Skip to content
Threat Feed
low advisory

Denial of Service Vulnerability in Red Hat WildFly and JBoss EAP

A vulnerability in Red Hat WildFly and JBoss Enterprise Application Platform allows a remote, unauthenticated attacker to trigger a denial-of-service condition.

CVE search metadata

CVE search record: CVE-2024-27365. Severity: medium. CVSS: 4.4. EPSS: 0.17%. KEV: no. Product: WildFly, JBoss Enterprise Application Platform. Brief: Denial of Service Vulnerability in Red Hat WildFly and JBoss EAP. Brief link: https://feed.craftedsignal.io/briefs/2026-08-wildfly-dos/

A vulnerability has been identified in Red Hat WildFly and Red Hat JBoss Enterprise Application Platform (EAP) that allows a remote, unauthenticated attacker to cause a denial-of-service (DoS) condition. The vulnerability, tracked as CVE-2024-27365, impacts the availability of the application server by enabling an attacker to overwhelm system resources or trigger an application crash. Because these servers are typically internet-facing components of an enterprise architecture, this vulnerability poses a risk to service uptime. Defenders should prioritize patching or applying vendor-recommended configurations to limit exposure of management interfaces and application endpoints to untrusted networks.

Impact

Successful exploitation results in the disruption of service for Red Hat WildFly or JBoss EAP instances. This can impact mission-critical business applications, internal services, and customer-facing portals that rely on these platforms.

Recommendation

  • Apply the security patches provided by Red Hat for all affected JBoss EAP and WildFly deployments.
  • Audit network perimeter defenses to ensure that management interfaces of application servers are not exposed to the public internet.
  • Monitor application server logs for frequent crash events or unexpected service restarts that may indicate exploitation attempts.

Mitigations

Patch Red Hat WildFly and JBoss EAP instances

immediate IT Operations

CVE-2024-27365