Fedora Account System
Red Hat Associate
Red Hat Customer
There exists a security vulnerability in Undertow that can cause remote DoS attacks. When server uses method FormEncodedDataDefinition.doParse(StreamSourceChannel) to parse large form data encoding with application/x-www-form-urlencoded, the method will cause OutOfMemory. This vulnerability can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. This happens because there is no size limit for this method hence a large request may jeopardize the environment leading to DoS.
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 Via RHSA-2025:22773 https://access.redhat.com/errata/RHSA-2025:22773
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 Via RHSA-2025:22775 https://access.redhat.com/errata/RHSA-2025:22775
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.0 Via RHSA-2025:22777 https://access.redhat.com/errata/RHSA-2025:22777
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 Via RHSA-2026:0386 https://access.redhat.com/errata/RHSA-2026:0386
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 Via RHSA-2026:0383 https://access.redhat.com/errata/RHSA-2026:0383
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 Via RHSA-2026:0384 https://access.redhat.com/errata/RHSA-2026:0384
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.0 Via RHSA-2026:3892 https://access.redhat.com/errata/RHSA-2026:3892
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 Via RHSA-2026:3891 https://access.redhat.com/errata/RHSA-2026:3891
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 Via RHSA-2026:3889 https://access.redhat.com/errata/RHSA-2026:3889
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 Via RHSA-2026:4915 https://access.redhat.com/errata/RHSA-2026:4915
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8 Via RHSA-2026:4916 https://access.redhat.com/errata/RHSA-2026:4916
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9 Via RHSA-2026:4917 https://access.redhat.com/errata/RHSA-2026:4917
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 Via RHSA-2026:4924 https://access.redhat.com/errata/RHSA-2026:4924
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 Via RHSA-2026:6012 https://access.redhat.com/errata/RHSA-2026:6012
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Via RHSA-2026:6011 https://access.redhat.com/errata/RHSA-2026:6011