Skip to content
Threat Feed
low advisory

CVE-2026-81624: Resource Exhaustion in Undertow WebSocket Implementation

A vulnerability in the Undertow web server used in JBoss EAP and WildFly allows remote attackers to trigger denial of service through WebSocket resource exhaustion due to unconfigurable limits.

CVE search metadata

CVE search record: CVE-2026-81624. Severity: high. CVSS: 7.5. KEV: no. Product: JBoss EAP, WildFly, Undertow. Brief: CVE-2026-81624: Resource Exhaustion in Undertow WebSocket Implementation. Brief link: https://feed.craftedsignal.io/briefs/2026-08-undertow-dos/

CVE-2026-81624 is a resource exhaustion vulnerability affecting the Undertow web server, a core component of JBoss EAP and WildFly. The flaw arises because the implementation fails to enforce configurable limits on WebSocket message buffer sizes and session timeouts, defaulting these settings to be effectively unlimited. A remote, unauthenticated attacker can exploit this by opening and maintaining an excessive number of WebSocket connections or by flooding the server with large data payloads. By keeping these connections alive indefinitely or consuming available memory through buffer saturation, an attacker can trigger a denial of service (DoS), rendering the server unresponsive to legitimate requests. Given its role in enterprise application servers, this vulnerability represents a significant risk for organizations relying on Java-based middleware to handle high-concurrency traffic.

Impact

Successful exploitation results in denial of service, potentially causing system crashes and service unavailability for applications hosted on JBoss EAP or WildFly. This impacts availability of web-based services and administrative interfaces, forcing a restart of the application server to restore functionality.

Recommendation

Prioritize auditing your infrastructure to identify JBoss EAP and WildFly instances exposing WebSocket endpoints to the internet. Since specific patch or configuration guidance is pending, monitor application server logs for abnormal patterns of WebSocket connection persistence or high memory consumption. Disable WebSocket functionality for services where it is not business-critical to minimize the attack surface.


Immediate actions

Inventory JBoss EAP and WildFly instances in the environment.

IT Operations 48h

Mitigations

Disable WebSocket endpoints in JBoss EAP/WildFly configurations for non-critical services.

medium_term IT Operations

CVE-2026-81624