Post #4507947
2026-08-11 09:30 UTC
Undertow, the web server inside Red Hat JBoss, has a pre-login flaw (CVE-2026-15565) that lets anyone crash the server by flooding a WebSocket until it runs out of memory.
Affects JBoss EAP 7/8 and Data Grid 8. No patch yet.
Fix: disable WebSockets where you can.
https://suriq.io/blog/undertow-jboss-websocket-preauth-dos
#CVE #Detection #infosec #cybersecurity
Replies (0)
No replies.