HIGH
CVE-2026-15561
CVSS
7.5
Description
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.
Weakness (CWE)
CWE-770
Resource Allocation Without Limits
EPSS Score
0.37%
Probability of exploitation in next 30 days
30.9th percentile
References
https://access.redhat.com/errata/RHSA-2026:53644
https://access.redhat.com/errata/RHSA-2026:53645
https://access.redhat.com/errata/RHSA-2026:53646
https://access.redhat.com/errata/RHSA-2026:53806
https://access.redhat.com/security/cve/CVE-2026-15561
https://bugzilla.redhat.com/show_bug.cgi?id=2483133
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.