{"id":"CVE-2026-5680","title":"A flaw was found in Undertow","summary":"A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDef…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-770"],"vendor":"Red Hat","product":"undertow-core","affected":["undertow-core (all versions)","undertow-core","undertow-core (all versions)","moditect","pki-core:10.6/resteasy","pki-deps:10.6/resteasy","resteasy (all versions)","undertow-core","undertow-core (all versions)","undertow-core (all versions)","undertow-core-2.3.10.Final.jar (all versions)","undertow-core (all versions)","undertow-core-2.3.10.Final.jar (all versions)","undertow-core-2.3.18.Final.jar","undertow-core-2.3.23.SP3-redhat-00001.jar","undertow-core (all versions)","undertow-core (all versions)"],"published":"2026-08-27","updated":"2026-09-22","sourceUpdated":"2026-09-22T16:17:49.230","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-5680","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:70228","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:70229","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:70230","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:70277","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-5680","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2455350","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5680.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-5680"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5680"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00404,"epssPercentile":0.34374,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-08-31T18:15:03.314114Z"},"ingestedAt":"2026-09-07T10:08:52.325Z","slug":"CVE-2026-5680","body":"## Overview\n\nA flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel for Spring Boot 4, Red Hat Data Grid 8, Red Hat Enterprise Linux 9, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, … · no fix planned: Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Process Automation 7, Red Hat Single Sign-On 7, … · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5680.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}