Product
low
advisory
CVE-2026-81624: Resource Exhaustion in Undertow WebSocket Implementation
1 TTP 1 CVEA vulnerability in the Undertow web server used in JBoss EAP and WildFly allows remote attackers to trigger denial of service through WebSocket resource exhaustion due to unconfigurable limits.
JBoss EAP +2
denial-of-service
webserver
java
1t
1c
high
advisory
Undertow AJP Authentication Bypass via CVE-2026-15554
2 TTPs 1 CVEThe Undertow AJP listener incorrectly trusts ssl_cert and is_ssl attributes within the AJP protocol without validating a shared secret, allowing unauthenticated attackers to bypass CLIENT-CERT authentication.
Undertow
vulnerability
authentication-bypass
network-security
2t
1c