Security Advisory

CVE-2026-81624

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-31 08:47:51
Last updated 2026-09-10 07:15:29
Assigner redhat
CVSS score 7.5
State PUBLISHED

Description

Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being unlimited. This allows a remote attacker to send large amounts of data or maintain connections indefinitely, potentially crashing the server by exhausting its memory or other resources.