Impact
A vulnerability exists in Undertow core that allows an attacker to send specially crafted WebSocket messages when permessage‑deflate compression is negotiated. The flaw causes the PerMessageDeflateFunction to use exponential doubling for buffer allocation, leading to excessive memory consumption. This can exhaust server resources and result in a denial of service. The weakness is classified as CWE‑770, representing excess resource consumption.
Affected Systems
Red Hat products that embed Undertow are affected, including Red Hat Enterprise Linux 8, 9, and 10; Red Hat Data Grid 8; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform versions 7 and 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat Process Automation 7; Red Hat Single Sign‑On 7; and Red Hat builds of Apache Camel – HawtIO 4 and Camel for Spring Boot 4. No specific version ranges are listed, so any installation that includes the vulnerable Undertow component may be impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact and available exploitation code, while the EPSS score is not provided. Consequently the exploitation probability is unclear, but the vulnerability is reachable from outside and can be triggered by a crafted WebSocket handshake, making it a serious risk for exposed services. The issue is not currently listed in the CISA KEV catalog, but the severity and potential for service interruption warrant immediate attention.
OpenCVE Enrichment