VulnSea

eap7-netty vulnerabilities

CVEs whose affected-version data names the eap7-netty package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

11 CVEsRSS

CVE-2026-86404High· 8.8
2w ago

EAP's Artemis deserialization configuration permits deserialization by default

EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() met…

TwilightRed Hat · eap7-activemq-artemisEPSS 0.50%via NVD
CVE-2026-15567High· 7.5
1mo ago

A flaw was found in Wildfly

A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that …

TwilightRed Hat · eap7-activemq-artemisEPSS 0.47%via NVD
CVE-2026-15565High· 7.5
1mo ago

A flaw was found in Undertow

A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack …

TwilightRed Hat · eap7-activemq-artemisEPSS 0.51%via NVD
CVE-2026-15563High· 7.4
1mo ago

A flaw was found in EAP's IIOP

A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.

TwilightRed Hat · eap7-activemq-artemisEPSS 0.31%via NVD
CVE-2026-15562High· 7.5
1mo ago

A flaw was found in EAP's jboss-remoting

A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to den…

TwilightRed Hat · eap7-activemq-artemisEPSS 0.46%via NVD
CVE-2026-15561High· 7.5
1mo ago

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the…

TwilightRed Hat · eap7-activemq-artemisEPSS 0.37%via NVD
CVE-2026-15556High· 8.1
1mo ago

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the prot…

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the prot…

TwilightRed Hat · eap7-activemq-artemisEPSS 0.24%via NVD
CVE-2026-15555High· 8.8
1mo ago

A flaw was found in JBoss marshalling

A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on …

TwilightRed Hat · eap7-activemq-artemisEPSS 0.28%via NVD
CVE-2026-15554High· 7.4
1mo ago

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentica…

TwilightRed Hat · eap7-activemq-artemisEPSS 0.24%via NVD
CVE-2026-15560High· 8.1
1mo ago

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in…

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in…

TwilightRed Hat · eap7-activemq-artemisEPSS 0.46%via NVD
CVE-2026-10579Critical· 9.8
1mo ago

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could l…

MidnightRed Hat · eap7-activemq-artemisEPSS 0.32%via NVD
eap7-netty vulnerabilities (CVEs) · VulnSea