat JBoss Enterprise Application Platform 8.1 for RHEL 9
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-15561
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-15561