---
id: CVE-2026-5680
title: A flaw was found in Undertow
summary: >-
  A flaw was found in Undertow. A remote attacker could exploit this
  vulnerability by sending specially crafted WebSocket messages with
  permessage-deflate negotiated. This could lead to excessive memory consumption
  due to the PerMessageDef…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
vendor: Red Hat
product: undertow-core
affected:
  - undertow-core (all versions)
  - undertow-core
  - undertow-core (all versions)
  - moditect
  - 'pki-core:10.6/resteasy'
  - 'pki-deps:10.6/resteasy'
  - resteasy (all versions)
  - undertow-core
  - undertow-core (all versions)
  - undertow-core (all versions)
  - undertow-core-2.3.10.Final.jar (all versions)
  - undertow-core (all versions)
  - undertow-core-2.3.10.Final.jar (all versions)
  - undertow-core-2.3.18.Final.jar
  - undertow-core-2.3.23.SP3-redhat-00001.jar
  - undertow-core (all versions)
  - undertow-core (all versions)
published: '2026-08-27'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T16:17:49.230'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5680'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:70228'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:70229'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:70230'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:70277'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-5680'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2455350'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5680.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-5680'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5680'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00576
epssPercentile: 0.46264
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-08-31T18:15:03.314114Z'
ingestedAt: '2026-09-07T10:08:52.325Z'
patched:
  - jboss_eap_8_1_for_rhel 10
  - jboss_eap_8_1_for_rhel 8
  - jboss_eap_8_1_for_rhel 9
---

## Overview

A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat build of Apache Camel for Spring Boot 4, Red Hat Data Grid 8, Red Hat Enterprise Linux 9, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Process Automation 7, … · no fix planned: Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Process Automation 7, Red Hat Single Sign-On 7, … · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5680.json)
- **RHSA-2026:70230** · Red Hat · fixed in: Red Hat JBoss EAP 8.1 for RHEL 10 · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70230)
- **RHSA-2026:70228** · Red Hat · fixed in: Red Hat JBoss EAP 8.1 for RHEL 8 · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70228)
- **RHSA-2026:70229** · Red Hat · fixed in: Red Hat JBoss EAP 8.1 for RHEL 9 · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70229)
