{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-15561","assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","state":"PUBLISHED","assignerShortName":"redhat","dateReserved":"2026-07-13T05:08:26.350Z","datePublished":"2026-08-11T08:49:49.419Z","dateUpdated":"2026-08-24T11:38:32.081Z"},"containers":{"cna":{"title":"Undertow-core: oom via missing limits in chunked trailer in eap's undertow","metrics":[{"other":{"content":{"value":"Important","namespace":"https://access.redhat.com/security/updates/classification/"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS"}],"descriptions":[{"lang":"en","value":"A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service."}],"affected":[{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4.25","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-activemq-artemis","defaultStatus":"affected","versions":[{"version":"0:2.16.0-22.redhat_00057.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-glassfish-jsf","defaultStatus":"affected","versions":[{"version":"0:2.3.14-11.SP11_redhat_00001.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-ironjacamar","defaultStatus":"affected","versions":[{"version":"0:1.5.26-2.Final_redhat_00001.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-jackson-annotations","defaultStatus":"affected","versions":[{"version":"0:2.18.8-1.redhat_00003.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-jackson-core","defaultStatus":"affected","versions":[{"version":"0:2.18.8-1.redhat_00003.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-jackson-databind","defaultStatus":"affected","versions":[{"version":"0:2.18.8-1.redhat_00003.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-jackson-jaxrs-providers","defaultStatus":"affected","versions":[{"version":"0:2.18.8-1.redhat_00003.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-jackson-modules-base","defaultStatus":"affected","versions":[{"version":"0:2.18.8-1.redhat_00003.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-jackson-modules-java8","defaultStatus":"affected","versions":[{"version":"0:2.18.8-1.redhat_00003.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-jboss-remoting","defaultStatus":"affected","versions":[{"version":"0:5.0.31-3.SP2_redhat_00001.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-jboss-server-migration","defaultStatus":"affected","versions":[{"version":"0:1.10.0-46.Final_redhat_00044.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-netty","defaultStatus":"affected","versions":[{"version":"0:4.1.135-1.Final_redhat_00001.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-netty-transport-native-epoll","defaultStatus":"affected","versions":[{"version":"0:4.1.135-1.Final_redhat_00001.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-picketlink-bindings","defaultStatus":"affected","versions":[{"version":"0:2.5.5-30.SP12_redhat_00020.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-picketlink-federation","defaultStatus":"affected","versions":[{"version":"0:2.5.5-24.SP12_redhat_00016.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-undertow","defaultStatus":"affected","versions":[{"version":"0:2.2.40-2.SP3_redhat_00001.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"eap7-wildfly","defaultStatus":"affected","versions":[{"version":"0:7.4.25-2.GA_redhat_00001.1.el7eap","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:jboss_enterprise_application_platform_els:7.4::el7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 7","collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","packageName":"undertow-core","defaultStatus":"affected","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:7"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform 8","collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","packageName":"undertow-core","defaultStatus":"affected","cpes":["cpe:/a:redhat:jboss_enterprise_application_platform:8"]},{"vendor":"Red Hat","product":"Red Hat JBoss Enterprise Application Platform Expansion Pack","collectionURL":"https://access.redhat.com/jbossnetwork/restricted/listSoftware.html","packageName":"undertow-core","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:jbosseapxp"]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:53644","name":"RHSA-2026:53644","tags":["vendor-advisory","x_refsource_REDHAT"]},{"url":"https://access.redhat.com/errata/RHSA-2026:53806","name":"RHSA-2026:53806","tags":["vendor-advisory","x_refsource_REDHAT"]},{"url":"https://access.redhat.com/security/cve/CVE-2026-15561","tags":["vdb-entry","x_refsource_REDHAT"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2483133","name":"RHBZ#2483133","tags":["issue-tracking","x_refsource_REDHAT"]}],"datePublic":"2026-08-11T05:52:49.718Z","problemTypes":[{"descriptions":[{"cweId":"CWE-770","description":"Allocation of Resources Without Limits or Throttling","lang":"en","type":"CWE"}]}],"x_redhatCweChain":"CWE-770: Allocation of Resources Without Limits or Throttling","timeline":[{"lang":"en","time":"2026-05-29T00:41:31.600Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-08-11T05:52:49.718Z","value":"Made public."}],"providerMetadata":{"orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat","dateUpdated":"2026-08-24T11:38:32.081Z"},"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-11T16:09:41.801549Z","id":"CVE-2026-15561","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-11T16:09:53.364Z"}}]}}