Bug 2431938 (CVE-2026-24329) - CVE-2026-24329 wildfly-core: WildFly Core: Denial of Service via malformed payload injection by an authenticated administrative user.
Summary: CVE-2026-24329 wildfly-core: WildFly Core: Denial of Service via malformed pa...
Keywords:
Status: NEW
Alias: CVE-2026-24329
Deadline: 2026-07-29
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-01-22 03:14 UTC by OSIDB Bzimport
Modified: 2026-08-11 00:45 UTC (History)
45 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-01-22 03:14:23 UTC
A remote user authenticated as administrative user can inject a malformed payload into the
Inet Address field, that is accessible via the Management Model. Once the management
interface is successfully modified, the server crashes and cannot be recovered (not even by
a Super User) because the payload is written into the standalone.xml configuration file.
Manual removal of the injected date from the file is required in order to bring the server
back online.


Note You need to log in before you can comment on or make changes to this bug.