Beveiligingsadvies

CVE-2026-5680

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-27 16:25:29
Laatst bijgewerkt 2026-09-09 11:34:26
Toegewezen door redhat
CVSS-score 7.5
Status PUBLISHED

Beschrijving

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.