eap8-jbossws-api vulnerabilities
CVEs whose affected-version data names the eap8-jbossws-api package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-85511Medium· 4.2A flaw was found in EAP's Elytron
A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.
▾ SunlitRed Hat · eap8-activemq-artemisEPSS 0.17%via NVD
CVE-2026-14180Medium· 5.3A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding
A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the …
▾ SunlitRed Hat · eap8-activemq-artemisEPSS 0.57%via NVD