{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awildflywildfly/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redhat:jboss_enterprise_application_platform:*:*:*:*:*:*:*:*","cpe:2.3:a:wildfly:wildfly:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-81624"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["JBoss EAP","WildFly","Undertow"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","webserver","java"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-81624 is a resource exhaustion vulnerability affecting the Undertow web server, a core component of JBoss EAP and WildFly. The flaw arises because the implementation fails to enforce configurable limits on WebSocket message buffer sizes and session timeouts, defaulting these settings to be effectively unlimited. A remote, unauthenticated attacker can exploit this by opening and maintaining an excessive number of WebSocket connections or by flooding the server with large data payloads. By keeping these connections alive indefinitely or consuming available memory through buffer saturation, an attacker can trigger a denial of service (DoS), rendering the server unresponsive to legitimate requests. Given its role in enterprise application servers, this vulnerability represents a significant risk for organizations relying on Java-based middleware to handle high-concurrency traffic.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in denial of service, potentially causing system crashes and service unavailability for applications hosted on JBoss EAP or WildFly. This impacts availability of web-based services and administrative interfaces, forcing a restart of the application server to restore functionality.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize auditing your infrastructure to identify JBoss EAP and WildFly instances exposing WebSocket endpoints to the internet. Since specific patch or configuration guidance is pending, monitor application server logs for abnormal patterns of WebSocket connection persistence or high memory consumption. Disable WebSocket functionality for services where it is not business-critical to minimize the attack surface.\u003c/p\u003e\n","date_modified":"2026-08-31T11:17:38Z","date_published":"2026-08-31T11:17:38Z","id":"https://feed.craftedsignal.io/briefs/2026-08-undertow-dos/","summary":"A vulnerability in the Undertow web server used in JBoss EAP and WildFly allows remote attackers to trigger denial of service through WebSocket resource exhaustion due to unconfigurable limits.","title":"CVE-2026-81624: Resource Exhaustion in Undertow WebSocket Implementation","url":"https://feed.craftedsignal.io/briefs/2026-08-undertow-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wildfly:wildfly:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}