Red Hat JBoss Enterprise Application Platform

38 known vulnerabilities in Red Hat JBoss Enterprise Application Platform, 2 critical, 1 actively exploited, with patch priority, exploit likelihood and the…

Recently exploited

  • CVE-2026-34197 CVSS 8.8 high · actively exploited Apache ActiveMQ Improper Input Validation Vulnerability

Latest vulnerabilities

  • CVE-2026-101292 CVSS 8.2 high Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy()…
  • CVE-2026-93574 CVSS 6.5 medium A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially…
  • CVE-2026-93562 CVSS 6.5 medium A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to…
  • CVE-2026-93579 CVSS 6.5 medium A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line…
  • CVE-2026-93576 CVSS 7.5 high A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in…
  • CVE-2026-93573 CVSS 6.5 medium A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation…
  • CVE-2026-93569 CVSS 8.2 high A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process…
  • CVE-2026-93568 CVSS 7.5 high A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended…
  • CVE-2026-93567 CVSS 7.5 high A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host…
  • CVE-2026-93566 CVSS 6.5 medium A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control…
  • CVE-2026-93565 CVSS 7.5 high A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens…
  • CVE-2026-93564 CVSS 7.5 high A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to…
  • CVE-2026-93558 CVSS 7.5 high A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using…
  • CVE-2026-85511 CVSS 4.2 medium A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection…
  • CVE-2026-10832 CVSS 5.9 medium A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability…
  • CVE-2026-93560 CVSS 7.5 high A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header…
  • CVE-2026-93492 CVSS 5.3 medium A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large…
  • CVE-2026-93491 CVSS 7.5 high A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1…
  • CVE-2026-93488 CVSS 7.5 high A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because…
  • CVE-2026-93575 CVSS 7.5 high A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted…
  • CVE-2026-93572 CVSS 7.5 high A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially…
  • CVE-2026-93563 CVSS 7.5 high A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP…
  • CVE-2026-93561 CVSS 6.5 medium A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as…
  • CVE-2026-93494 CVSS 7.5 high A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially…
  • CVE-2026-81829 CVSS 5.3 medium A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application…
  • CVE-2026-86404 CVSS 8.8 high EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses…
  • CVE-2026-17615 CVSS 7.5 high A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote…
  • CVE-2026-81624 CVSS 7.5 high Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket…
  • CVE-2026-5680 CVSS 7.5 high A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with…
  • CVE-2026-49875 CVSS 9.8 critical Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening…